|
|
|
|
|
by hvb2
233 days ago
|
|
This has nothing to do with testing. This is a lack of training. I would say they need to 'think like an attacker' at least some of the time. But this is still too high of a bar. I think this is really a problem of rewarding people when they finish things. One way or the other. It works, so on to the next project... |
|
Shift-left was supposed to fix that but it failed because the primary persona to sell ended up becoming the CISO again, and not trying to find a way to make security ownership a Dev and QA responsibility as well (this is largely organizational).