
The security industry has an accountability crisis. It’s time to talk about it, then fix it. Whenever a massive cyber attack occurs inevitably a chorus of voices rises to blame the victims. Β WannaCry on 5/12 and Petya on 6/27 yet again kicked off the familiar refrains of:
βIf users didnβt click on stuff they shouldnβtβ¦.β
βIf they patched they wouldnβt be downβ¦.β
βThis is what happens when security isnβt a priorityβ¦.β
βNow maybe someone will care about securityβ¦β
I have yet to meet a single user that clicked a malicious link intentionally β beyond security researchers and malware analysts that is. I have yet to meet anyone that delights in not patching as a badge of honor. There are great reasons not to patch, and terrible reasons not to patch. As always context and situation matter.
…
http://blogs.forrester.com/jeff_pollard/17-06-27-victim_blaming_wont_stop_global_ransomware_attacks
Source: DRJ New feed





















