I would posit that it is more likely than not that ALL companies lie about security and intrusions. This one will pass on into the night and is unlikely to affect the company, because security is not something most people want to think about. Passwords will not be changed, protocols will not be updated, and it will happen again.
I think this take is a little bit naive given that a lot of the customers using Okta are themselves regulated by things like healthcare records legislation, financial services regulations, GDPR, and similar. It isn't an option to not use effective security or to claim that it's somebody else's responsibility when you were holding data that has been exfiltrated illegitimately
Comments
I would posit that it is more likely than not that ALL companies lie about security and intrusions. This one will pass on into the night and is unlikely to affect the company, because security is not something most people want to think about. Passwords will not be changed, protocols will not be updated, and it will happen again.
I think this take is a little bit naive given that a lot of the customers using Okta are themselves regulated by things like healthcare records legislation, financial services regulations, GDPR, and similar. It isn't an option to not use effective security or to claim that it's somebody else's responsibility when you were holding data that has been exfiltrated illegitimately