Freshworks should have tools to discourage brute force hackers. Example lock account for 15 minutes after 5 failed login attempts, etc.
Today, if a hacker goes to our helpdesk, they can:
a) get my customer email address (username) from LinkedIn, press releases etc.
b) brute force the password, because there are no limits to the number of password attempts

