Earlier quoted context omitted.
>Personally, i think the worst part about it is handling a low probability as something that's not gonne happen. Thats, especially in IT-Sec, one of the worst practices. If you are an online service provider, sure. Low probability means it's going to happen, especially as you scale with users. For a small business IT team? You can't keep a clean sheet, the strategy is to reduce the probabilities of an incident and re…
Well even tho i think at the end of your comment you went a bit out of the way, i get your point and i agree to a certain point. You cannot reduce the risks to 0 - that's a matter of fact and i would never claim you could. I tend to say its a question of cost/gain. If the cost the attacker has to pay (work/invest/...) is higher than the possible gain (data/funds/...) you are on a good track for your companies securit…
I can see why you would take "online service provider" to mean an ISP, but I meant it to include SaaS and apps like whatsapp, google, etc.. as well
>Therefor the next time you argue that some security measure is just an CISO that doesn't really care about its users
Oh I didn't mean to imply that, there's no doubt that IT admins that overimplement security policies care in general, the critique is not about motives, rather the efficiency. I don't argue that they don't care or even that they are wildly inefficient, just that they are suboptimal on this specific point by going overboard.