I don't think so -- people don't think of security when they think CRUD applications. What they do think about is outsourcing it to a team of 10 people that will work for $1/day on it. And then they get what they pay for.
Hire competent programmers to do important tasks and you won't be disappointed. The problem is that there aren't very many competent programmers.
I don't intend to imply that security products/services will address the problems inherent to badly architected/implemented IT systems.
Just that we can expect to see an upswing in expenditures for these sorts of tack-on products/services from CIOs seeking silver-bullet assurances from those naive about their corporate infrastructures' security exposure, or blame deflection, from those savvy about the same.
In other words, it might be a good time to start a white-hat IT security audit tools/services company.
But the targets are usually not so prominent. As higher profile attacks occur, people in related companies will start to worry if they're next, and start a spending frenzy to try and prevent it (it is, of course, doubtful any product they buy will do any good).
Comments
HB Gary... Sony... Fox/X-Factor... others/more to come...
Prediction: Web security products/services will be the hot ticket for the rest of 2011-2012.
I don't think so -- people don't think of security when they think CRUD applications. What they do think about is outsourcing it to a team of 10 people that will work for $1/day on it. And then they get what they pay for.
Hire competent programmers to do important tasks and you won't be disappointed. The problem is that there aren't very many competent programmers.
I don't intend to imply that security products/services will address the problems inherent to badly architected/implemented IT systems.
Just that we can expect to see an upswing in expenditures for these sorts of tack-on products/services from CIOs seeking silver-bullet assurances from those naive about their corporate infrastructures' security exposure, or blame deflection, from those savvy about the same.
In other words, it might be a good time to start a white-hat IT security audit tools/services company.
People get pwned, dbs get dumped, and sites get defaced e'eryday. This is nothing new.
But the targets are usually not so prominent. As higher profile attacks occur, people in related companies will start to worry if they're next, and start a spending frenzy to try and prevent it (it is, of course, doubtful any product they buy will do any good).