
"We have never been attacked!" 🙈😃
Have you also heard people/companies proudly saying that?
If yes, I want to remind you of the test I ran last year, which showed that it takes only 5-10 minutes for some of the hundreds of thousands of automated bots out there in the wild to start scanning your beautiful, newly created publicly accessible endpoint against known vulnerabilities, even if you are a small startup!
So, the translation to the first sentence is either of these:
- To avoid cybersecurity incidents, we have decided to choose the "strategy" of closing our eyes... 👀
- We might gather different logs (access logs, network, system, etc.) for someone to hopefully do something with them later. 💚
- we think all these 3rd-party solutions are expensive
- oh yea and AWS WAF is expensive too!
- even if we use, no one even checks.
