| ▲ | dwaltrip 4 hours ago | ||||||||||||||||
The saying that stuck with me was "defenders have to be right 100% of the time, while attackers only have to be right once". You are suggesting this isn't correct? > a defender gets to pick the surface area What do you mean? You don't pick what you need to defend. Unless you choose not to build a feature. But that's a product design choice... Not a cybersecurity strategy. | |||||||||||||||||
| ▲ | sudosysgen 3 hours ago | parent [-] | ||||||||||||||||
> "defenders have to be right 100% of the time, while attackers only have to be right once" If you have an adaptive system that can react to attacks flexible (say, your own AI agent), then no, that's not correct. It is correct in the classical conception of cybersecurity where the defender is basically static. | |||||||||||||||||
| |||||||||||||||||