Wendy Nather · @wendynather
2295 followers · 2651 posts · Server infosec.exchange

We can’t really address the underlying dynamics of the if we don’t even know what constitutes effective security or whether it’s even affordable for most orgs.

#securitypovertyline

Last updated 2 years ago

Wendy Nather · @wendynather
2295 followers · 2649 posts · Server infosec.exchange

Another thing I’m thrilled to see: the growth of Applied Cybersecurity Community Clinics, where cybersecurity students get hands-on experience doing pro bono work for those below the : strausscenter.org/events/infor

#securitypovertyline

Last updated 2 years ago

Wendy Nather · @wendynather
1551 followers · 907 posts · Server infosec.exchange

@boblord @jack_daniel @accidentalciso It’s true that the loudest, most visible representatives of at conferences are military, financial institutions, and tech companies (along with security vendors, duh). It’s especially important in to give a voice to everyone else, which is why I keep harping on the . Nobody’s going to step on a stage and say “Our security sucks,” but these stories need to be told.

#infosec #policy #securitypovertyline

Last updated 3 years ago

Wendy Nather · @wendynather
991 followers · 413 posts · Server infosec.exchange

@0x7eff @mdfranz @gdbassett That’s how I phrase it when I talk about the — they need budget, expertise, capability, and influence.

And expertise is more than just awareness or training; it includes the experience to know what to do with something you’ve never seen before.

youtu.be/7c-HrJmPj2Q

(talk starts about 10 minutes in)

#securitypovertyline

Last updated 3 years ago

mrjhnsn :verified: · @mrjhnsn
119 followers · 74 posts · Server infosec.exchange

One of my clients recently requested I do a security audit of an associated but independent side org.

There’s only 3 users and apparently an on-prem server. (They didn’t even know that’s what the computer in the corner of their office was.)
Their is unpatched.
Security has never been something they’ve even spent 10 seconds thinking about.

The SMBs I take on as clients, often aren’t even doing any attempt at until I’ve run through their stuff. Small Non-profits like this example are even worse off. MFA? yeah right. Password managers? you must be high.

There has to be a better way to serve these small orgs that’s not snake oil, and help them put up a solid defense somewhere above the .
/rant

#exchange #wordpress #defenseindepth #securitypovertyline

Last updated 3 years ago