I’ve long felt that if the software engineering world realized:
1) how accessible cybersecurity actually is in terms of an understanding of what matters in practice
2) how dreadfully behind the cybersecurity industry is in terms of basic practices, understanding of systems, etc.
immense outrage would foment at large, and perhaps real change demanded
there’s a reason why infosec pros present the problems as arcane and inaccessible, why they protect their own and knit tight cliques…