Question 1: Systems are never secure, but risk can be significantly reduced through cybersecurity measures. Yet, many organizations fail to do so. Why is cybersecurity so often neglected?
Question 2. Since 2017, federal agencies are required to implement the NIST Cybersecurity Framework. Should private companies be required to implement the framework as well? Explain your position.