Hacker News new | ask | show | jobs
by nonameiguess 1780 days ago
We deal with this by having multiple vulnerability scanners. Product A and Product B both scan your active environment. Product A scans Product B. Product B scans Product A. Additionally, make the vendors of those products sign NDAs so your threat actors, other than insiders, don't necessarily even know who they are. An attacker then needs to not only compromise both, but figure out who they are in the first place.
1 comments

To this I'd add what is colloquialy referred to as a "Chinese wall", so that even insiders aren't aware of the full picture.