Earlier quoted context omitted.
Agreed. Companies that are great at selling to governments and massive enterprises tend to be great at security theatre and security certifications, but that’s not the same as being great at security. Their tech tends to be bloated spaghetti full of tech debt, with a huge surface area for attacks, and systems like that are nearly impossible to secure in a truly robust way. Embedding this kind of software deep in your…
Would you mind briefly explaining the concept of "tech debt" to a layperson?
Anyway, here's a good introduction: https://en.m.wikipedia.org/wiki/Technical_debt