Politicians in IT
We’ve all seen it. Non-technical people making technical decisions. Be it the CFO of the company pulling the plug on password enforcement policies or an uninformed CIO making the proclamation that “we don’t need to be PCI compliant!”
As technology is a new a business in the world of business, there are a lot of uninformed people who look to these snake oil salesmen for direction within their company. There aren’t many laws when it comes to how the business of IT should be done – and most people only know IT as the guy who fixes their computer when their email won’t load. Unfortunately, most people only see IT as the group of nerds that require their passwords to be changed, or won’t allow them to install Candy Crush at work like on their home computer, or blocks Facebook at the firewall.
These Politicians use the masses to support their agenda and grow personally – most of the time spreading false “truths” to their peers. As long as they aren’t bit too hard, they generally continue to fatten their wallet, pad their resume, and convince the masses they’re what’s right in IT.
Unfortunately, when these companies do finally get bit by ransomware, copyright violations, or a regulatory compliance fine via PCI, HIPAA, or Sarbanes–Oxley; these sneaky folks are quick to point out the incompetence of their subordinates in an attempt to salvage their curated reputation. Regardless of the success of their ruse, it is pretty much a guarantee these folks will be moving on to the next town to sell their snake oil to the next unsuspecting crowd.
When people who truly know IT and CyberSecurity speak up, there is a reason why they say “IT is a lot like the wild west,” – it truly is.