Co-authored by Jason Barnes and John Khotsyphom
Some of us in the security community took a step backward last week in our ability to deal with the crisis involving Okta. Instead of exercising well-thought-out and practiced contingency plans to objectively assess risk, many individuals took a trolling posture on social media. The reaction was neither professional nor conducive to our mission as defenders against threat actors seeking to do us harm. We should take a collective look in the mirror and reconsider our attitudes and reactions when one of our partners endures a crisis even when communications are questionable.
Understandably, leaders and practitioners are under intense pressure any time an Okta, SolarWinds, or Target hits the news. We scramble for answers. As humans, that is our nature. But fixing the blame on Okta via social media based on some screenshots proves some in the community have far more improvements to make than we imagined. Some of us seem to have reverted back to the hope that technology will save us all, ignoring the imperative of critical thought required to effectively defend an enterprise.