|
|
|
|
|
by dogman144
810 days ago
|
|
Maybe pointed at me - criticism comes from a sec startup selling a tool that, when deployed correctly, plugs into every upstream and downstream mission-critical data source, sees every security event worth responding too, and runs response… paired with zero upfront context on how the startup does security themselves (and upon further discussion, it’s not in their background, they have no hires, didn’t know 101 enterprise sec, and what is present is outsourced), what their roadmap is in this regard, why their tool is safe to use given those integrations, and the only info avail in this direction was a boilerplate security.md on GitHub. All together, it tells me they know how to do great data eng, but not how to do their own blue team and didn’t consider this a critical topic to handle, but also want to sell to blue teams. Security Saas with great tech are burning sec teams left and right these last 3 years, such that vendor risk questionnaires are changing to ask specifically about what I did in my thread. |
|