They won't make the same mistake twice and will build a comprehensive cybersecurity program, and it will succeed. Up until someone questions this cost and they forgot what they are paying for because everything was so smooth and repeat the cycle.
The objective of security is risk identification and management, not creating an impervious barrier for potential adversaries.
You couldn’t have said it better.
Just ask any CISO if they would bet their job on surviving a $1M unrestricted red team exercise with a year-long timeframe. They would all be scared shitless by the thought. I bet if you asked the CISO of MGM three days before the attack: "How much would it cost to hack MGM and cripple operations?" they would answer like every other CISO I have heard answer that question and say something on the order of $100K. They know it does not work; they are there to be sacrificed and just hope it does not happen on their watch.
Keep in mind that amounts to around 100 person-years of dedicated hacking labor. I get a team of 50 and 2 years to achieve total compromise. I get to burn 5-10 zero click RCE zero-days. The idea that any of the commercial cybersecurity companies or any commercial IT organization could design a system that could resist such an attack is laughable. This is not a question of resources, it is one of ability.
I agree, compliance is not an above-average security program. But an security program that is merely above-average is woefully underprepared for the modern threat landscape. You need a security program 100x better than “best practices” to stand a meaningful chance and you are not finding that amongst the charlatans in the big cybersecurity players.
Speaking from my experience, many don't understand the threats even after an incident. The reaction is often to add 'more security' under any name. More restrictive policies, more scanning, more layers of MFA - just blindly layering on things because it's seen as 'more secure' without properly understanding how it affects risk is an awful approach to managing security.
They have an incredibly crusty, buggy billing system written in PowerBuilder, and I swear it's a holdover from the Voice stream days
Disclaimer: Worked there in Tech Support.
And then, when it does, they blame the people who were pointing out the risks and suggesting solutions rather than the people who were ignoring those people the whole time.
Unless they don't have cyber insurance