At one former gig “security architect” and ciso didnt even flinch when okta got breached the first time. They still happily migrated to it with much fanfare since it helped them tick a compliance box
This is a naive take. Okta solves both security and non-security problems.
If they keep undermining the 'security' bits they will 100% get ditched. Assuming there is a credible alternative. But I'd argue there isn't a credible alternative at the moment (on either the security or non-security front).
If you listed all of the 'security forward' SaaS companies you can think of. I guarantee 3/4 use Okta. I also bet all would be keen to switch as soon as an alternative was reasonably 2x better on either the 'security' or 'non-security' fronts. Even given the massive pain in the bum it would be to migrate. No one loves Okta or their sales team.
The dumbest guidance your security architect could have given was "Okta got hacked by actors that don't care about us. We should move to ${SOLUTION} that is objectively worse for users and probably worse for security"
> If they keep undermining the 'security' bits they will 100% get ditched.
No they won’t. This is my point - the ‘security’ bit isnt even on the radar of 3/4 of those companies. Compliance is
We were using a different solution at that point and planning a move TO okta. It wasn’t just about the fact it was hacked (happens to the best of us) but how they got hacked, how they found out and how they responded all of which made immediately clear what a nightmare it was/is