Comment by chii
8 hours ago
> pay their fortinet renewal and check "Security: Done!" without any kind of analysis.
there exists objective measure of security, which would be some sort of hacks/breaches per period. If customers cared about it (and i assume they do), they would choose companies that have less breaches over others with higher counts, normalized on cost differences.
Therefore, if companies didnt actually try to fix their security but instead just checked boxes, they would get breached more often, resulting in customer losses.
The only thing stopping this from actually occurring is the lack of mandatory regulatory reporting of it. So this is where gov't needs to step in and mandate disclosure etc.
Breaches don’t happen often enough to be a useful metric. Most smaller companies are never breached, despite having basically zero security.
The number of breaches would have to be honestly reported for that idea to work. None of the security firms would want to do that; least of all the lowest quartile of them.
> would have to be honestly reported for that idea to work.
and why does this idea work for accounting audits, but not for security? As long as regulations for companies exist, they would necessarily follow it, and this would lead to reporting of security breaches just like companies would have to report their financials honestly.
Accounting is generally both easier to do correctly and easier to verify than security practices, unfortunately