>Seems like management believes it is better to wait for real bad actor to purposefully destroy your site than have it done by your honest employees by accident.
From a politics standpoint that is completely true. Which would you rather tell your boss:
Q: Why is the website offline?
A: One of our sys admins accidentally deleted it.
OR
Q: Why is the website offline?
A: Some nation-state/teenager launched a sophisticated cyber attack, we need to increase the cybersecurity budget. It's the wildwest out there!
There is this saying that only a person that does absolutely nothing never makes any mistakes.
Mistakes are normal course of action at a corporation. Sane managers will understand that is not possible to not have people make any mistakes. Mistakes are part of the learning process.
Now, when somebody makes a mistake what I am looking for are:
Does this person show good judgment? Were precautions taken by the person reasonable?
Does the mistake show pattern of abnormality? Some people seem to attract failure, maybe there is some underlying cause?
Is the person learning from mistakes? Learning is expensive, if somebody made an expensive mistake I want as much learning as possible for the expense.
Is there some kind of external factor that made the mistake possible or more likely? Usually it is possible to improve the environment to reduce the number of mistakes.
As to preventing these guys from scanning ever again, that is bad decision because it is likely they would never make the same mistake again. What's done is done. The scan showed there are problems with the app, now we should want to know if there are more problems but without risking the application stability (too much).
---
-- Do you know what the Big Co. pays when they pay high salary for an experienced engineer?
-- They pay for all the mistakes he/she made at her previous place.
From a politics standpoint that is completely true. Which would you rather tell your boss:
Q: Why is the website offline?
A: One of our sys admins accidentally deleted it.
OR
Q: Why is the website offline?
A: Some nation-state/teenager launched a sophisticated cyber attack, we need to increase the cybersecurity budget. It's the wildwest out there!