Adam Shostack and Andrew Stewart released the book The New School of Information Security in 2008. The premise of the book is that we need to get more empirical and scientific about how we approach security. He says some of the old myths about what happens after a data breach — that your share price tumbles, that someone always gets fired — are still some of those, but I see progress in these ways, he says. “There’s real progress. Some amazing progress,” he says of the Verizon data breach report.”]

