cybersecurity is broken

Поделиться
HTML-код
  • Опубликовано: 15 ноя 2024

Комментарии • 56

  • @ichibot-app
    @ichibot-app Месяц назад +14

    "$10 trillion" - do you realise that's 10% of all transactions that occur in the entire world?

    • @CybersecPat
      @CybersecPat  Месяц назад +9

      Yeah I misspoke, that is the total cost of breaches not the net profit. I’m going to pin your comment so that others can see my mistake. I doing want to mislead people

    • @ichibot-app
      @ichibot-app Месяц назад +1

      @@CybersecPat ok even so, how is the cost 10% of global GDP?

    • @PantaBell
      @PantaBell Месяц назад

      @@ichibot-app The salaries of all people involved in "defending" plus and approximation of the money not being made by the businesses. It is not 10 trillion in a bank account

    • @Not26416
      @Not26416 Месяц назад

      @@ichibot-app just shut it already!

  • @angrydachshund
    @angrydachshund Месяц назад +19

    The demand must come from consumers. Right now, every software VP is telling his devs, "We need these 19 new features and they need to ship last week." And the devs say, "But what about security?" And the VP doesn't care because nobody is willing to pay for that.

  • @CybersecPat
    @CybersecPat  Месяц назад +15

    Thanks for listening to me rant for 20 minutes, you're a real one.

  • @natevsdawrld
    @natevsdawrld Месяц назад +7

    pretty much everything going to the cloud makes it a bigger and easier target

  • @iZlick
    @iZlick Месяц назад +3

    Good summary, adding my rant as a different perspective you may want to consider: Education is good and all, but human error covers more than just social engineering (such as phishing). Misconfigurations and cumbersome or complicated processes are large contributors to why the human element is such an issue; it is not exclusively that a small minority of people don't care. On top of training we need to make it easier to do the right thing and harder to do the wrong thing. Change control to minimise misconfigurations, secure-by-default/design technology for day-to-day business, and making security controls transparent to the point where personnel are unaware of how many security layers they are going through. Examples are password policies to direct users towards stronger passwords; default access control configurations to stop users creating company-wide Sharepoint sites with sensitive information; data-leak prevention to stop users from moving sensitive documents outside of the orginisation; for cloud, pre-configured hardened images, centrally managed WAF/VPC/Security Groups - you get the point.

    • @CybersecPat
      @CybersecPat  Месяц назад

      You said it better than I! Appreciate you sharing your thoughts.

  • @Liriq
    @Liriq Месяц назад +7

    Cybersecurity is an economics (incentives) problem, not a technical or technological problem. IoT can be done securely. Cloud can be done securely. We know how to do security. Consumers don't value security. Normal people cannot see the value in security, especially not against the value of some shiny doohickey or dumb stunt. Security has a PR problem.

    • @CybersecPat
      @CybersecPat  Месяц назад +2

      damn right on target

    • @XtremuZ
      @XtremuZ Месяц назад +1

      people have no idea what they should worry about, most have no tech literacy.. companies MUST have

  • @naesone2653
    @naesone2653 Месяц назад

    I think maybe there just needs to me better pay for entry level jobs and even more for senior ones, that would discourage the financial aspect of wanting to pursue cybercrime activities, but it’s probably much. More complex than that…

  • @RichPober
    @RichPober Месяц назад +5

    Great subject that no one is addressing.

    • @CybersecPat
      @CybersecPat  Месяц назад +3

      Thank you for the kind words! I'm hoping to raise awareness of these issues in an easy to understand manner that is interesting for both novices and experienced professionals. I appreciate you stopping by and for your feedback

    • @JanasV
      @JanasV Месяц назад

      Everyone is addressing it. I don't know about US, but european countries focus on prevention, workplaces give employees secondary phones with 2FA already set up, VPN's set up, rules explained, and you are informed of your role in cybersecurity. We even receive fake phishing emails so that the cybersecurity company that works with our company can see if we fall for it, if we need additional training.

    • @justinh489
      @justinh489 Месяц назад

      I was just about to comment this. Really great topic.

  • @WellBeSerious12
    @WellBeSerious12 Месяц назад

    Simply: Hoomon dum dum.
    Complex: It's complicated. Watch the video above for basics.

  • @JF-if8jh
    @JF-if8jh Месяц назад

    Entry level security jobs pay too well there’s no incentive for a SOC Analyst 1 to become a Network Security Architect if they aren’t obsessively passionate about security.
    My company has too many SOC Analyst III but Senior, Engineer and Architect roles stay open for months on end because the analysts don’t want to do training. They’re comfortable.

