Hacker News new | ask | show | jobs
by eastbound 723 days ago
> it’s seen as an enterprise product

Seen? SMBs need to be SOC2 (et al., such as PCI-DSS or HIPAA), and the requirement of controlling all accounts’ permissions at all times is often fulfilled with SSO. How else would you “reset the user’s password after 3 attempts” if the attacker can try the password 3 times on… all of your intranet websites? let alone on Cloud products.

SOC2 is indeed seen as an enterprise feature, but giving access to SMBs strengthens the global security landscape.

1 comments

> SOC2 is indeed seen as an enterprise feature

Then charge your customer for it.

> but giving access to SMBs strengthens the global security landscape.

How does giving away an expensive-to-support feature “strengthen the landscape?”