Discussion
Loading...

Post

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Claudius Link
@realn2s@infosec.exchange  路  activity timestamp 3 weeks ago

I continuously experience a #cybersecurity conundrum.

A manufacturer/developer isn't investing in security because the customers don't demand security. And even less are running to pay a premium for security.

With the end users there still seems to be an "I have nothing to hide" attitude.

So I'm looking for ideas, suggestions and experiences on how to increase and generate security awareness both on the management side as well as on the end user side.

Regarding end users there is the additional challenge of another layer of indirection.
I need to enable the "sellers" to create the security awareness, as they talk to the end users.

I'm NOT looking for advice like "just tell them what can go wrong" because i don't think it works. Or at least not if it is abstract and isn't personal.

#fedipower

  • Copy link
  • Flag this post
  • Block
Earl Dave of Sudseax 馃枛
@DaRC_Fantom@thefolklore.cafe replied  路  activity timestamp 3 weeks ago

@realn2s
legal obligation within the data protection laws - heavy fines.
Use examples of companies heavily impacted or closed... https://www.bbc.co.uk/news/articles/cx2gx28815wo

Customers assume security but don't want it to cause friction in what they want to do.

  • Copy link
  • Flag this comment
  • Block
Claudius Link
@realn2s@infosec.exchange replied  路  activity timestamp 3 weeks ago

@DaRC_Fantom
Nice example. Sound like a good story for the #BigBookOfLittleBreaches 馃槂
(https://infosec.exchange/@realn2s/112240250364961390)

In my experience the "legal obligation", "heavy fines" line doesn't work too well 馃槧
It shifts the goal from providing adequate security to just avoiding the fines 馃槧
And this sadly, often can be accomplished by transferring the risk (it's someone else's fault or problem) instead of eliminating or reducing the risk
E.g. by just adding some documentation of what "users" need to do to stay secure and blame them if they didn't do it.

  • Copy link
  • Flag this comment
  • Block
Claudius Link
@realn2s@infosec.exchange replied  路  activity timestamp 3 weeks ago

@0x00string
馃檹馃徎 Understood and I agree.
Sadly, I went to one "care too much" cycle.
I hope that I learned to reduce the amount of care to an acceptable level

  • Copy link
  • Flag this comment
  • Block
Claudius Link
@realn2s@infosec.exchange replied  路  activity timestamp 3 weeks ago

@0x00string
馃槶
I'm very close to doing that 馃お
Both 馃槣

  • Copy link
  • Flag this comment
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About 路 Code of conduct 路 Privacy 路 Users 路 Instances
Bonfire social 路 1.0.1-alpha.8 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login