#soc-2 — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #soc-2, aggregated by home.social.
-
🚨BREAKING: Former #Deloitte auditor drops the entire SOC 2 playbook on GitHub! 🎉 Now you too can follow the riveting, edge-of-your-seat protocols for #AI #audit readiness. Because nothing screams "cutting-edge innovation" quite like publicly available boilerplate #compliance documents. 📄🤖
https://github.com/Chiaro-HQ/methodology #SOC2 #GitHub #Innovation #HackerNews #ngated -
🚨BREAKING: Former #Deloitte auditor drops the entire SOC 2 playbook on GitHub! 🎉 Now you too can follow the riveting, edge-of-your-seat protocols for #AI #audit readiness. Because nothing screams "cutting-edge innovation" quite like publicly available boilerplate #compliance documents. 📄🤖
https://github.com/Chiaro-HQ/methodology #SOC2 #GitHub #Innovation #HackerNews #ngated -
Ex-Deloitte auditor open-sourced the whole SOC 2 method for your AI
https://github.com/Chiaro-HQ/methodology
Comments: https://news.ycombinator.com/item?id=49171140
#HackerNews #ExDeloitte #Auditor #SOC2 #AI #OpenSource #AuditMethodology
-
Ex-Deloitte auditor open-sourced the whole SOC 2 method for your AI
https://github.com/Chiaro-HQ/methodology
Comments: https://news.ycombinator.com/item?id=49171140
#HackerNews #ExDeloitte #Auditor #SOC2 #AI #OpenSource #AuditMethodology
-
GRC Platforms vs. Managed Compliance: Understanding the Gaps
TL;DR
A GRC platform tells you where you stand. A managed compliance service (in theory) does the standing-up.
Before you sign either contract, make someone in the room answer this out loud:
when a control fails at 2 a.m., who fixes it, how fast, and how do we know it actually happened?
If nobody can answer that today, that’s the gap you’re actually buying a solution for — not the framework name on the badge.Btw, If the 2 a.m. question above didn’t have a clean answer, it’s worth a look at what a fully managed model covers versus what’s still sitting on your team’s plate. Check out the Espresso Labs platform
If you’ve bought a GRC (governance, risk management, and compliance) tool in the last five years, you’ve probably had this moment: the dashboard is green, the auditor is happy, and yet you still have an unencrypted laptop sitting in someone’s bag, a service account with a password from 2021, and a patch cadence that only exists on paper. The tool told you the truth. It just didn’t fix anything.
That gap — between visibility and operationalization — is worth thinking about carefully, because it’s where a lot of compliance budget quietly goes to die.
What GRC platforms like Vanta and Drata actually solve
Vanta and Drata deserve real credit. They replaced the compliance shared-spreadsheet — the one where “evidence” meant a screenshot pasted into a folder six weeks before the audit. What they do well:
- Pull control status from the tools you already run via read-only integrations
- Map passing/failing checks to a framework (SOC 2, ISO 27001, HIPAA, CMMC, etc.)
- Automate evidence collection so audit season isn’t a fire drill
- Alert you when something drifts out of policy
For a company with a mature security function — people who own EDR, MDM, SSO, backup, and vulnerability management day to day — this is exactly the layer you want. It turns “prove you’re compliant” from an annual archaeology project into a live, queryable system.
The quiet assumption baked into that model
Here’s the thing these platforms assume, and it’s almost never stated out loud in the sales process: you already have the underlying security program.
The dashboard reports on controls; it doesn’t implement them, enforce them, or fix them when they break.
When Vanta flags an unencrypted disk, or Drata flags a stale account, that finding lands in a queue. Someone — on your team, or a vendor you’ve separately hired — has to:
- Triage it
- Actually go fix it (device by device, user by user)
- Confirm the fix took
- Make sure it doesn’t regress next sprint
For a company with a five-person security team and a mature IT function, that’s Tuesday. For the median SMB or mid-market company — the ones without a dedicated security engineer, running IT through an MSP or a stretched-thin generalist — that queue just grows. You end up with excellent visibility into a program that isn’t actually being run.
