You can just do what my university did, hire a small shell firm with 3 employees to hold all your data, and when it got hacked they just went bankrupt and we switched to a new shell firm with similar form and function.
Minimizes money usage and does not require any security investments
Problem is that most breaches are social engineering attacks where employees or customers are phished for their credentials or even to approve/install some malicious code. It's very hard for businesses to defend against this.
They can try:
* various education campaigns
* force users/customers to adopt passkeys or other phishing resistant mfa
* add various alarms and alerts for unusual activity, resulting in lockout
The problem is that even after adopting all of the above, it's still not too hard to breach virtually all companies, and there is massive user opposition to the last two.
augment_me · · focus · HN ↗
Minimizes money usage and does not require any security investments
louthy · · focus · HN ↗
carefree-bob · · focus · HN ↗
They can try:
* various education campaigns
* force users/customers to adopt passkeys or other phishing resistant mfa
* add various alarms and alerts for unusual activity, resulting in lockout
The problem is that even after adopting all of the above, it's still not too hard to breach virtually all companies, and there is massive user opposition to the last two.