Security Program Is Shit
crankysec.com
crankysec.com
So glad I quit that job.
I hope to take the same action as you in the near future.
What's the motivation to do anything right in security if most of the time you don't have a breach and you can get away cutting corners? When something does go wrong, you can blame it on underlings, claim it was a "sophisicated attack from nation-state actors", and rely on the public to not care?
I don't know that security is comparable to project management, health care services, or marketing. Inefficiencies in those have visible costs and reasonably good incentives for improving them.
Consultants get paid to come in and advise, and internal staff are ignored? Suck it up, it's not a problem particular to security. I've seen it everywhere.
People don't choose hospitals because of their security program? Well, duh. They don't choose hospitals for all kinds of non medical reasons that are still vital for the damn thing to function. Get back to me when you're in surgery and the whole hospital goes down in a ransomware attack.
Honestly, if I had to listen to this person on my team for more than 10 seconds, I'd be on the phone to Deloitte before you could blink.
You Security Program Is Shit