A Million Records is a Large Sample Size
One million.
That's how many students, parents and teachers just had their personal info leaked by Mathspace; in auditing, we call that a significant sample size. For Mathspace executives, it's a liability that will haunt their balance sheet for years.
I saw this constantly when I started SOX work in the early 2000s. Companies spent six months building binders of policies that looked great to regulators. Everything had a signature. They had a process for access reviews. Then you would actually check the server and find some employee from three years ago still had domain admin rights; why does this keep happening?
It’s the same rot here.
Most companies treat security like a grocery list, and they grab a certificate, check a box on some vendor form and tell their board the environment is safe. That isn't a control. It's theatre. A real control doesn't just claim that data is protected. It stops the data from leaving the building in the first place.
The question I always ask during a walkthrough is: what does this cost you at year-end?
Bad control design is a trap, and you aren't paying a consultant to fill a gap. You're paying a regulator a fine and a law firm a settlement. For Mathspace, it's worse than the cleanup costs. They lost trust in EdTech, where the users are children.
People will tell you no system is unhackable or that they had reasonable security, and that's just an excuse for bad design. If a million records vanish, the control didn't fail. It wasn't there. You can't call a fence effective when it has a hole big enough to drive a truck through.
Then there are the auditors, and whoever signed off on the latest assurance report for Mathspace is now looking at a gap between their opinion and what actually happened. Insurers don't just care about the breach, and they want to know who vouched for the controls beforehand.
Does California really think requiring independent audits of AI systems will work? It seems naive. If we can't handle basic database access controls in 2026, an audit of a black box AI won't stop a disaster; we're just buying expensive paper to hide the same holes.
I've seen this play out before, and the company panics and hires a big firm for remediation. They spend millions on software they can't even configure. Then they ask for a new certificate so they can tell the world they've changed.
They haven't. They've just bought a more expensive version of the theatre.
I'll start believing in "assurance" once a firm admits their controls are broken before they get hacked, instead of waiting until a million records end up on the dark web. Until that happens, look at your logs and stop trusting certificates.
Sources
The reporting this piece was written from. Check the originals before relying on anything here.
- OpenAI launches ChatGPT for Financial Services to do junior banker work - Pasquale Pillitteri Compliance Week (Google News)
- California enacted the first U.S. laws requiring independent audits of AI systems - qz.com Compliance Week (Google News)
- User Data Breach at Revolut Exposed, High-Net-Worth Clients - Coinfomania Data Privacy (Google News)
- Glass House Brands (GLAS) changes auditor and updates filings - Stock Titan Compliance Week (Google News)
- Thailand’s SEC Limits Stablecoin Transfers to $151K Daily - Coinfomania Compliance Week (Google News)
- Sioux Falls City Council finalizes budget, retains Flock camera funding despite privacy concerns - Dakota News Now Data Privacy (Google News)
- Legislature and Appellate Court Bring Clarity to California Invasion of Privacy Act - JD Supra Data Privacy (Google News)
- Mathspace Breach Exposes 1 Million Students, Parents, and Teachers - securitybrief.com.au Data Privacy (Google News)