Ancestors

Written by April King on 2024-12-10 at 16:08

was asked a really interesting question in an interview yesterday: given a budget, which areas of security spending produce the greatest and worst (or negative) ROI?

my answer:

positive: SSO/OAuth, hardware keys

worst: DAST, DLP, honorable mention to poorly configured IDS’s

what’s your answer?

=> More informations about this toot | More toots from april@macaw.social

Toot

Written by Konstantin Weddige on 2024-12-10 at 16:23

@april I think it depends a bit on where you start from and how big the budget is with respect to what would be necessary.

For example, pentests can have a great ROI if and only if you already have some baseline and the budget to fix the findings that will inevitably come up.

If the budget is extremely tight, it may be best to do nothing (new) and instead give your admin(s) some slack to catch up on their day-to-day tasks.

=> More informations about this toot | More toots from weddige@gruene.social

Descendants

Written by Konstantin Weddige on 2024-12-10 at 16:26

@april pentests without the budget to fix any of the findings might be an example of a negative ROI: You have the same problems as before, but now more people (including your own employees, that got the report) know about them.

=> More informations about this toot | More toots from weddige@gruene.social

Proxy Information
Original URL
gemini://mastogem.picasoft.net/thread/113629450515622574
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
268.576201 milliseconds
Gemini-to-HTML Time
0.432049 milliseconds

This content has been proxied by September (ba2dc).