The narcissistic side of me likes to brag that the 451 Group’s Josh Corman owes his fame to me for writing about his talk on PCI as “No Child Left Behind” more than a year ago.The article caused heated debate on Twitter and led to a two-part podcast debate I co-hosted with Network Security Podcast host Martin McKeay. The debate then turned into a road show of sorts, with PCI panel discussions at several security conferences last year, with different players in each town.Now, I know I really had nothing to do with Corman’s fame. He was already well on his way before we met at Chris Hoff’s July 4 party in 2009. He’s earned his place in the community for taking on Rugged and putting together colorful presentations like this: But I am happy to have played a role in the PCI debate. I’d like to think we’re all a bit smarter about PCI and compliance in general as a result of the trouble that little story caused. Which gives me the nerve to suggest something that’ll probably make Corman annoyed with me, if he’s not already.We’re seeing another acronym getting thrown around a lot these days, largely thanks to RSA’s recently-announced security breach: APT, the advanced persistent threat.one-stop view of latest business threats. We created it for you! Bookmark it! Use it!CSO’s Daily Dashboard gives you a Last week Corman made a comment on Twitter about APT being the new PCI.It was said in partial jest, but there’s something there, in my opinion. APT is becoming as overused among security vendors as PCI is, and that means companies will be buying security products based as much on their fear of becoming the target of an APT as they were of becoming the target of a cranky PCI auditor. Sign up today.Get your morning news fix with the daily Salted Hash e-newsletter! When fear drives your security decisions, those decisions often lead to other holes an attacker will eventually find and exploit.So what do we do about that? My suggestion is a rolling debate on the APT, with Corman in a starring role. It can start with a podcast debate like we did with PCI and mushroom in similar fashion. It’s a broad enough subject that his ongoing themes of Rugged and zombies will fit in nicely.That’s my suggestion.Now to go hide before that angry call from the 451 Group appears on my phone.–Bill Brenner Related content news Gwinnett Medical Center investigating possible data breach After being contacted by Salted Hash, Gwinnett Medical Center has confirmed they're investigating a security incident By Steve Ragan Oct 02, 2018 6 mins Regulation Data Breach Hacking news Facebook: 30 million accounts impacted by security flaw (updated) In a blog post, Facebook’s VP of product management Guy Rosen said the attackers exploited a flaw in the website's 'View As' function By Steve Ragan Sep 28, 2018 4 mins Data Breach Security news Scammers pose as CNN's Wolf Blitzer, target security professionals Did they really think this would work? By Steve Ragan Sep 04, 2018 2 mins Phishing Social Engineering Security news Congress pushes MITRE to fix CVE program, suggests regular reviews and stable funding After a year of investigation into the Common Vulnerabilities and Exposures (CVE) program, the Energy and Commerce Committee has some suggestions as to how it can be improved By Steve Ragan Aug 27, 2018 3 mins Vulnerabilities Security Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe