What Did 181,874 Records Cost?
181,874.
That's the number of meeting records leaked by tl;dv this week. The kicker isn't the volume of data—though it's plenty for a regulator to chew on—it's that the company held a SOC 2 certification.
For those who haven't spent two decades in the trenches, let me be clear: a SOC 2 report is not a security certificate. It isn't a badge of honor or a seal of quality. It is an auditor's opinion on whether a set of controls was designed and operating effectively during a specific window of time.
When I started doing this work in the early 2000s, we didn't have the luxury of automated evidence collection. We spent weeks in windowless rooms arguing over whether a signed piece of paper actually proved a manager reviewed a report. It was tedious, but it forced us to look at the actual design of the control. Today, that's been replaced by "control theatre."
Companies chase SOC 2 like it's a trophy. They build just enough process to satisfy the auditor’s checklist, get the report, and then hand it to their customers as a way to shut down any further questioning. It's a shortcut. The tl;dv leak happened because of a vendor-related failure. If you have a SOC 2 but your data is leaking through a third party, your vendor management control isn't working. Period.
I judge every finding by one metric: what does this cost you at year-end?
For the CISO, it costs them their credibility. For the board, it's a liability nightmare. For the auditors who signed off on those controls, it's an embarrassing gap in their testing.
Some will argue that no certification can stop a determined attacker or a freak vendor failure. They'll say that SOC 2 is just a baseline and not a guarantee of absolute security. That's a hedge. The real issue here isn't the "unforeseeable" nature of the leak; it's the reliance on a report as a substitute for actual oversight. If you trust a vendor because they have a SOC 2, but you don't actually verify how they manage *their* sub-processors, you haven't implemented a control. You've implemented a filing system.
The second-order effect here is the ripple through the supply chain. Every customer of tl;dv who relied on that SOC 2 report to check a compliance box now has a hole in their own risk register. They outsourced their trust to a piece of paper, and that paper just caught fire.
We're seeing this blindness everywhere. Look at the €225 million in GDPR fines hitting the books in the second quarter. Or the fact that Medusa ransomware has hit north of 500 critical infrastructure organizations. These aren't "unfortunate events." They are the result of people prioritizing the appearance of compliance over the reality of control design.
I remember a project back in '04 where we found a company had a perfect audit trail for their approvals, but the person signing off on everything was using a rubber stamp and didn't even have access to the system they were approving. It looked great on paper. It was useless in practice.
We've just returned to that era, only now the rubber stamps are digital and we call them "certifications."
If you want to know if your vendors are actually secure, stop asking for their SOC 2 report. Start asking how they handle a failure at their own third-party providers and demand to see the evidence of the last time they actually tested that failure path.
Most won't be able to show you.
Sources
The reporting this piece was written from. Check the originals before relying on anything here.
- PLDT Inc. (PHI) to amend 2025 Form 20-F after material control weakness and pulled audit opinions - Stock Titan PCAOB
- SEC charges former execs of auto subprime lender giant Tricolor with fraud, falsifying loan documents - Compliance Week Compliance Week (Google News)
- tl;dv Leaked 181,874 Meeting Records: SOC 2 and the Vendor Problem - Machine Brief InfoSec Compliance (Google News)
- SEC lays groundwork for crypto issuers to raise flexible capital with new rules proposal - | Governance Intelligence Compliance Week (Google News)
- Medusa Ransomware Group Has Attacked 500+ Critical Infrastructure Orgs - The HIPAA Journal InfoSec Compliance (Google News)
- Nasdaq warns SAGTEC Global (Nasdaq: SAGT) over sub-$1 shares, with delisting risk - Stock Titan Compliance Week (Google News)
- Utah governor says he’s ‘deeply troubled’ by Flock cameras, calls for review to protect privacy - Utah News Dispatch Data Privacy (Google News)
- EHang (EH) replaces PwC as 2026 auditor, names new audit firm - Stock Titan Compliance Week (Google News)