How do you make your customers feel safe from the log4j vulnerability?
(a) Say nothing
(b) Disclose.
I hate to pitch any company, other than mine, obviously, but AWS has done a "Good Thing" (TM) by publishing their activities.
At a minimum,
- Please have a security page or blog
- Tell people you are on tracking log4j vulnerabilities
- Tell people you have no direct log4j vulnerabilities OR you have mitigated the issues
- You will keep them informed if there are any new developments.