@inthehands @randomgeek I often tell people at work that my job here as an infosec practitioner is basically 3 things. Identifying risk, Presenting risk to the business, and helping you understand the effects of the risk. Everything else is someone else's decision, and businesses are not minor risk adverse as long as the reward exceeds the punishment, which makes the solution so blindly obvious...