Why we need to stop cutting down security's tall poppies | ZDNet

General News

Summary

And it might sound like the noble and "right" thing to say when we apologise, that we can do better, and accept that we made stupid, avoidable mistakes, I think a lot of information security professionals are quite often simply too hard on themselves and on their colleagues. Do we ever read, in the companys annual report, how the actions of an response team saved however many millions of dollars in lost revenue, reputation damage, non-compliance fines, or potential investigations by privacy regulators? I wouldnt have so much of a problem with that — every industry has its unsung heroes — but its when on top of the existing work theyre not acknowledged for, we want, or even demand, that information security professionals go even further PayPal, for example, declined to pay up via its bug bounty scheme for 17 year old Robert Kugler. I understand that its a frustrating experience knowing of a vulnerability that it should be seemingly trivial to fix, and yet nothing happens, but Ive also been on the side of writing up code and seeing how small changes can have significant ripple effects across a project. I was one of the many that misplaced their anger, and there are probably countless out there that didnt pick up on PayPals message that part of better disclosure is actually about not creating undue work for their security team, while also ensuring that people like Kugler get the recognition they deserve.

Classifications

industries
HealthTech
applications
No applications detected

AskAI Classifications

Labels
Cybersecurity Application Security Software Development

Linked Companies

Acunetix
$10M to $25M