Discussion about this post

User's avatar
richardstevenhack's avatar

"or getting the headcount and budget that matches the actual size of the problem."

And whose fault is that?

As usual: Management.

A management that is ignorant about security - and since it's not a profit-maker, couldn't care less.

Also, they're making a "risk assessment" - increase profits vs reduce profits by spending on security - a risk that may or may not occur during their tenure as management.

In essence, it's Bruce Schneier's "people are bad at assessing risk" problem.

Scale this across all organizations, and wallah! Cybersecurity crisis.

Now tack AI on top of that. Cybersecurity apocalypse.

There is only one solution: Using deterministic AI - NOT LLMs - to produce provable correct code - and also to monitor the organization's non-code risks (because it doesn't matter if the code is provably correct if your perimeter problems remain.)

No posts

Ready for more?