Panacea? MFA isn't even a good idea, and I wish security professionals would stop pretending it is. Certainly the VP isn't without blame, but the biggest error is trying to externalize the cost of security on to someone who has no expertise in that field. If your authentication process *requires* users to do absolutely everything right at all times, you've done a poor job of architecting your system. I mean, take those 10 mistaken MFA approvals. I'm 100% certain that there were *many* signs that the activity was suspicious (e.g., access via foreign IPs), but that information was probably completely ignored. Likewise, no single person should be trusted to the extent that apparently this VP was over the operation of their *entire* IT infrastructure. If that was a management decision, the CEO bears a significant portion of the blame, too. b8f9b4c22df5899ba441c7be370b0490d120120b43851fee736e30fb543d4d4e