This is also why “we’re SOC 2 compliant” and “we’re actually secure” are not the same sentence. A dashboard can be green because your controls are well-enforced, or it can be green because someone knows exactly which checkboxes the auditor samples. Both look identical from the dashboard.
Naming the other model: managed enforcement
There’s a second category worth knowing about, and it’s growing for a reason: fully managed IT/security/compliance services that don’t just monitor your stack, they are the stack — implementing controls, enforcing them continuously, and remediating drift without waiting for a human to pick up a ticket. Espresso Labs is one vendor pitching this model explicitly against Vanta and Drata, and their framing is a useful lens even if you never buy from them: dashboard vendors show you gaps, managed-service vendors are supposed to close them.
The pitch, generalized across this category, usually includes:
- Implementation of baseline controls (MFA, disk encryption, device hardening, patching) rather than just checking for them
- Continuous enforcement across devices and users, not a point-in-time or scheduled check-in
- 24/7 monitoring of the actual environment, not just what connected tools self-report
- Automated or human-assisted remediation when something drifts
- Incident response bundled in, rather than “bring your own IR retainer”
- One monthly bill instead of a GRC subscription plus an EDR license plus an MDM license plus the labor to glue it together
For a lean team, that consolidation is genuinely attractive. It’s also worth being honest about what you’re trading away.
What a CISO should actually diligence before choosing either path
This is the part vendor comparison pages conveniently skip, so here’s the checklist I’d actually run:
If you’re leaning toward a GRC dashboard (Vanta/Drata/similar):
- Do you have a named owner for every control category who will actually close findings, not just watch them?
What’s your median time-to-remediate on a flagged finding today? If you don’t know, that’s the answer.
Is your underlying stack (EDR, MDM, IdP, backup) already mature, or are you about to be running a dashboard on top of nothing?
If you’re leaning toward a managed compliance/enforcement service:
- Who owns the risk when something goes wrong — contractually, not just in the sales deck? Compliance liability doesn’t fully transfer just because implementation did.
- Can they show you audit history and named references from companies in your size band and framework, not just logos?
- What’s the actual SLA on remediation and incident response, in writing, with penalties — not “24/7 monitoring” as a marketing phrase?
- How much visibility and control do you retain? A vendor that enforces controls also has broad access to your endpoints and identity systems — understand the blast radius if that relationship ends badly or that vendor itself has an incident.
- Is there a subcontractor chain? Ask who’s actually touching your environment at 2 a.m., not just whose logo is on the contract.
- Does their AI-driven remediation have a human escalation path you control, or does “automated” mean “opaque”?
Neither model is inherently safer.
A dashboard with a disciplined team behind it can outperform a managed service with weak SLAs. A managed service can be the right call for a 40-person company that will never hire a dedicated security engineer.The mistake is buying the dashboard and assuming it’s the program, or buying the managed service and assuming you’ve fully offloaded accountability — you haven’t. Your board and your regulator still hold you responsible.
The one-line version
A GRC platform tells you where you stand. A managed compliance service (in theory) does the standing-up.
Before you sign either contract, make someone in the room answer this out loud:when a control fails at 2 a.m., who fixes it, how fast, and how do we know it actually happened?
If nobody can answer that today, that’s the gap you’re actually buying a solution for — not the framework name on the badge.
Curious where you actually stand?
If the 2 a.m. question above didn’t have a clean answer, it’s worth a look at what a fully managed model covers versus what’s still sitting on your team’s plate. Check out the Espresso Labs platform, run the diligence checklist above against them directly, and decide for yourself whether it closes your gap or just moves it.
Rate this:
#AI #CISO #Compliance #cybersecurity #GRC #ISO27001 #security #SOC2 -
GRC Platforms vs. Managed Compliance: Understanding the Gaps
TL;DR
A GRC platform tells you where you stand. A managed compliance service (in theory) does the standing-up.
Before you sign either contract, make someone in the room answer this out loud:
when a control fails at 2 a.m., who fixes it, how fast, and how do we know it actually happened?
