U.S. Senate to probe whether legislation needed to combat cyber attacks
11–20 of 66 posts
Re: U.S. Senate to probe whether legislation needed to combat cyber attacks
#12It's mind boggling that the government needs to require this. What bureaucrat is refusing some IT person from requesting the funds doing this?
Literally all of them. Security is a cost center, and non bureaucrats salaries are minimized as much as possible until you are left with "warm body to fill chair". Even the NSA doesn't pay well, compared to private sector.
On the other hand, I bet it's pretty fun working for the NSA: https://en.wikipedia.org/wiki/NOBUS
Re: U.S. Senate to probe whether legislation needed to combat cyber attacks
#13Earlier quoted context omitted.
Literally all of them. Security is a cost center, and non bureaucrats salaries are minimized as much as possible until you are left with "warm body to fill chair". Even the NSA doesn't pay well, compared to private sector.
I'm wholly aware the private sector pays better, but in the grand scheme of pay/average citizen, they still make decent salaries. In that regard, why is upper management ignoring IT security at a base-line level of at least rotating backups? Like even that is pretty cheap and you can revert systems back within a day or two with a few days of lost work. Nobody is saying have a top tier security team.
Re: U.S. Senate to probe whether legislation needed to combat cyber attacks
#14Re: U.S. Senate to probe whether legislation needed to combat cyber attacks
#15I am always worried non-programmers don't sufficiently understand how pathetic it is that we limp along with bloated Unix and other accidents of history that were never retired. And this lassies-fair approach to cleanliness and reducing complexity both makes us more vulnerable and less productive.
Why single out Unix and not, you know, Windows ?
Re: U.S. Senate to probe whether legislation needed to combat cyber attacks
#16reverse the terrible ITAR legacy fund foundational security and mandate its use by government agencies and suppliers
Can you tell us what that means?
Re: U.S. Senate to probe whether legislation needed to combat cyber attacks
#17Legislation is required to reverse the posture of the NSA from offense to defense. Nothing else will help until that is done.
Re: U.S. Senate to probe whether legislation needed to combat cyber attacks
#18Re: U.S. Senate to probe whether legislation needed to combat cyber attacks
#19Earlier quoted context omitted.
I'm wholly aware the private sector pays better, but in the grand scheme of pay/average citizen, they still make decent salaries. In that regard, why is upper management ignoring IT security at a base-line level of at least rotating backups? Like even that is pretty cheap and you can revert systems back within a day or two with a few days of lost work. Nobody is saying have a top tier security team.
I was on a temporary pentesting contract at a Fortune 500 company, and the reason for ignoring security came down to cost. Our contact in their IT department said that when they were trying to get the budget to fix their longstanding security issues, they were told that it's cheaper to accept occasionally getting hacked than it is to fix things. They said that public relations people at big companies had pushed the "…
Real security is extraordinarily expensive. Very rarely is that compatible with shareholder value.
Re: U.S. Senate to probe whether legislation needed to combat cyber attacks
#20Legislation is required to reverse the posture of the NSA from offense to defense. Nothing else will help until that is done.