Earlier quoted context omitted.
Depends on what types of apps are being built, what data they touch, and what those apps are exposed to from a network perspective. Ie; all of the fundamentals of information/network security. Generally speaking, most executives do not have an information/network security background but do have privileged access to extremely valuable information, even if an attacker just has access to their email.
> most executives do not have an information/network security background but do have privileged access to extremely valuable information, even if an attacker just has access to their email. In a properly structured organization, of which there are many and who are required by regulations and/or best practices, senior executives tend to have need/role-based access to information, just like everyone else in the organiz…
These are 'proper' (sometimes) access controls, but can still be abused. Not from email...but you get the idea.