Security News > 2021 > May > Debunking infosec purity and other security myths in the wake of recent attacks
The security team at Forrester busts a number of security myths.
Recently, an op-ed sent information security Twitter into a tizzy by blaming cybersecurity industry best practices for recent high-profile security breaches.
For the security team at Forrester, the op-ed furthered a number of security myths that we felt compelled to bust here.
A quick nose count among the Forrester security and risk team determined that if security teams only hired people who had never worked for a firm that had suffered a security incident, most of us would no longer be employable.
Those who lack an understanding of security may believe that zero-incident security is possible or that the perfect chief information security officer is the one who never had an incident.
This doesn't occur by a miracle, but by taking a methodical approach to: 1) set the tone from the top with your board; 2) build a human-centric security program; 3) build support, manage detractors, and navigate politics; 4) move outside the silos with security champions, whether they're developers helping you address application security issues or champions helping you rebrand; and 5) trumpet your progress and successes across the organization.
News URL
Related news
- Critical Security Flaw in WhatsUp Gold Under Active Attack - Patch Now (source)
- 18-year-old security flaw in Firefox and Chrome exploited in attacks (source)
- Most Ransomware Attacks Occur When Security Staff Are Asleep, Study Finds (source)
- SQL Injection Attack on Airport Security (source)
- Security biz Verkada to pay $3m penalty under deal that also enforces infosec upgrade (source)
- Homeland security hopes to scuttle maritime cyber-threats with port infosec testbed (source)
- Security measures fail to keep up with rising email attacks (source)