Can’t make the wrong people look bad.

  • chiliedogg@lemmy.world
    link
    fedilink
    arrow-up
    1
    ·
    9 days ago

    The point is to have multiple layers of protection. With users who are vigilant it’s less likely for something to get through even if IT fails to filter out an attack.

    Think of it like gun safety. Even though a gun is unloaded you don’t aim it at someone.

    • raspberriesareyummy@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      9 days ago

      No argument there - training cybersecurity awareness is fine, but singling users for clicking on a link alone is moronic. Most security fuckups in my experience result from stupid IT policies and rarely do the responsible admins / managers ever get flak for their fuckups.

      • chiliedogg@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        9 days ago

        In my experience (I’m not in IT), the IT folks only get recognized for fuckups. When they do things right nobody notices and thinks they’re a waste of money, resulting in the company cutting back on their budget then freaking out when they’re not equipped to do their job and something goes wrong.

        • raspberriesareyummy@lemmy.world
          link
          fedilink
          arrow-up
          1
          ·
          9 days ago

          Ok let me rephrase: IT management never gets the flak they often deserve.

          But also there’s a distinction to be made between competent IT and IT service contracts where the contract officers are corrupt and/or incompetent and then the service is awful as a whole.