If nobody can answer that today, that’s the gap you’re actually buying a solution for — not the framework name on the badge.Btw, If the 2 a.m. question above didn’t have a clean answer, it’s worth a look at what a fully managed model covers versus what’s still sitting on your team’s plate. Check out the Espresso Labs platform
If you’ve bought a GRC (governance, risk management, and compliance) tool in the last five years, you’ve probably had this moment: the dashboard is green, the auditor is happy, and yet you still have an unencrypted laptop sitting in someone’s bag, a service account with a password from 2021, and a patch cadence that only exists on paper. The tool told you the truth. It just didn’t fix anything.
That gap — between visibility and operationalization — is worth thinking about carefully, because it’s where a lot of compliance budget quietly goes to die.
What GRC platforms like Vanta and Drata actually solve
Vanta and Drata deserve real credit. They replaced the compliance shared-spreadsheet — the one where “evidence” meant a screenshot pasted into a folder six weeks before the audit. What they do well:
- Pull control status from the tools you already run via read-only integrations
- Map passing/failing checks to a framework (SOC 2, ISO 27001, HIPAA, CMMC, etc.)
- Automate evidence collection so audit season isn’t a fire drill
- Alert you when something drifts out of policy
For a company with a mature security function — people who own EDR, MDM, SSO, backup, and vulnerability management day to day — this is exactly the layer you want. It turns “prove you’re compliant” from an annual archaeology project into a live, queryable system.
The quiet assumption baked into that model
Here’s the thing these platforms assume, and it’s almost never stated out loud in the sales process: you already have the underlying security program.
The dashboard reports on controls; it doesn’t implement them, enforce them, or fix them when they break.
When Vanta flags an unencrypted disk, or Drata flags a stale account, that finding lands in a queue. Someone — on your team, or a vendor you’ve separately hired — has to:
- Triage it
- Actually go fix it (device by device, user by user)
- Confirm the fix took
- Make sure it doesn’t regress next sprint
For a company with a five-person security team and a mature IT function, that’s Tuesday. For the median SMB or mid-market company — the ones without a dedicated security engineer, running IT through an MSP or a stretched-thin generalist — that queue just grows. You end up with excellent visibility into a program that isn’t actually being run.
This is also why “we’re SOC 2 compliant” and “we’re actually secure” are not the same sentence. A dashboard can be green because your controls are well-enforced, or it can be green because someone knows exactly which checkboxes the auditor samples. Both look identical from the dashboard.
Naming the other model: managed enforcement
There’s a second category worth knowing about, and it’s growing for a reason: fully managed IT/security/compliance services that don’t just monitor your stack, they are the stack — implementing controls, enforcing them continuously, and remediating drift without waiting for a human to pick up a ticket. Espresso Labs is one vendor pitching this model explicitly against Vanta and Drata, and their framing is a useful lens even if you never buy from them: dashboard vendors show you gaps, managed-service vendors are supposed to close them.
The pitch, generalized across this category, usually includes:
- Implementation of baseline controls (MFA, disk encryption, device hardening, patching) rather than just checking for them
- Continuous enforcement across devices and users, not a point-in-time or scheduled check-in
- 24/7 monitoring of the actual environment, not just what connected tools self-report
- Automated or human-assisted remediation when something drifts
- Incident response bundled in, rather than “bring your own IR retainer”
- One monthly bill instead of a GRC subscription plus an EDR license plus an MDM license plus the labor to glue it together
For a lean team, that consolidation is genuinely attractive. It’s also worth being honest about what you’re trading away.
What a CISO should actually diligence before choosing either path
This is the part vendor comparison pages conveniently skip, so here’s the checklist I’d actually run:
If you’re leaning toward a GRC dashboard (Vanta/Drata/similar):
- Do you have a named owner for every control category who will actually close findings, not just watch them?
What’s your median time-to-remediate on a flagged finding today? If you don’t know, that’s the answer.
Is your underlying stack (EDR, MDM, IdP, backup) already mature, or are you about to be running a dashboard on top of nothing?
