Auditen
framework watch

Does Your SOC 2 Cover Your Vendors?

tl;dv leaked over 180,000 meeting records recently. The kicker isn't just the volume of data—though that's plenty for a regulator to chew on—it's that they held a SOC 2 certification while it happened. The leak stemmed from a vendor-related security failure.

This is the gap where most "mature" compliance programs fall apart.

Too many firms treat a SOC 2 report as a binary switch: either the vendor has one or they don't. If they have it, the checkbox is ticked and the risk is deemed "mitigated." It’s a lazy way to handle third-party risk. I've seen this from both sides of the table. As an auditor, I see the spreadsheet where every vendor is marked "Compliant" because there's a PDF in a folder. As a practitioner, I know that PDF was likely signed six months ago and covers a scope that might not even include the specific service you're using.

The real question is: what would you show an assessor on a Tuesday?

If I walked into your office mid-week and asked for evidence that you’ve actually verified the controls of your critical sub-processors, most of you would point to the SOC 2 report. That isn't evidence of a control; it's evidence that someone else's auditor was satisfied with a sample last year.

The strongest objection here is usually about CUECs—Complementary User Entity Controls. Your compliance lead will tell me they've reviewed the CUECs in the vendor's report and confirmed they are implemented internally.

That's a lie. Or, more likely, a misunderstanding of what "confirmed" means.

Reading a list of required controls isn't the same as testing them. If the vendor says you must "monitor user access to the platform quarterly," and your evidence is just a policy document saying you *should* do it, you've failed. You haven't implemented the control; you've just acknowledged its existence.

The second-order effect here hits the insurers. Cyber insurance underwriters aren't blind to these leaks. When they see "certified" firms leaking hundreds of thousands of records via a third party, the SOC 2 becomes less valuable as a proxy for risk. We're moving toward a world where insurers will demand actual proof of vendor monitoring—logs, access reviews, and heartbeat checks—rather than a signed opinion from a CPA firm.

If your "mature" program relies on a library of PDFs to prove your supply chain is secure, you don't have a security program. You have a filing system.

The next time you're reviewing a vendor, ignore the certification for a moment. Ask them for the raw logs of their last three failed login attempts from an administrative account at one of their own sub-processors.

See how fast they stop talking about their "mature" posture.

Sources

The reporting this piece was written from. Check the originals before relying on anything here.

  1. Investigation opened on OpenAI by Attorney General Austin Knudsen following data breach - Fairfield Sun Times Data Privacy (Google News)
  2. SEC Drafts Major Overhaul Of Transfer Agent Rules, Mentions Blockchain - menafn.com Compliance Week (Google News)
  3. SEC charges former execs of auto subprime lender giant Tricolor with fraud, falsifying loan documents - Compliance Week Compliance Week (Google News)
  4. tl;dv Leaked 181,874 Meeting Records: SOC 2 and the Vendor Problem - Machine Brief InfoSec Compliance (Google News)
  5. SEC lays groundwork for crypto issuers to raise flexible capital with new rules proposal - | Governance Intelligence Compliance Week (Google News)
  6. Medusa Ransomware Group Has Attacked 500+ Critical Infrastructure Orgs - The HIPAA Journal InfoSec Compliance (Google News)
  7. Nasdaq warns SAGTEC Global (Nasdaq: SAGT) over sub-$1 shares, with delisting risk - Stock Titan Compliance Week (Google News)
  8. SEC Moves to Let Transfer Agents Use Blockchain for Official Ownership Ledgers - finance.biggo.com Compliance Week (Google News)

How stories are selected and assessed