In 2001, the SANS Institute published a landmark list of the ten most common cybersecurity mistakes made by individuals and organizations. Twenty-five years later, nine of those ten problems remain largely unsolved. This is not a technical mystery or a resource problem. It is the predictable result of three interlocking failures:
• A broken economic incentive structure that shifts the cost of insecurity onto victims rather than those best positioned to fix it.
• A legal framework built around End User License Agreements (EULAs) that systematically shield software vendors from liability for insecure products.
• An industry that has found it more profitable to treat symptoms than to cure the underlying diseases.
The cybersecurity industry is more analogous to a pharmaceutical industry that profits from managing chronic conditions than to the sanitation industry, which profits from eliminating disease vectors. Root-cause solutions commoditize or destroy adjacent revenue streams.
These powerpoint slides summarize each of the 4 parts of the series.
For the full text version of the series, go to https://vtrandy.substack.com/p/cybersecuritys-original-sin-executive
Powered by GoDaddy Website Builder