Security - Just Another Risk
I made a conscious decision to move away from full-time information security work. I retain an interest, and try to keep up with developments, but I don’t want to be “the security guy.” There are several reasons for it, but a large part is due to the hype, the bullshit, and general inability for the security industry to act like grown-ups.
The most frustrating part was the inability to properly classify risk. Robert Graham put this eloquently here:
Infosec isn’t a real profession. Among the things missing is proper “risk analysis”. Instead of quantifying risk, we treat it as an absolute. Risk is binary, either there is risk or there isn’t. We respond to risk emotionally rather than rationally, claiming all risk needs to be removed. This is why nobody listens to us. Business leaders quantify and prioritize risk, but we don’t, so our useless advice is ignored.
Security folk often forget that they are just another risk. Yes, it’s a risk shipping the product with that bug. But not shipping at all might be a larger risk to the business. Even complete data breach may or may not be catastrophic to the business - RSA is still around.
The behaviour of the ‘researchers’ mentioned in the post hardly helps advance the image of the industry either. That’s before we get into the ‘conferences’ with lock-picking competitions & martial arts comparisons.
Do I believe security matters? Yes, definitely. Would I work in security again? Maybe. But not right now.