The original post: /r/cybersecurity by /u/uneasy_urchin on 2024-07-04 08:38:05.

tl;dr: C-suite won’t prioritize table stakes security for the business, is there any recourse? Maybe complain to the board?

While I’ve learned to appreciate that security isn’t top of mind for a small business, when I try to push table stakes security practices, the C-suite won’t buy in and has even cut down things like mandatory antivirus, MDM, PII security, not using personal laptops, etc

Shouldn’t C-suite prioritize some level of security in line with their fiduciary responsibility?