Insight #1
There will never be an environment that is totally, 100% secure — at least, not one that provides any functionality. With that in mind, examine what security control layers you can and should add to get it as close as possible.
Insight #2
I’ve seen a lot about how bad false negatives are, but the reality is there are 80+ Common Vulnerabilities and Exposures (CVEs) released per day. There will ALWAYS be false negatives. False positives are a more detrimental aspect to any security program, as they create angst between security and developers and result in wasted time spent on “fixing.”
Insight #3
The Securities and Exchange Commission (SEC) is really trying to move the public sector in cybersecurity transparency and accountability. From sending Wells notices to SolarWinds executives — i.e., formal notifications that it’s considering bringing enforcement action — to implementing new requirements in breach reporting. I look forward to even more from the Commission in the near future.