If you’re leaning toward a managed compliance/enforcement service:
- Who owns the risk when something goes wrong — contractually, not just in the sales deck? Compliance liability doesn’t fully transfer just because implementation did.
- Can they show you audit history and named references from companies in your size band and framework, not just logos?
- What’s the actual SLA on remediation and incident response, in writing, with penalties — not “24/7 monitoring” as a marketing phrase?
- How much visibility and control do you retain? A vendor that enforces controls also has broad access to your endpoints and identity systems — understand the blast radius if that relationship ends badly or that vendor itself has an incident.
- Is there a subcontractor chain? Ask who’s actually touching your environment at 2 a.m., not just whose logo is on the contract.
- Does their AI-driven remediation have a human escalation path you control, or does “automated” mean “opaque”?
Neither model is inherently safer.
A dashboard with a disciplined team behind it can outperform a managed service with weak SLAs. A managed service can be the right call for a 40-person company that will never hire a dedicated security engineer.The mistake is buying the dashboard and assuming it’s the program, or buying the managed service and assuming you’ve fully offloaded accountability — you haven’t. Your board and your regulator still hold you responsible.
The one-line version
A GRC platform tells you where you stand. A managed compliance service (in theory) does the standing-up.
Before you sign either contract, make someone in the room answer this out loud:when a control fails at 2 a.m., who fixes it, how fast, and how do we know it actually happened?
If nobody can answer that today, that’s the gap you’re actually buying a solution for — not the framework name on the badge.
Curious where you actually stand?
If the 2 a.m. question above didn’t have a clean answer, it’s worth a look at what a fully managed model covers versus what’s still sitting on your team’s plate. Check out the Espresso Labs platform, run the diligence checklist above against them directly, and decide for yourself whether it closes your gap or just moves it.
Rate this:
#AI #CISO #Compliance #cybersecurity #GRC #ISO27001 #security #SOC2 -
SOC 2 compliance guide, no fluff: Trust Services Criteria explained, Common Criteria controls mapped, and practical best practices for log collection, anomaly detection, incident response, and access management.
Link: https://graylog.org/post/the-definitive-soc-2-compliance-guide/
-
SOC 2 compliance guide, no fluff: Trust Services Criteria explained, Common Criteria controls mapped, and practical best practices for log collection, anomaly detection, incident response, and access management.
Link: https://graylog.org/post/the-definitive-soc-2-compliance-guide/
-
🔐 𝗦𝗢𝗖 𝟮 alignment is about trust, resilience, and doing security right by design.
At 𝗥𝗘𝗟𝗜𝗔𝗡𝗢𝗜𝗗, our load balancing and application delivery platform is aligned with the 𝗦𝗢𝗖 𝟮 𝗧𝗿𝘂𝘀𝘁 𝗦𝗲𝗿𝘃𝗶𝗰𝗲𝘀 𝗖𝗿𝗶𝘁𝗲𝗿𝗶𝗮—𝗰𝗼𝘃𝗲𝗿𝗶𝗻𝗴 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆, 𝗔𝘃𝗮𝗶𝗹𝗮𝗯𝗶𝗹𝗶𝘁𝘆, 𝗖𝗼𝗻𝗳𝗶𝗱𝗲𝗻𝘁𝗶𝗮𝗹𝗶𝘁𝘆, 𝗣𝗿𝗼𝗰𝗲𝘀𝘀𝗶𝗻𝗴 𝗜𝗻𝘁𝗲𝗴𝗿𝗶𝘁𝘆, 𝗮𝗻𝗱 𝗣𝗿𝗶𝘃𝗮𝗰𝘆.
Because reliability isn’t optional—it’s expected. 🚀
🔗 Read more about our SOC 2 alignment statement.
https://www.relianoid.com/security-compliances/soc-2-compliance/
#SOC2 #CyberSecurity #Compliance #CloudSecurity #ZeroTrust #SRE #RELIANOID
-
Agent Sprawl is the 2026 engineering risk your auditor hasn't named yet.
Uncontrolled parallel AI coding sessions are a silent SOC 2 liability.
I review how GitKraken finally instrumented the required control plane.
