It’s the latter. They actually get thrown all sorts of money in part because they say they need tools. The standard corporate load has at least 3 patch management software suites, two ‘cybersecurity monitoring solutions’, three anti-malware software products.
Sometimes their automation fails and this was one of those situations where his and at least in our department only his where their automation failed for some reason or another. So they fall back to a sketchy looking exe on some random web server they don’t even bother to enable https on (they also provision root CAs, so it’s not like it would be a challenge for them to have https on an internal domain).
They aren’t very good, but they are doing things perfectly right; so long as the one deciding what is right is the sales reps of the software they use.
It’s the latter. They actually get thrown all sorts of money in part because they say they need tools. The standard corporate load has at least 3 patch management software suites, two ‘cybersecurity monitoring solutions’, three anti-malware software products.
Sometimes their automation fails and this was one of those situations where his and at least in our department only his where their automation failed for some reason or another. So they fall back to a sketchy looking exe on some random web server they don’t even bother to enable https on (they also provision root CAs, so it’s not like it would be a challenge for them to have https on an internal domain).
They aren’t very good, but they are doing things perfectly right; so long as the one deciding what is right is the sales reps of the software they use.