Hacker News new | past | comments | ask | show | jobs | submit login

> empowering someone to say "Not until you do all this unwelcome work to implement it to the standards the company has chosen"

It has not been my experience that this is what most IT security orgs say in practice.

It's usually "No, unless we do it" followed by "And we don't have time to do it."

Which is fundamentally because they're a cost center, and typically staffed like one.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: