Skip to content
Notifications
Clear all

Help: Our CEO's laptop won't connect, and I'm getting pressure to make an exception.

2 Posts
2 Users
0 Reactions
4 Views
(@data_meets_ops)
Estimable Member
Joined: 2 months ago
Posts: 76
Topic starter   [#21336]

Okay, so I’m in a situation that’s probably familiar to some of you. I’m the de facto data and infrastructure person at my company, and we’ve been rolling out Banyan Security for our zero-trust access. The policy is straightforward: no device trust, no access to internal data tools or warehouses.

The problem: Our CEO’s personal laptop (a macOS device) fails the device certificate check. It’s not managed by our MDM, and it never will be. The CEO needs access to Looker and our Snowflake dashboards *now*, and I’m getting direct pressure to “just make it work” by creating an exception.

My dilemma:
* Our data pipelines and warehouses hold sensitive customer data. A hard-line security stance feels correct.
* But the pushback is real. The argument is that other tools (like a VPN) would let him in, so why is Banyan blocking it?
* I’m worried that creating a one-off policy for the CEO sets a precedent. Suddenly, every VP will want the same.

Has anyone navigated this? Specifically:
* Is there a Banyan workflow I’m missing for high-privilege, unmanaged devices that doesn’t completely bypass device trust?
* How do you communicate the *why* to non-technical leadership in a way that sticks? I’ve explained the principle, but it’s being dismissed as “my problem to solve.”
* If you’ve had to make an exception, how did you contain the scope? Did you couple it with stricter session logging or something else?

I feel like this is less about Banyan’s tech and more about the classic data governance vs. operational pressure clash. Looking for any practical advice or lessons learned.



   
Quote
(@charliep)
Reputable Member
Joined: 1 week ago
Posts: 172
 

Other tools would let him in because they're worse. That's the whole point you spent money on Banyan. A VPN is just a door, zero trust actually checks who's knocking.

If you make an exception now, you didn't buy a security product, you bought an expensive suggestion box. The next budget meeting where they question the spend will be fun.

Explain it in terms he gets: it's the equivalent of letting anyone walk into the office because the CEO forgot their key card. The policy isn't about his device, it's about every device that isn't his that will immediately ask for the same pass.


Your stack is too complicated.


   
ReplyQuote