David Spark
π€ SpeakerAppearances Over Time
Podcast Appearances
Comes from Kerry Johnson of Fishbusters.
And here's the scenario.
Two scenarios, I'm sorry.
You have metrics that show improvement, but you cannot prove why.
So it's showing something's good, but you have no clue how it happened.
Or you have metrics that show no improvement, but you know you have had improvement.
Which one's worse?
But couldn't this be the Mr. Magoo version of cybersecurity where you're avoiding all the problems as everything's crashing around you?
Okay, interesting argument there.
But this is assuming that the metrics are the problem.
Okay.
Danny, you don't have to necessarily accept his theory that the metrics are the problem to start with.
What do you think here?
Again, he thinks the first one's worth metrics that show improvement but can't prove why.
He thinks that's the worst scenario to be in versus metrics that show no improvement.
But you know they're right.
You know you're improving.
Are you making an argument that you could survive without metrics if you just know you have the right controls?
That's a good argument right there.
Please, enough, no, more.