Hacker News new | ask | show | jobs
by cassianoleal 563 days ago
> Even if much of that caring is box ticking rather than actually looking into the security (hello ISO27001), you’d expect it to result in generally a security conscious culture.

If the whole value is in ticking the box, why would that develop a culture that values anything more than the tick?

1 comments

The cycle usually goes something like box ticking, complacency, security scare, remediation, rinse and repeat.