kaaswe<p>The good thing working with security is I don’t have to evolve in my role, the same slides I presented 20+ years ago still are valid…</p><p>That was irony, big time, sadly but true</p><p>Basic security hygiene is still left out in every major company, why?</p><p>One dangerous trend is that before containers, devops order a server from server team, network team assigned VLAN and IP, firewall team opening what was required as a minimum. </p><p>Now, devops team controls the tenant deploys hundreds of containers in seconds, allowing inbound Internet access with no other security than Microsoft components (if we are in Azure) and we all know that standard components are Not enough security. </p><p>This is a major problem in several ways<br>1. Too much privledge and authorities in one person, often with not enough knowledge <br>2. Lack of Asset management, after a while no one knows how many functions exists where, what they do, or how they interact.<br>3. Excessive energy consumption, despite this was one selling point, </p><p>But there are light in the tunnel, we can regain control. The tools are there, it’s “only” a matter of structure and process, bringing me back to the start of this article and what my slides contained and still contains.</p><p>Keep it up out there, and don’t give up even when it feels hopeless </p><p><a href="https://swecyb.com/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cybersecurity</span></a> <a href="https://swecyb.com/tags/grc" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>grc</span></a></p>