Discussion
Loading...

Post

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Claudius Link
@realn2s@infosec.exchange  ·  activity timestamp 2 days ago

I continuously experience a #cybersecurity conundrum.

A manufacturer/developer isn't investing in security because the customers don't demand security. And even less are running to pay a premium for security.

With the end users there still seems to be an "I have nothing to hide" attitude.

So I'm looking for ideas, suggestions and experiences on how to increase and generate security awareness both on the management side as well as on the end user side.

Regarding end users there is the additional challenge of another layer of indirection.
I need to enable the "sellers" to create the security awareness, as they talk to the end users.

I'm NOT looking for advice like "just tell them what can go wrong" because i don't think it works. Or at least not if it is abstract and isn't personal.

#fedipower

  • Copy link
  • Flag this post
  • Block
Earl Dave of Sudseax 🖖
@DaRC_Fantom@thefolklore.cafe replied  ·  activity timestamp 2 days ago

@realn2s
legal obligation within the data protection laws - heavy fines.
Use examples of companies heavily impacted or closed... https://www.bbc.co.uk/news/articles/cx2gx28815wo

Customers assume security but don't want it to cause friction in what they want to do.

  • Copy link
  • Flag this comment
  • Block
Claudius Link
@realn2s@infosec.exchange replied  ·  activity timestamp 2 days ago

@DaRC_Fantom
Nice example. Sound like a good story for the #BigBookOfLittleBreaches 😃
(https://infosec.exchange/@realn2s/112240250364961390)

In my experience the "legal obligation", "heavy fines" line doesn't work too well 😠
It shifts the goal from providing adequate security to just avoiding the fines 😠
And this sadly, often can be accomplished by transferring the risk (it's someone else's fault or problem) instead of eliminating or reducing the risk
E.g. by just adding some documentation of what "users" need to do to stay secure and blame them if they didn't do it.

  • Copy link
  • Flag this comment
  • Block
Nullstring 🏴‍☠️
@0x00string@infosec.exchange replied  ·  activity timestamp 2 days ago

@realn2s burn down the building across the street, or learn to stop caring in your heart more than your client does

  • Copy link
  • Flag this comment
  • Block
Claudius Link
@realn2s@infosec.exchange replied  ·  activity timestamp 2 days ago

@0x00string
😭
I'm very close to doing that 🤪
Both 😜

  • Copy link
  • Flag this comment
  • Block
Nullstring 🏴‍☠️
@0x00string@infosec.exchange replied  ·  activity timestamp 2 days ago

@realn2s i dont mean it to be like... flippant or dismissive... i mean to really genuinely, like for your own mental health and happiness. caring more than clients do is... devastating tbh. in order to do all this as work it helps imo to have some amount of compartmentalization for it.

  • Copy link
  • Flag this comment
  • Block
Claudius Link
@realn2s@infosec.exchange replied  ·  activity timestamp 2 days ago

@0x00string
🙏🏻 Understood and I agree.
Sadly, I went to one "care too much" cycle.
I hope that I learned to reduce the amount of care to an acceptable level

  • Copy link
  • Flag this comment
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.0 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login