← Back to context

Comment by hnlmorg

5 hours ago

That’s not been my experience at all when working in DevSecOps.

What actually happens in organisations is they define risks and then sign off what risks they’re willing to accept.

Any business that looks at security as a binary value is running their business wrong. Period.

And yes, people really are that lazy. There are countless studies that have shown just how lazy people are. It’s why shadow IT is a big problem in many orgs. And why consumers are constantly taken advantage of

I think that's separate. You can define an obvious risk e.g. "we may be infected with ransomware" and the security spending / productivity costs to stop it are still unlimited because nobody knows how to solve it.