One area commonly overlooked (by defenders, but not by attackers) is identity sync infrastructure. If you harden your AD but don't do this, you are wasting your time.
The fishbowl distorts perception, but in a way which confirms our biases. How does this hurt us in security and transformation, and what should we do about it?
Along with "people are the weakest link", this phrase has been shaping unhealthy cultures in security for years. It's time to stop saying it, and here's why.
What voice do you want to have in the world? Never, ever give yourself so fully to what you're doing now that it undermines your development into who you want to become.
It's simple, but it's not easy: if you change the tech but not the culture, none of the gains you realize in the short term will be sustainable in the long term.
Because DevOps has effectively joined the Operational and Dev domains, it introduces security dependencies which neither domain had to consider before.