Is not the tech a part of the organizations way of doing business?
These things are highly related to what’s going down in a thread [1] from yesterday (about “shitty projects”).
I’m sure these guys spend many millions each year on security products, but either people in the know on the tech side is ignored, or they have no competencies left.
In the thread I mention above I have actually posted about my general experience from a major insurance player.
A concrete example:
We were making changes to a custom software and as there were concerns about bandwidth requirements and latency I took it upon myself to figure out what a specific process looked like, from the business perspective.
In short, in the middle of the workflow, customers journals was written to CD and mailed to physicians. Encryption? Eh, no... Any process in place to ensure safe keeping and return/destruction? Uh, forget about it...
This was in the time when a lot of these “lost usb devices” and hacked systems seemed to pop up daily.
I obviously raised this with the security team, the security officer and the business unit.
No one wanted to touch this finely tuned business process.
It felt like I was working at fawlty towers.
Again, that companies have drawn this line between business and tech, “‘cause tech is not core bidniz”, will haunt a lot of big players for years to come.
[1] https://news.ycombinator.com/item?id=19998806