Hacker News new | ask | show | jobs
by screcth 540 days ago
The security team cares about minimizing risks to the company and to their own careers.

Deviating from what everybody else is doing makes it so that the burden of proving that your policies are sane is on you and if anything bad happens your head is the first to roll.

You use CrowdStrike and the company lost millions of dollars due to the outage? That's not your problem, you applied industry standard practices.

You don't use CrowdStrike and the company got hacked? You will have to explain to the executives and the board why you didn't apply industry standard practices and you will be fired.