-
A $32M YC-backed compliance startup faces allegations of fabricating 494 SOC 2 certifications.
The structural problem: audits certify documents. Behavioral monitoring catches runtime behavior. The gap between those is what the agent at ENERGENAI LLC calls Phantom Compliance.
Behavioral monitoring: https://the-service.live?ref=mastodon-phantom-compliance
-
A $32M YC-backed compliance startup faces allegations of fabricating 494 SOC 2 certifications.
The structural problem: audits certify documents. Behavioral monitoring catches runtime behavior. The gap between those is what the agent at ENERGENAI LLC calls Phantom Compliance.
Behavioral monitoring: https://the-service.live?ref=mastodon-phantom-compliance
-
Love them or hate them, SOC 2 reports have become table stakes for SaaS deals. But the framework leaves the vendor in control of the system boundary and auditor selection, which means the reports vary drastically in rigor.
I wrote about what that structural gap means for vendors trying to build credible programs and buyers trying to evaluate them:
-
Love them or hate them, SOC 2 reports have become table stakes for SaaS deals. But the framework leaves the vendor in control of the system boundary and auditor selection, which means the reports vary drastically in rigor.
I wrote about what that structural gap means for vendors trying to build credible programs and buyers trying to evaluate them:
-
AWS European Sovereign Cloud: Erste Compliance-Meilensteine mit ISO, SOC 2 und C5
Mit der Verfügbarkeit von SOC-2- und C5-Typ-1-Berichten sowie sieben ISO-Zertifizierungen legt Amazon Web Services eine überprüfbare Vertrauensgrundlage für europäische Unternehmen und Behörden, die mit sensiblen Daten arbeiten.
-
#SOC2 and #PCI-DSS frameworks categorize End-of-Life (#EOL) software as a business liability and immediate migration of complex stacks is often technically impossible. Josh Bressers (Anchore) and Mike Morgan (HeroDevs) will discuss on February 25 the "EOL Trap" and how to bridge the gap between security mandates and operational reality.
Expect tech talk, demos and real world scenarios. Register today. https://go.anchore.com/solve-the-end-of-life-trap-herodevs-anchore.html -
#SOC2 and #PCI-DSS frameworks categorize End-of-Life (#EOL) software as a business liability and immediate migration of complex stacks is often technically impossible. Josh Bressers (Anchore) and Mike Morgan (HeroDevs) will discuss on February 25 the "EOL Trap" and how to bridge the gap between security mandates and operational reality.
Expect tech talk, demos and real world scenarios. Register today. https://go.anchore.com/solve-the-end-of-life-trap-herodevs-anchore.html -
#SOC2 and #PCI-DSS frameworks categorize End-of-Life (#EOL) software as a business liability and immediate migration of complex stacks is often technically impossible. Josh Bressers (Anchore) and Mike Morgan (HeroDevs) will discuss on February 25 the "EOL Trap" and how to bridge the gap between security mandates and operational reality.
Expect tech talk, demos and real world scenarios. Register today. https://go.anchore.com/solve-the-end-of-life-trap-herodevs-anchore.html -
#SOC2 and #PCI-DSS frameworks categorize End-of-Life (#EOL) software as a business liability and immediate migration of complex stacks is often technically impossible. Josh Bressers (Anchore) and Mike Morgan (HeroDevs) will discuss on February 25 the "EOL Trap" and how to bridge the gap between security mandates and operational reality.
Expect tech talk, demos and real world scenarios. Register today. https://go.anchore.com/solve-the-end-of-life-trap-herodevs-anchore.html -
📣 If you're managing domains and DNS while pursuing compliance certifications, Infrastructure as Code isn't optional, it's essential 👊.
The DNSimple Terraform provider makes this possible with full domain lifecycle management, giving you the tools to manage #domains and #DNS with the same rigor you apply to other critical infrastructure.
❌ No more manual tweaks risking errors or failed reviews.👉 https://blog.dnsimple.com/2025/12/domain-compliance-with-dnsimple/
#SOC2 #ISO27001 #Compliance #AuditReadiness, #infrastructureAsCode
-
📣 If you're managing domains and DNS while pursuing compliance certifications, Infrastructure as Code isn't optional, it's essential 👊.
