Do you at least have 2FA for all users?
I can't really discuss that, unfortunately.
How so?
If you can gain access to the second factor or bypass it through social engineering it's worse to have it than to not have it. Why? Because it requires extra time every day for something that doesn't work as intended. Kinda like all that airport security after 9-11
what LOLOLCUS said, plus this: https://yewtu.be/watch?v=3jQoAYRKqhg
(post is archived)