Ask HN: Why are there so many security breaches?
Is there any common reason behind the breaches? Is it the technology that is not mature enough or is it the cost cutting that results in breaches? Is it more about people behaviour or corporate decisions?
10 comments
[ 4.7 ms ] story [ 45.7 ms ] threadThis is the crux of the entire information security industry.
> Is it more about people behaviour or corporate decisions?
Yes. A small number of people directly decide what corporations do. A corporation's activity is usually carried out by a larger number of people, who have some, less direct, control over the corporate decision making. Orders of magnitude more people are affected by those decisions and have extremely limited and indirect means of influencing them.
The goals and motivations of capital will never be truly aligned with that of the individual/people/society.
Less bankers. Tax capital.
For a transaction I had recently to install an ID app that then wanted to take photos of my face and my ID card. I had no recourse to another method nor can I know where and how these data will be stored. This data, collected in the name of increased security and trust, has now become part of the global data trove, making it a little bit more attractive to commit online crimes. Therefore, the party that forced me to undergo the procedure has, by their action, made the world at large and online transactions in particular a little less secure and trustworthy.
Optimism bias is also a thing. People assume bad things won't happen to them. (This is a psychological phenomenon not just an IT thing). So if you're an exec, you could advocate for spending the money or you could just pocket your bonus for cutting costs and go "pfft nothing is going to happen".
And there's the old "if it's cheaper to deal with breaches if they happen than to pay security staff most places are just going to assume nothing bad will happen and deal with the cost if it ever comes up".
This is the crux of the issue. Organizations have no incentive to invest in good security because they don't see any negative ROI in the now. It's amazing just how much they invest after the fact of a breach. They have to assume they will be breached at some point and have all the necessary operational security in place when they do get breached to limit the blast radius.
Opsec is usually an infosec term, but businesses do opsec all the time to protect assets and inventories, only it's not called opsec, just 'standard practice', or a 'business plan' or other terms, but really it's opsec under the hood. Also, opsec is not new, it's something long practiced by organizations and companies across the world.