  • @morethanmello
    @morethanmello Месяц назад

    Based on your experience, could you critique my current plan. I'm currently going to wgu for cyber. I've been practing fundamentals and doing labs. While going to school I am getting my az-900 and aws. Should take me a year. Would you recommend this path for a role like cloud support or soc1?
    Thank you

    • @CybersecPat
      @CybersecPat  Месяц назад +1

      I think that is a solid plan! If you can land a SOC position that'd be best

  • @ajpresents5317
    @ajpresents5317 Месяц назад +2

    You are awesome with your explanation 👍❤🎉

  • @actualBIAS
    @actualBIAS Месяц назад

    Well, this is the problem with money. People don't want to invest into cybersecurity and clean code. We have intentionally made complex systems where memory leaks are all over the place and it's a real playground for people who are looking for them.

  • @cataclysmcrew
    @cataclysmcrew Месяц назад

    Thanks Pat, you earned a new subscriber. I'm currently in an AS program for cyber security. Opinions like yours are helping me tighten my focus to an applicable discipline. Also encouraging me to participate in the NCL this season, so thanks!

    • @CybersecPat
      @CybersecPat  Месяц назад

      Thanks so much! Best of luck with your journey, I’m sure you’re going to absolutely slay!

  • @cheyssentaylor
    @cheyssentaylor Месяц назад +2

    Nobody looks at the open source policy problem. You can leave the entire code laying around on the internet for everyone & anyone to mess with

    • @XtremuZ
      @XtremuZ Месяц назад +1

      that's honestly a problem that security personnel look at open source as unproblematic.. geez

    • @thealligator6187
      @thealligator6187 Месяц назад

      Security by obscurity isn't working either and there's no middle ground at the moment

    • @johndoe1274
      @johndoe1274 Месяц назад

      If your codebase relies on not being seen for security, it's not secure.

    • @cheyssentaylor
      @cheyssentaylor Месяц назад

      @@johndoe1274 but doesn't these licenses force developers to release their full code of every version any software ?

    • @johndoe1274
      @johndoe1274 Месяц назад

      @@cheyssentaylor Can you state what you said any clearer? I don't understand what you're getting at.
      Open source means anyone can view it and it can be forked into another repository. If your code is not seen then more people will not try to break it/hack it, hence it's less secure.

  • @Jignjip
    @Jignjip Месяц назад

    Really like your take on the problems. It really is true that it can be hard getting into cyber security.

    • @CybersecPat
      @CybersecPat  Месяц назад +1

      It is harder than it should be. I think we’ve got many talented people who’d love to get into it, but there just aren’t enough entry level positions.

  • @CamMcLain-e8r
    @CamMcLain-e8r Месяц назад

    Good video. Interesting. Thanks for making it

  • @Elsag_GeliNakh
    @Elsag_GeliNakh Месяц назад

    Yes, that's exactly it, you nailed it, mate👍

  • @motazlabidi2623
    @motazlabidi2623 Месяц назад

    U gained a fallower my freind keep up the good work

    • @CybersecPat
      @CybersecPat  Месяц назад

      Thanks! I hope to make more videos you enjoy in the future :D

  • @Sasquatchbones
    @Sasquatchbones Месяц назад

    Sounds like job security 😊

  • @filipemecenas
    @filipemecenas Месяц назад

    Yeah

  • @boomknight1015
    @boomknight1015 Месяц назад

    16:00 I'm getting into cyber sec and my plan in to pass the basics that I need to show I can pass a test, then to plot out making a network, test it till I think it's ready and make it a honey pot to actively let it be attacked, or maybe make a CTF for a really bored red team to go for it, with consent.
    How ever yes, you wont be hired if you just pass some tests because they made it vary clear, you understand it and the best way to show it, is to make a network and defend it. Sadly that's what I see as the bare minimum, due to most places not wanting to train people, so you have to do it yourself. Which is not easy, to be honest.

    • @boomknight1015
      @boomknight1015 Месяц назад

      Yes I'm aware setting up a net work and fire wall and defending it is vary different then having to deal with unprotected networks. How ever that's why no trust is a thing that is tossed at me so much in the stuff I'm working on test wise. To put up so many internal gates, the damage done will hopefully be limited.

    • @CybersecPat
      @CybersecPat  Месяц назад

      Reminds me of my job hunting strategy. I make some automation involving the tech in the job listing, then I give a live demo of that automation in the job interview. Makes you stand out and more memorable.