Elektrine lite

← Feed

@subm3rge@infosec.exchange

Post #4054949

2026-07-24 05:23 UTC

@julie@merida.hair Indeed, and that is a culture issue owned by others than me - my job is to secure what the org wants to do, not tell them what to do.. I don't agree with the label you put on what I need to do to secure those who are exploited, or those who are reckless, in the de facto environment and culture we have rather than the ideal one. Often it seems security is viewed as the sole restraing and controlling part of an org, and the discussion stays around how such control is applied, basically putting the onus of doing it "right" all on Security. This leaves out the mission goal: "secure the org". It is not the same thing to secure a scared, chaotic org, as an aware and structured one. You can't use the same methods. Talking to users and really understanding what their goals are is key, absolutely. All the users, individually and as an org.

Replies (0)

No replies.