Your SOC 2 certificate isn't a security guarantee
The tl;dv leak is a perfect example of why you shouldn't trust a piece of paper over your own common sense. Over 180,000 meeting records were exposed because of a failure at the vendor level. The kicker? They had their SOC 2 certification.
For most small firms, a SOC 2 report is a badge of honor used to win bigger contracts. You pay an auditor a few thousand dollars, you gather your screenshots, and you get a PDF that tells your customers their data is safe. But as this leak shows, there's a massive gap between being "compliant" and being secure.
The problem is how we treat vendor management. Most small firms handle it by asking their vendors for their own SOC 2 report, filing it in a folder, and ticking a box. This is what I call the "compliance chain of trust," and it's essentially a game of telephone where everyone assumes the person before them actually did the work.
If you're relying on a vendor's certification to protect your data, you're not managing risk. You're outsourcing your liability to a document that was likely signed off on during a narrow window of time last year.
Some will argue that an audit is the only objective way to verify security for a third party. They’ll say it's impossible for a ten-person team to manually inspect every vendor's server configuration.
They aren't wrong about the effort, but they are wrong about the objectivity. An auditor doesn't spend a month living in your vendor's network; they sample a few tickets and check if a policy exists on paper. A policy that says "we encrypt data" is not the same thing as data actually being encrypted when a rogue script runs at 3 a.m. on a Tuesday.
The second-order effect here hits the insurers. When these leaks happen, insurance companies don't care about your SOC 2 certificate. They look for negligence. If you can't show that you actually monitored your vendors—rather than just collecting their certificates—you might find your premiums spiking or your claim denied. Your customers will be angry, but your underwriters will be the ones who actually make your life miserable.
I hate advice that tells a small business owner to "simply implement" a vendor risk management program. You don't have the headcount for a dedicated risk officer, and you certainly don't have the budget for a fancy GRC tool that costs more than your monthly rent.
You need cheap controls that actually work.
Stop treating the SOC 2 report as a binary "yes/no" for security. When a vendor sends you their report, don't look at the opinion letter. Look at the "Complementary User Entity Controls" section. This is the part of the report where the auditor explicitly lists what *you* are responsible for doing to make the system secure.
Most firms ignore this section because it’s boring and looks like legal jargon. But those controls are essentially a map of where the vendor's security ends and your vulnerability begins. If the report says you must "regularly review user access," and you haven't looked at your user list since 2024, the certificate is worthless. You've left the door unlocked and then pointed to the vendor's fence as proof of safety.
Certification is a sales tool, not a security strategy. If you treat it as the latter, you're just paying for an expensive way to be surprised.
Check your most critical vendor's SOC 2 report this week—specifically the section on User Entity Controls—and see if you're actually doing any of them.
Sources
The reporting this piece was written from. Check the originals before relying on anything here.
- PLDT Inc. (PHI) to amend 2025 Form 20-F after material control weakness and pulled audit opinions - Stock Titan PCAOB
- SEC charges former execs of auto subprime lender giant Tricolor with fraud, falsifying loan documents - Compliance Week Compliance Week (Google News)
- tl;dv Leaked 181,874 Meeting Records: SOC 2 and the Vendor Problem - Machine Brief InfoSec Compliance (Google News)
- SEC lays groundwork for crypto issuers to raise flexible capital with new rules proposal - | Governance Intelligence Compliance Week (Google News)
- Medusa Ransomware Group Has Attacked 500+ Critical Infrastructure Orgs - The HIPAA Journal InfoSec Compliance (Google News)
- Nasdaq warns SAGTEC Global (Nasdaq: SAGT) over sub-$1 shares, with delisting risk - Stock Titan Compliance Week (Google News)
- Utah governor says he’s ‘deeply troubled’ by Flock cameras, calls for review to protect privacy - Utah News Dispatch Data Privacy (Google News)
- EHang (EH) replaces PwC as 2026 auditor, names new audit firm - Stock Titan Compliance Week (Google News)