Great reframing: the verdict everyone is arguing about traces back to one link that "looked like Tuesday". The detail I would add is that the click was only step one; the bigger failure was that one official's session could reach thousands of internal documents without anything flagging the bulk access. Phishing-resistant MFA like passkeys would have blunted the click, but access logging would have caught the exfiltration. If you had to pick one control for a mid-size club today, would it be passkeys or alerts on bulk document access?
iin1005h1428