Is your organisation reasonable?

Are your coworkers reasonable about cybersecurity?

In your software company…

--- primary_color: "#77b6ea" secondary_color: lightgray text_color: black shuffle_questions: false show_hint: false shuffle_answers: false --- ## Has a C-Suite executive questioned the value of the security team's projects in the last 3 months? 1. [ ] Yes 1. [x] No ## Has the CEO criticised the security team for not bringing in enough customers or helping with marketing? 1. [ ] Yes 1. [x] No ## Has the CEO told the security compliance specialists that their jobs are "useless bullshit"? 1. [ ] Yes 1. [x] No ## Has the CTO asked about the possibility of removing the EDR agent from employees' workstations to reduce CPU & RAM usage? 1. [ ] Yes 1. [x] No ## Has the CTO suggested moving from an enterprise grade IDP to a self-hosted OpenLDAP server to reduce costs? 1. [ ] Yes 1. [x] No ## Has the CTO criticised the security team for not putting in enough pull requests on the company's main software products? 1. [ ] Yes 1. [x] No ## Has the CTO suggested replacing the company's SIEM with "a cronjob that runs grep commands"? 1. [ ] Yes 1. [x] No ## Has the CTO suggested replacing the MDM with a "cronjob that calls some scripts"? 1. [ ] Yes 1. [x] No ## Has the CFO suggested merging security with IT support because "both are support functions"? 1. [ ] Yes 1. [x] No ## Have engineers suggested having the security team fix vulnerabilities in their systems? 1. [ ] Yes 1. [x] No
 

What’s your score?

  • 🔟, 9️⃣ or 8️⃣ → You’re in reasonable organisation. Hang tight and don’t let go.
  • 7️⃣ or 6️⃣ → Your average organisation, probably.
  • 5️⃣ or 4️⃣ → Now is the time to start looking for another job.
  • < 4️⃣ → It’s impressive that org is paying someone to do security.