@matthew_d_green I started thinking recently that anyone in any sort of position of authority in infosec should take an academic introduction to cryptography course, as an easy way of at least realizing that the approach of "things are true or false, we might just not know", "modus ponens works", "vacuously satisfied implications are true, not some weird third state", ... exists (and, I'd hope, adopting it at least somewhat).