Ask HN: What cloud security practices should you do, but don't?
Why not?
Why not?
This was due to being inexperienced with the work, too many duties, and a time line that didn't give me the time that I needed to fully understand some topics.
TLDR; -Security vulnerabilities from version updates -SSL on some platforms -Not having a dedicated / experienced individual on staff for dev ops in general
I'm not surprised to see that the first thing you listed was patching known vulnerabilities. Staying up to date with known vulnerabilities is the baseline of a security policy, but patch management is needlessly hard, especially if you don't have dedicated staff to scour security mailinglists.
We built a product to make this easier: https://appcanary.com . Maybe it would have helped your old employer.
</self promotion>
From a sysadmin/devops PoV boils down to flexibility. Security comes at the expense of flexibility and flexibility is more important for the survival and well-being of many/most IT companies and its especially crucial to startups.