Corporate InfoSec is vastly more complicated than locking a car door, and is not a core business function for most companies. They’ll never get pro-active about security to any meaningful level. Maybe they shouldn’t have to.
I'm getting extremely fed up with the victim-blaming in InfoSec. Nobody has a security budget that exceeds their attack surface, and few companies have sufficient staffing. So who's "fault" is that breach exactly?
Upgrade to a new iPhone for "free" with trade-in... as long as you agree to the 36-month installment plan during which your phone is carrier locked (inluding the eSIM). I'm calling BS on you @ATT.
However the initial connection with -N and port forwarding does log your source IP server side. The sudo command is logged. It’s not like you’re invisible. And if you were planning on deleting the logs anyway, then you are just wasting time (and are vulnerable to remote logging).