|
|
|
|
|
by eropple
659 days ago
|
|
> I'm sorry, but what else are defenders trying to do that isn't defense? This is an uncharitably narrow reading of the post to which you're replying, isn't it? Defenders are trying to ship. To make money to make payroll. Create profit centers, not cost centers. You can say that security is a feature and a load-bearing one, and I'd agree with you, but not everyone who makes decisions will do the same. |
|
> "You can say that security is a feature and a load-bearing one, and I'd agree with you, but not everyone who makes decisions will do the same."
Maybe it is, but I wouldn't put it that way. Security teams exist because people with bad intent that want to harm you exist. Just like lawyers exist because people who sue you (including the government) exist.
Imagine stating "lawyers don't exist to protect from lawsuits", that's how it sounds to me. If defenders aren't there to defend, then their existence isn't justified.
> "Defenders are trying to ship"
Defenders are there so that when other teams who "ship" attempt to do so, they don't get the application, system, company or wherever you have protected data doesn't get compromised. And this is before and after "shipping" or deployment. Security is a cost of business, whose RoI is measured by the fact that you are doing business without getting hacked, nothing more.