There are far too many unserious people representing our industry.
There are far too many unserious people representing our industry.
But companies still want to sell products, including to people who are at least nominally concerned about security, and marketing's gonna market.
Security is expensive, C suite does not understand the benefit (we have been fine for X years!), and the ROI is seemingly 0 (until it is not).
If most ICs had a say, their system would probably be Fort Knox. I try to instill good security practices around my company, but over and over again the response is… “okay but does this slow us down or speed us up?” or “just fill out the compliance form and make it sound like we do this stuff” (which I refuse to, every time).
I cannot imagine what the worst of the worst looks like, but security is one of those things where something FINALLY happens and you start to adopt better practices. But until then, who cares!
That said I'm pretty sure the main reason is that corporate cybersecurity policies are often such an incomprehensible byzantine mishmash that trying to do the right thing will be rewarded with an all expenses three week stay in a Kafka novel. Once, when I was new at a company and hopelessly naive, I triggered a multi-month delay in deploying a security fix because I made the mistake of filing proper paperwork as per the company policy that I had been so recently trained on. If I had just deployed it, as I later discovered everyone else usually did, I could have saved myself a person-week's worth of struggling with red tape.
Competence isn't widely valued, obedience and sales figures are. Which wouldn't be so problematic if evolution could run its course and eliminate incompetence naturally, but that's now hard to see coming to pass when we have towering circular supply chains that feed on it.