Single post
I‘m busy preparing lectures (and will be for the rest of the term), both for foundations of cyber security and, more specialized, #incidentresponse & incident management. Last week I was wondering which recent motivational examples to use, this weekend it’s hard to decide between the oddly specific KiteWorks warning and yet another round of Citrix quality solutions. I’ll probably just take both and link them with their respective past issues and (exemplary) their impact in terms of resulting compromises. Would love to see numbers on total costs resulting from auch a single supply chain issue, but I doubt there’s more than more or less (un)realistic estimates, if any.
Full-cost pricing of deciding for a product from a vendor with a non-impressive security track record. „Customers similar to you, who bought this product, had 5y aggregated follow-up costs from resulting incidents and remediation of x k€.“ Now that would be market transparency.