I think more modern security is an "emperor has no clothes" situation than people think. The LLMs are gonna have a field day.
Companies always prioritize features/capabilities up until shit starts hitting the fan, but even then the culture and requirements makes everything just a job of trying to patch a sinking ship if you're lucky.
> I think more modern security is an "emperor has no clothes" situation than people think.
Outside of a few cases, it's always been a box checking exercise. If you're fortunate, the boxes are kept up to date / written by somebody that knows what they're doing. If you're like most, the box hasn't changed since the 90s when "complex passwords, changed quarterly" was in vogue.