Listen "EP 105 : SDP 5 Work Factor "
Episode Synopsis
https://www.yourcyberpath.com/105/
In this episode, we are returning to the Security Design Principles series, this time with Work Factor.
Work factor refers to how much work it’s going to take an adversary to attack your assets and succeed in doing so. This is coming directly from the world of physical security that was imported into the cybersecurity realm.
What you need to understand is you don’t need perfect security. You don’t have to create an impregnable system (if that even existed) to be able to protect yourself from most dangers. You just need to become a more difficult target than other organizations. And this is where work factor comes in.
While you need to make it difficult for attackers to consider you as a target, you also need to make sure you are not spending too much time and money doing so, to the point where you are building a $1000 fence to protect a $100 horse. Balancing security and business value is a critical aspect when planning out your security posture.
Another important aspect that a lot of people usually ignore is the anticipated resources available to the attacker. Understanding how your adversary works and what kind of resources they might be able to utilize can help you determine how much protection you need to put in.
What You’ll Learn
● What is Work Factor?
● Do you need perfect security?
● How do you value how much protection you need?
● What kind of attacks endanger small to mid-sized businesses?
Relevant Websites For This Episode
● Your Cyber Path
● IRRESISTIBLE: How to Land Your Dream Cybersecurity Position
● The Cyber Risk Management Podcast
Other Relevant Episodes
● Episode 103 - SDP 4: Compromise Recording
● Episode 98 - SDP 2: Psychological Acceptability
● Episode 101 - SDP 3: Economy of Mechanism
More episodes of the podcast Your Cyber Path: How to Get Your Dream Cybersecurity Job
EP 116 - What's next after season 2?
16/02/2024
EP 115 - SDP 10: Separation of Privileges
06/02/2024
EP 114 - NIST CSF Versus The Top 18
19/01/2024
EP 113 - SDP 9 Least common Mechanism
05/01/2024
EP 112 - Listeners' Questions
22/12/2023
EP 111: SDP 8 Open Design
08/12/2023
EP 109: SDP 7: Complete Mediation
10/11/2023
Episode 108: Self-Care
27/10/2023
EP 107: SDP 6: Fail-safe Defaults
13/10/2023
ZARZA We are Zarza, the prestigious firm behind major projects in information technology.