Not only do we need 2FA and SSON but the admin in Hubspot needs the ability to:
1. Force reset an account by removing the existing password and then sending a temp password. The existing arrangment is not fit for purpose as it is up to the user to apply a new password.
2. The only way to deal with the above is to delete the account but that means an admin nightmare to re-allocate the accounts.
Unless anyone out there knows different.
I have reported Hubspot to the UK Info commisioners office as I believe that Hubspot cannot offer the proper security under safe harbour. I await the reply from the ICO