Re: Security & Safety
imho, it’s mainly down to a couple of things
a) everyone wants a "one stop shop", so multiple different systems have to be integrated through APIs (Application Programme Interfaces) to allow data to flow/be converted to from systems, providing more complexity, and usually the more complex systems get, the harder it is to provide complete security (and it costs more for no tangible benefit, until you need it - see below); this also includes fail-over/resilient systems
b) businesses want everything to be more cost-effective/cheaper, and good IT Security is expensive, time-consuming, and often annoys users with the requirements/actions they have to follow to keep it secure, and like any insurance, people bitch about paying for something they don’t think they need (until they do)
c) related to b), companies want to save money by outsourcing, but often have a mindset that transfers responsibility for the system (and associated security) to the outsourcer, when if fact they still have the responsibility to ensure the system provides appropriate service and security
d) a reasonable amount of end-users fall for phishing emails - no matter how many times you tell them not to click on links, and that the IT Department would never ask for their password on an email, they still do, which gives the blackhats access to the systems
e)more and more of what we do every day is now online - the last 20 years, with the introduction of smartphones, tablets, and the associated Apps, allow much more opportunities for phishing/scamming
All of the above are from real-world scenarios I have been personally involved in…
__________________
Thank you for calling the Abyss.
If you have called to scream, please press 1 to be transferred to the Void, or press 2 to begin your stare.
If my post is in bold and this colour, it's a Moderator Request.
Last edited by Hugh; Today at 13:18.
|