Erik van Straten<p>EvS infosec myth#1: "Not my problem"</p><p><span class="h-card" translate="no"><a href="https://infosec.exchange/@varx" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>varx</span></a></span> wrote:<br>——<br>Some discussion of TOTP [...]<br>[...]<br>(I'd rather use a U2F Yubikey! Far, far, far safer. But IT won't enable that option. Fine. Not my problem.)<br>——<br>Thanks for sharing! Something is very wrong if that's your feeling.</p><p>Companies where one or more employees (were made to) believe that SECURITY IS NOT EVERYONE'S BUSINESS, are facing much bigger infosec challenges than organizations where everyone, starting at the top, KNOWS, and (team) leaders ENFORCE, that each and every person with access to job-related information bears a security responsibility.</p><p>Way too often the "BOFH's from IT" were ALSO assigned the task "to make and keep things secure" (or they decided themselves to grab that task, because nobody cared).</p><p>IMO it is a huge management failure to let this happen/continue. Worse, too often I've experienced board level managers stating "haha, not my probiem, IT already takes care of that, haha" when such matters were brought to their attention.</p><p>Although sometimes it is fine to make jokes about security, I wish management in particular would stop ridiculizing infosec. Security is not a joke.</p><p>——<br>Previous myth: Authentication, factors and impersonation: <a href="https://infosec.exchange/@ErikvanStraten/111991418581543444" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">infosec.exchange/@ErikvanStrat</span><span class="invisible">en/111991418581543444</span></a></p><p><a href="https://infosec.exchange/tags/notmyproblem" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>notmyproblem</span></a> <a href="https://infosec.exchange/tags/myth" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>myth</span></a> <a href="https://infosec.exchange/tags/myths" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>myths</span></a> <a href="https://infosec.exchange/tags/BOFH" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BOFH</span></a> <a href="https://infosec.exchange/tags/responsibilities" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>responsibilities</span></a> <a href="https://infosec.exchange/tags/management" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>management</span></a> <a href="https://infosec.exchange/tags/board" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>board</span></a></p>