> usually get access through a bastion that anonymizes data and logs access
I think this may be something that is unique to a certain size tech company that simply isn't the case at 99.99% of companies with user data in their possession.
It hasn't been until recently. We are currently locking down all internal systems based on the minimum necessary accesses for various systems. We should have done this a lot sooner.
I think this may be something that is unique to a certain size tech company that simply isn't the case at 99.99% of companies with user data in their possession.