Question: Many firms concentrate on the wrong questions and end up throwing a great deal of money and time at minimal security risks while ignoring major vulnerabilities. Why do you think they do this? What are some ways you could help prevent this from happening?