Auditen
action postmortem

Who Is Actually Managing the Vendor?

The SOC 2 report is the favourite security blanket of the modern SaaS provider. It’s a tidy packet of paperwork that tells a prospective customer: "We have processes in place, and an auditor has seen them." It provides a certain warmth to the procurement officer's heart. However, as tl;dv recently discovered, there is a cavernous gap between having a certificate on your website and actually keeping 181,874 meeting records from spilling into the public domain.

The failure here wasn't a lack of certification. tl;dv had their SOC 2. Instead, the collapse happened at the boundary where the company’s controls ended and their vendor’s began. A security failure at a third party led to the exposure of nearly 182,000 records. For those unfamiliar with the nuance of these filings, this is the classic "Vendor Problem."

The organisation likely had a control in place that looked something like this: *Vendor X provides an annual SOC 2 report to prove their security posture.*

On paper, that's a checkmark. In practice, it’s useless for stopping a live breach. A SOC 2 is a retrospective attestation; it tells you how things were managed during the audit window, not whether the vendor's database is currently open to the internet. The control was a snapshot of a moment in time, masquerading as continuous oversight.

The correct control should have been an active Vendor Risk Management (VRM) programme that didn’t stop at the collection of PDFs. This means requiring real-time incident notification SLAs—where the vendor must report a breach within hours, not weeks—and conducting periodic technical validations rather than just trusting another auditor's opinion. Most importantly, it requires the principle of least privilege applied to data transit: why did the vendor need access to that volume of records in a way that allowed for such a wholesale leak?

Then there is the cost. While we wait for the regulators to finish their maths, the immediate expense isn't just the potential fines—which could be significant given that GDPR fines hit north of €225 million in the second quarter alone. The real cost is the "trust tax." When a company markets its security via SOC 2 and then leaks nearly 200,000 records due to a vendor failure, the certificate becomes a liability. It proves the company knew how it *should* have been doing things but failed to do them.

Some will argue that no amount of oversight can prevent a determined breach at a third-party provider. They'll say that as long as you've done your due diligence and checked the boxes, you've met your regulatory burden.

That is a comfortable lie.

The regulator doesn't care about your "due diligence" if the data vanishes. The regulator cares about whether the control was effective. A control that relies entirely on a third party's self-reported status isn't a control; it's a hope.

The second-order effect here is where it gets interesting for the rest of the sector. This leak puts a spotlight on the auditors who signed off on tl;dv’s SOC 2. If the auditor ignored a glaring lack of vendor oversight, their own reputation takes a hit. More importantly, every other firm using that same failed vendor is now staring at their own risk register, wondering if they've also just been relying on a piece of paper while their data walked out the door.

It turns the SOC 2 from a shield into a target.

The industry loves to treat compliance as a destination—a certificate you earn and then display like a trophy. But this incident reminds us that the paperwork is merely the map, not the terrain. You can have a perfectly drawn map of a bridge and still drive off the cliff if the bridge has collapsed.

I suspect we'll see a shift in how procurement teams handle these certificates. The "send us your SOC 2" email is becoming an admission of laziness. The real question for any CISO now is whether they can prove their vendors are secure today, not just that they were compliant six months ago during an audit window.

If you're still relying on a PDF from last year to ensure your data is safe, you aren't managing risk. You're just filing it.

Sources

The reporting this piece was written from. Check the originals before relying on anything here.

  1. PLDT Inc. (PHI) to amend 2025 Form 20-F after material control weakness and pulled audit opinions - Stock Titan PCAOB
  2. SEC charges former execs of auto subprime lender giant Tricolor with fraud, falsifying loan documents - Compliance Week Compliance Week (Google News)
  3. tl;dv Leaked 181,874 Meeting Records: SOC 2 and the Vendor Problem - Machine Brief InfoSec Compliance (Google News)
  4. SEC lays groundwork for crypto issuers to raise flexible capital with new rules proposal - | Governance Intelligence Compliance Week (Google News)
  5. Medusa Ransomware Group Has Attacked 500+ Critical Infrastructure Orgs - The HIPAA Journal InfoSec Compliance (Google News)
  6. Nasdaq warns SAGTEC Global (Nasdaq: SAGT) over sub-$1 shares, with delisting risk - Stock Titan Compliance Week (Google News)
  7. Utah governor says he’s ‘deeply troubled’ by Flock cameras, calls for review to protect privacy - Utah News Dispatch Data Privacy (Google News)
  8. EHang (EH) replaces PwC as 2026 auditor, names new audit firm - Stock Titan Compliance Week (Google News)

How stories are selected and assessed