Loading…
AtlSecCon 2022 has ended
Friday, April 8 • 16:00 - 17:00
Closing Keynote - Security Debt, Running with Scissors

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Security debt, is “the accumulation of the patches missed, the risks accepted, and the configurations misapplied,” is a serious and common problem for many organizations, especially with the move to cloud com putting and rise of IoT. Part of the problem is that, while organizations might accept the risks they encounter, they often neglect to review them or make a plan for the future, and that risk is compounded when patches are passed from person-to-person through staff changes and/or employee churn. However, it doesn’t have to be this way - to track and address security debt, organizations must develop and implement defined, repeatable processes. They should look to strategies like the zero-trust model, trust but verify, sanitation of inputs and outputs, and of course, make sure to execute patches instead of pushing it onto the next person.

Security debt occurs when a technological debt has manifested as a security issue and the associated risks are accepted but not addressed. The longer organizations wait to address risks, the harder it is to address them to eliminate debt, organizations should create defined and repeatable processes with plans for action.

Speakers
avatar for Dave Lewis

Dave Lewis

Dave has 30 years of industry experience. He has extensive experience in IT security operations and management. Dave is the Founder and Managing Director for Liquidmatrix.io. Dave has worked at companies such as Akamai, IBM, Duo Security, Cisco and AMD. He is the founder of the security... Read More →


Friday April 8, 2022 16:00 - 17:00 ADT
Track 1 - Ballroom