
Companies, government agencies and other organizations should concentrate the vast bulk of their cyber security efforts on implementing best practices with the least effort going to incident response to buy down risk, a Department of Homeland Security (DHS) official, told Congress this week.“At least 70 percent” of the effort of companies and agencies should be for implementing best practices, “in particular through the Cybersecurity Framework,” Andy Ozment, assistant secretary for the Office of Cybersecurity & Communications within the DHS National…