▲ | neilv 2 days ago | |
Agreed that sometimes it makes sense to outsource, if Bob's App Factory is big and complex enough to actually need SSO, but isn't big enough to want to run it themselves. (I was thinking more F500, which is what I did a lot of SSO work for.) But if you are a larger company who is outsourcing security, then you're subject to enterprise sales and vendors (Google excepted) who might be ridiculously incompetent. (Even if you have people on staff qualified to vet vendors of infrastructure, now you're in SaaS enterprise sales territory, where decisions aren't always rational or informed.) And you're also looking at lots-of-eggs-in-one-basket centralized single point of failure for swaths of the country, which is a more attractive target than Bob's App Factory alone. Example related infrastructure: https://en.wikipedia.org/wiki/SolarWinds#2019%E2%80%932020_s... |