|
|
|
|
|
by JimDabell
235 days ago
|
|
When a person leaves an organisation, it’s difficult to find all the various team accounts they have been added to in order to remove them. So you end up in a situation where people no longer in the organisation frequently still have access to anything non-SSO. That’s a very obvious, legitimate security issue, why are you accusing people of being insincere about it? |
|
Again, that's inconvenient but doable, just like phishing prevention.
>That’s a very obvious, legitimate security issue, why are you accusing people of being insincere about it?
I'm not denying it's a security issue, any more than I'm denying that phishing isn't a security issue. I even specifically mentioned the possibility of employees that fail phishing training. I'm objecting specifically to the "ransom" framing, which is a pejorative way to imply that companies have a duty to offer all security features for free.