5 ms·
But how do policy changes result in a 50% increase in total expenses? They can't be hiring that many lawyers.
by paxy 8y ago
But how do policy changes result in a 50% increase in total expenses? They can't be hiring that many lawyers.
- xxorlak 8y agoImplementation of policies has a waterfall effect throughout the org. EG: Adding something as simple as a privilege expiration (generic example) and propagating it through the org and various teams itself will take time.
- bobdole12345 8y agoThey're hiring 2/3rd more employees to act as content moderators from the sounds of the guidance.
- cxhandley 8y agoThey're about to break the brains of 1000s of people subjecting them to aweful content. This will also have consequences. What was it "move fast and break things"!
- deleted 8y ago[deleted]
- CalRobert 8y agoEvidently it's not employees, but contractors (via Accenture, etc). Rumour around these parts is a content mod killed themselves at work a couple months ago. Wouldn't want to put that on actual employees of course!
- foobarian 8y agoYou should have seen how much harder life got at our company when we discontinued a common root password across the back office. Things that used to take 5 minutes to fix by self-service now take a ticket to the owner of a system, which can take days.
- deleted 8y ago[deleted]
- jessaustin 8y agoIf one bought into "the security story", one would expect your company after this policy change to have seen fewer random regressions due to random people rooting around in systems for which they were not responsible. Did you find that to be the case?
- rorykoehler 8y agoIt's about reducing exposure to risk more than actual occurrences. You only need to regress once for it to permanently damage your business. Just because it never happened until now doesn't mean that it won't in the future.
- jessaustin 8y agoISTM typically there would have to be more going wrong for "permanent damage"? Not that it would be surprising for a shared-root organization e.g. to have poor backup skills...
- rorykoehler 8y agoCommercial damage is often worse than technical
- Pyxl101 8y agoEven if you don't have a common root password, you can still have groups of people who are sudoers for different systems.
- rachelbythebay 8y agoShhh...
- zeroxfe 8y agoExample: audit all employee access to PII data. Anyone who's worked at a large company can tell you how incredibly complex and expensive this can get if your systems aren't designed for this.
- TheSpiceIsLife 8y agoThat’s upside down, me thinks. It would be difficult to incur a 50% increase in expenses without massive policy shift.