Yes, the shared responsibility model long predates the cloud, but the cloud era is proving that true sharing of responsibility is more complicated than it seems, leaving enterprises less secure as a result.

  • @stringere
    link
    English
    211 days ago

    So much of my job in security was getting people to sign off on risks they would not patch.

    • @[email protected]
      link
      fedilink
      English
      211 days ago

      Yeah we did security notices based on customers doing stupid shit, and got yelled at for “annoying” them with an email every week or two, depending on when the reports we ingested were turned into notifications.

      So many people screeching about spamming them, and harassing them, and how this was bullshit and they never had this problem with other PaaS platforms.

      …until, of course, oopsie their shit was hacked, and NOW it’s my fault we didn’t warn them enough.

      I am never working for THE CLOUD ever again, lol.