The DNSimple Terraform provider makes this possible with full domain lifecycle management, giving you the tools to manage #domains and #DNS with the same rigor you apply to other critical infrastructure.
❌ No more manual tweaks risking errors or failed reviews.👉 https://blog.dnsimple.com/2025/12/domain-compliance-with-dnsimple/
#SOC2 #ISO27001 #Compliance #AuditReadiness, #infrastructureAsCode
-
Your private AWS VPC isn’t as safe as you think. ☁️🔓
We just released the full recording of our live workshop from Infosecurity Europe 2025.
In this session, our CEO Adrian Furtună and Product Manager Dragoş Sandu bypass the "safety" of a private network to compromise a mock healthcare infrastructure ("SynaptiCare") live on stage.
The attack chain:
1️⃣ Tunneling: Using a VPN Agent to breach the private IP range.
2️⃣ RCE: Escaping a Redis sandbox to get root access.
3️⃣ Exfiltration: Bypassing Next.js auth to dump .env keys.
4️⃣ Compliance: Automating the fix for SOC 2 evidence.It’s a practical look at automating vulnerability validation behind firewalls.
📺 Watch the full demo here: https://pentest-tools.com/events/infosecurity-europe-2025
#Infosec #RedTeam #CloudSecurity #Pentesting #SOC2 #AWS #InfosecurityEurope
-
Your private AWS VPC isn’t as safe as you think. ☁️🔓
We just released the full recording of our live workshop from Infosecurity Europe 2025.
In this session, our CEO Adrian Furtună and Product Manager Dragoş Sandu bypass the "safety" of a private network to compromise a mock healthcare infrastructure ("SynaptiCare") live on stage.
The attack chain:
1️⃣ Tunneling: Using a VPN Agent to breach the private IP range.
2️⃣ RCE: Escaping a Redis sandbox to get root access.
3️⃣ Exfiltration: Bypassing Next.js auth to dump .env keys.
4️⃣ Compliance: Automating the fix for SOC 2 evidence.It’s a practical look at automating vulnerability validation behind firewalls.
📺 Watch the full demo here: https://pentest-tools.com/events/infosecurity-europe-2025
#Infosec #RedTeam #CloudSecurity #Pentesting #SOC2 #AWS #InfosecurityEurope
-
If you're in legal I'm sure you're interested in compliance. It is exciting after all, lol. Anyway... here are some you need to consider when it comes to compliance and your tech.
#AI #LawFirm #GDPR #HIPPA #SOC2 #GeneralDataProtectionRegulation #HealthInsurancePortabilityandAccountabilityAct #ArtificialIntelligence #ServiceOrganizationControl2
-
📢 At RELIANOID, we follow SOC 2 Trust Service Criteria to ensure Security, Availability, Confidentiality, Processing Integrity, and Privacy across our load balancing solutions — whether on-prem, cloud, or hybrid.
Our controls align with the needs of highly regulated environments such as finance, healthcare, and government, helping our customers operate securely and confidently.
🔗 Read our full SOC 2 Alignment Statement here: https://www.relianoid.com/security-compliances/soc-2-compliance/
-
Plans, Policies, and Procedures: SOC 2
Designed to help organizations demonstrate that they have implemented appropriate controls to protect customer data and systems.
https://blackcatwhitehatsecurity.com
#Plans #Policies #Procedures #SOC2 #Programming -
Plans, Policies, and Procedures: SOC 2
Designed to help organizations demonstrate that they have implemented appropriate controls to protect customer data and systems.
https://blackcatwhitehatsecurity.com
#Plans #Policies #Procedures #SOC2 #Programming -
Nouvel épisode PME sur les certifications de sécurité (ISO 27001, SOC 2)!
Avec Cyndie Feltz, Nicholas Milot et Dominique Derrier, on démystifie comment aborder ces certifications sans paniquer ni se ruiner.
Conseil clé : Conformité ≠ Sécurité. Choisissez le plus petit périmètre qui fait du sens!
