OWASP Speaker Calls Traditional Risk Management a Waste of Time
At the OWASP Global AppSec conference, cybersecurity expert Adam Shostack criticized traditional risk management models that rely on multiplying likelihood by impact, calling them unreliable and counterproductive. He argued that most organizations lack accurate data to make such calculations meaningful, and that these models often create confusion instead of clarity. Shostack advocated for a shift toward practical threat modeling focused on four key questions: what’s being built, what can go wrong, what can be done about it, and whether the fixes succeeded.
Comments
Post a Comment