Comment by andrewflnr
2 days ago
I worked for a bit in an org that was agglomerated into CISA. Let's just say PKI integration continues to be infeasibly difficult for most projects, especially small ones. (And cost is very, very much a concern. Be honest, do you want your taxes going into a project where it isn't?)
In the context of secrets getting lost with access to a number of sensitive systems, yes, I do think they could spend maybe a bit more money.
"A bit more" is not comparable to "money is no concern". Either way, no amount of money can replace good judgment, which is what was actually lacking: if nothing else, judgment in who to hire.