Boards want to know if theyre less exposed than last quarter. Patching metrics arent the solution A decade or two ago, board executives asked why should I care about cybersecurity? Five years ago, they were asking Are you patching our software vulnerabilities? Now, theyre starting to ask: Are we actually secure? They might want a simple yes or no initially, but eventually theyll say the most dreaded thing of all, and itll be a demand, not a question: Prove it. Traditional vulnerability...

Read the full article at The Register