🎧 Web: https://polysecure.ca/posts/episode-0x644.html#d9cdf080
🎧 Spotify: https://open.spotify.com/episode/6KUCg4yKbikiaHcOFzgB1V?si=8kw_sjraSXG4Wu8-tZGUTA🎧 YouTube: https://youtu.be/a2Xb-yXmYIM
-
From Spreadsheets to Strategic Defense: Andrew Morton Walks Us Through TPRM Transformation https://thecyberexpress.com/third-party-risk-management-best-practices-andrew-morton/ #Multi-factorAuthentication #GovernanceRiskCompliance #ThirdPartyRiskManagement #VendorRiskManagement #ProcurementSecurity #SupplyChainSecurity #RiskBasedSecurity #TPRMBestPractices #ChemistWarehouse #Fourth-PartyRisk #VendorAssessment #VendorOnboarding #CyberEssentials #legalcompliance #VendorTiering #BusinessNews #SOC2
-
From Spreadsheets to Strategic Defense: Andrew Morton Walks Us Through TPRM Transformation https://thecyberexpress.com/third-party-risk-management-best-practices-andrew-morton/ #Multi-factorAuthentication #GovernanceRiskCompliance #ThirdPartyRiskManagement #VendorRiskManagement #ProcurementSecurity #SupplyChainSecurity #RiskBasedSecurity #TPRMBestPractices #ChemistWarehouse #Fourth-PartyRisk #VendorAssessment #VendorOnboarding #CyberEssentials #legalcompliance #VendorTiering #BusinessNews #SOC2
-
📊 78 security pros from 14 countries joined us live to learn how to make SOC 2 prep less painful.
Now the full webinar is available on-demand.
Catch Adrian Furtună (CEO) and Dragos Sandu (Product Lead) as they show you how to:
✅ Automate scanning across hybrid cloud assets
✅ Zoom in on validated vulnerabilities that actually matter
✅ Deliver SOC 2 audit-ready reports without juggling 5 tools at the same timeMissed it live? You can still get all the insights right away, the replay is up and ready for you: https://pentest-tools.com/webinars/how-to-automate-for-soc-2
-
📊 78 security pros from 14 countries joined us live to learn how to make SOC 2 prep less painful.
Now the full webinar is available on-demand.
Catch Adrian Furtună (CEO) and Dragos Sandu (Product Lead) as they show you how to:
✅ Automate scanning across hybrid cloud assets
✅ Zoom in on validated vulnerabilities that actually matter
✅ Deliver SOC 2 audit-ready reports without juggling 5 tools at the same timeMissed it live? You can still get all the insights right away, the replay is up and ready for you: https://pentest-tools.com/webinars/how-to-automate-for-soc-2
-
Chainlink Hits Compliance Milestone as LINK Active Addresses Reach 10,000 - TLDR:
Chainlink earned ISO 27001 and SOC 2 compliance, validating its security and opera... - https://blockonomi.com/chainlink-hits-compliance-milestone-as-link-active-addresses-reach-10000/ #proofofreserve #stablecoins #blockchain #pricefeeds #chainlink #linkprice #smartdata #iso27001 #fintech #navlink #oracles #crypto #defi #ccip #soc2
-
Chainlink Hits Compliance Milestone as LINK Active Addresses Reach 10,000 - TLDR:
Chainlink earned ISO 27001 and SOC 2 compliance, validating its security and opera... - https://blockonomi.com/chainlink-hits-compliance-milestone-as-link-active-addresses-reach-10000/ #proofofreserve #stablecoins #blockchain #pricefeeds #chainlink #linkprice #smartdata #iso27001 #fintech #navlink #oracles #crypto #defi #ccip #soc2
-
The updated security whitepaper for Passbolt v5 is now available. It explains how passbolt protects your data, including a clear breakdown of security model based on the #OpenPGP encryption standard.
The paper also outlines how we keep the platform secure over time, from built-in risk mitigations strategies, to yearly independent code audits to ongoing SOC 2 Type II compliance checks, and more.
