You have a management problem.
I have three questions for you to start off this post. I don’t care if you’re “in the security field” or not. In fact, I’m more interested in your answers if you aren’t tasked with security, privacy, compliance, or risk management as a part of your defined work role. The questions: If I asked you to show me threat models for your major line of business applications, could you? If I asked you to define the risks (all of them) within…