Discussion about this post

User's avatar
Postern's avatar

The attacker-economics framing maps onto the other end of company size too, just inverted. Your three recommendations all assume an existing security function to build on, threat-informed defense, telemetry correlation, tested incident response. Early startupscompany doesn't have that scaffolding yet, and 'obscurity is dead' means something different for them: they were never using obscurity as a strategy, they were just genuinely too small to be worth an attacker's time. That protection is quietly disappearing too, for the exact same reason you describe, reconnaissance cost approaching zero. The prioritization problem you're describing at enterprise scale is the same shape of problem at four-person-company scale, just with a much smaller resource pool and no existing function to lean on.

Josh Woodruff's avatar

The obscurity point held up in an odd way this summer. Wiz pointed an agent at one of Snowflake's public code projects and turned a five-day-old bug into a working key, no attacker required, which is your economics argument with a receipt. On the defender's information edge, most teams still can't say what a single service account reaches, so that edge stays on paper until somebody owns the asset map. Which of your three do teams actually fund first?

19 more comments...

No posts

Ready for more?