Rant timeβ¦
YOU CANNOT CONSTANTLY RECOMMEND RIP OUT AND REPLACE FOR FLAWS.
What brings this up was I was attending the #SimplyCyber podcast livestream this morning, and the Somicwall web portal breach story came up. One of the first things said on air was to replace all Sonicwall appliances. Now it was brought up that they are mostly SMBs that use them and are cost effective for that segment so instead rotate passwords and tokens.
The idea that 1) Our first reaction is to rip and replace makes no sense. Should you do that with Cisco, Palo or any others that reveal major vulns? 2) It is not a matter of if, but when is a company/device gonna have a major vuln.
Stop thinking of perfect security and understand that imperfect security is usually better than no security.