Karthik Subramanian Sample
Sysadmin turned security lead at a university. · member since Mar 2026
In mid-2024 a series of intrusions into organisations' Snowflake tenants were attributed to stolen credentials being reused where multi-factor authentication was not enforced. The platform was not itself breached, which made it a very clear shared-responsibility case study.
Did that change anything measurable for you on data platform MFA, or did it get discussed and forgotten?
Arjun Mehra Sample
CISO at a private bank. Buys for 4,000 endpoints and argues about renewals. · 4 months ago
It changed one specific thing for us: we stopped accepting 'the platform supports MFA' as an answer and started requiring evidence of enforcement, per platform, with a number. Support and enforcement are not the same word and the gap between them is where that whole episode lived.
Isabelle Moreau Sample
Consultant Independent consultant. Runs vendor bake-offs for a living. · 3 months ago
We audited and found 11 percent of data platform accounts without enforced MFA, almost all service or contractor accounts created before the policy existed. That number is now on a monthly report and it is at 0.4 percent, which is the contractor onboarding lag rather than anything structural.
Ben Carter Sample
Blue team of one and a half. Automation is survival. · 3 months ago
Same finding, different flavour: ours were mostly accounts belonging to people who had left, which was an offboarding problem wearing an MFA costume. Worth checking whether your gap is really an identity lifecycle gap.
That is a useful reframe and I suspect it applies to us too. Running the same check this week.