
Sverdlov shares his insights into why this might be the case, notably that someone has to control the quality and security of IT work done by the IT provider (and it can’t be the same IT provider). Secure architecture security controls could potentially save firms millions of pounds (see attached pdf).
As he explains: ‘If you look at your IT team as the construction team which builds and maintains your IT infrastructure, why would you trust your construction workers with defence, too? Would a country trust construction workers with military and police responsibilities?’
@atlant_security