Read the full whitepaper: https://www.passbolt.com/security
-
The updated security whitepaper for Passbolt v5 is now available. It explains how passbolt protects your data, including a clear breakdown of security model based on the #OpenPGP encryption standard.
The paper also outlines how we keep the platform secure over time, from built-in risk mitigations strategies, to yearly independent code audits to ongoing SOC 2 Type II compliance checks, and more.
Read the full whitepaper: https://www.passbolt.com/security
-
This year's SOC-2 audit is even worse than last year.
I got a not so technical auditor and it's hard to explain why git repository with no code but critical in other way does not have dependency CVE scan enabled.
Any recommendations for next year's SOC-2 auditor ?
-
SOC 2 isn’t broken—but your expectations may be.
We’re hosting a live panel on what comes next: real risk reduction, stronger vendor trust, and why HITRUST may be the better path.
July 31st | Register: https://www.crowdcast.io/c/beyond-the-checkbox-rethinking-soc-2-cybersecurity-and-third-party-risk-in-2025-an-itspmagazine-webinar-with-hitrust
-
SOC 2 isn’t broken—but your expectations may be.
We’re hosting a live panel on what comes next: real risk reduction, stronger vendor trust, and why HITRUST may be the better path.
July 31st | Register: https://www.crowdcast.io/c/beyond-the-checkbox-rethinking-soc-2-cybersecurity-and-third-party-risk-in-2025-an-itspmagazine-webinar-with-hitrust
-
Excalidraw finally got its SOC 2 sticker, 🤡 not because it cares about #security, but because filling out #endless #questionnaires is #hard work! 📝🔒 Now they can rest easy until the next shiny #certification we collectively pretend to understand. 🚀🎉
https://plus.excalidraw.com/blog/excalidraw-soc2 #Excalidraw #SOC2 #work #HackerNews #ngated -
Excalidraw finally got its SOC 2 sticker, 🤡 not because it cares about #security, but because filling out #endless #questionnaires is #hard work! 📝🔒 Now they can rest easy until the next shiny #certification we collectively pretend to understand. 🚀🎉
https://plus.excalidraw.com/blog/excalidraw-soc2 #Excalidraw #SOC2 #work #HackerNews #ngated -
Excalidraw wrote about its journey to SOC 2 Type 1 compliance and why SaaS companies would want to become certified.
I participated in SOC 2 compliance efforts at a few companies. It forces best common practices to be affirmed within organizations and is useful for getting those “we know we should but don’t” tasks prioritized.
https://plus.excalidraw.com/blog/excalidraw-soc2?ref=activitypub
-
From scanning ports to structuring security programs that meet real-world demands, this book helps practitioners level up from technical know-how to strategic capability.
It bridges foundational knowledge with practical security leadership. Designed for those who build, defend, and explain security every day
https://nostarch.com/foundationsinfosec
#infosec #cybersecurity #securityengineering #nmap #SOC2 #compliance #devops #securityculture
-
Lumoar – Free SOC 2 tool for SaaS startups
#HackerNews #Lumoar #SaaS #SOC2 #startups #tools #free #cybersecurity
-
Actionable Protection Strategies for 2025 with Shrav Mehta – Source: securityboulevard.com https://ciso2ciso.com/actionable-protection-strategies-for-2025-with-shrav-mehta-source-securityboulevard-com/ #rssfeedpostgeneratorecho #RegulatoryCompliance #CyberSecurityNews #SecurityBoulevard #VideoInterviews #Compliance #regulation #HIPAA #SOC2
-
The Importance of Code Signing Best Practices in the Software Development Lifecycle – Source: securityboulevard.com https://ciso2ciso.com/the-importance-of-code-signing-best-practices-in-the-software-development-lifecycle-source-securityboulevard-com/ #HardwareSecurityModules(HSMs) #CertificateAuthority(CA) #rssfeedpostgeneratorecho #SecurityBloggersNetwork #CertificateManagement #CyberSecurityNews #SecureCodeSigning #SecurityBoulevard #codesigning #CA/BForum #ISO27001 #NIST #SOC2