this post was submitted on 02 Sep 2024
32 points (92.1% liked)

Cybersecurity

5646 readers
66 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !cybersecurity@lemmy.capebreton.social !securitynews@infosec.pub !netsec@links.hackliberty.org !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 1 year ago
MODERATORS
 

Link goes to https://tfl.gov.uk/campaign/cyber-security-incident?cid=email_FINAL_TFLU369_Security_update-CTA_text_website

Got this email today. It seems someone is getting fired in the IT department...

you are viewing a single comment's thread
view the rest of the comments
[–] lando55@lemmy.world 4 points 2 months ago

Make sure you back up all email and IM communications and don't rely exclusively on server-side retention (provided your DLP policy allows for this.)

If it ever comes down to it and you are facing the possibility of being the scapegoat for a security incident, your attorney can review the relevant policy and determine whether or not and when you can use these to demonstrate that you communicated your concerns to management and stakeholders.

Depending on who you reached out to and who was included, absence of a response to your various methods of communication can be used to establish acceptance of risk by leadership.