Often boils down to end users who are anti-security and get their way more times than not.
I worked for a company where the IT team was more security oriented than the InfoSec team because they were just trying to make end users happy.
I recall them arguing in favor of a longer auth window for confluence, but if you got someone's computer or got into their computer, that auth would last for like 30 days and didn't need a daily update. A lot of physical controls around the device, but if you're actively in it, it's yours.
Won't change until CEOs stand up for cybersecurity.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.