Hacker News new | ask | show | jobs
by krthkv 1939 days ago
The "employee access to customer data isn't protected" sits as unsolved an opportunity canvas/brief in almost every SaaS company. You can get to a fair amount of controls with little to no code and only with process changes (aka SoC and ISO certifications), which is also what SaaS security teams spend quite a bit of time on. There are a fair amount of problems to be solved here.
1 comments

Agree. And as much as policies are in place, it is not unusual to see csv exports downloaded to local laptops for analysis as part of work.