As security practitioners, one of the common misconceptions most of us have is that the alerts we receive about application or system vulnerabilities are really only of interest and use to us, and maybe to the extended IT team.
Now I’m not advocating providing your CEO with detailed alerts about every application vulnerability out there, but there are specific use cases that can inform the directives of other internal teams, not to mention our ability to provide a high level summary of what the threat landscape looked like in the prior period to these business unit leaders who are likely involved in risk management tradeoffs.
For example, if you receive alerts about possible phishing sites exploiting your brand or campaigns against your customer base, as a security practitioner the common viewpoint has been “well it’s the end-user’s system and choice.” But give that same information to your...