The vanity of security certifications
Chief Compliance Officers love this idea. They think that if they've got the right certificates hanging in the virtual lobby (metaphorically speaking), they're safe. We've spent most of a decade treating SOC 2 reports and ISO certifications like some kind of spiritual armour. The logic is simple: if the auditor signed off on the controls, then the risk is handled.
Then comes a week like this one.
Revolut confirmed the breach. No hacking happened. No encryption was broken. Scammers sent emails impersonating government officials. Staff believed them. They handed over Irish users' personal and financial data; one click of 'send' did the damage. The request looked official enough to stop people thinking.
This is the gap between compliance and security. One is a checklist; the other is a state of being.
Companies are leaning into checklists more than ever. Look at Kaspersky. They recently finished a SOC 2 audit to show off their security control maturity, and on paper it looks like a win. In a boardroom, it's just a slide that claims risk has been mitigated. But think about what a SOC 2 report actually is. It is a snapshot of whether you have a process. That isn't the same thing as that process actually working when some person is being pressured by a fake regulator.
Most people tell us the answer to social engineering is more training and tighter tech controls. Many firms are swapping SMS codes for authenticator apps to stop SIM swapping. But isn't that just replacing one digital lock with another? It ignores the real problem. People want to be helpful when they think an authority figure is asking.
The weird truth is that our obsession with certifications actually makes us weaker, and we build a culture where compliance is a finish line you cross once the auditor leaves. Once the certificate arrives, everyone relaxes, and staff stop asking why they follow a protocol and just start trusting the badge.
Some would argue social engineering is an inevitable human flaw. They'll say you can't write a rule to keep someone from being gullible.
That is exactly my point, and when we pretend we can certify this risk away, we stop looking at where our workflows actually break. We care if a policy exists in some PDF instead of asking why a junior staffer feels pressured to send customer data to an external email without a second verification.
This does more than just leak data; it poisons the audit profession. When a firm passes its audits and then gets hit by a catastrophic phishing mail, the auditor stays clean. Only the human element looks bad. Eventually though, insurers won't care about the certificates. They will look at loss history. We are moving toward a time where a SOC 2 report is about as useful to an underwriter as a polite letter of recommendation.
The regulators aren't giving us any clear direction either; the FTC just rescinded its 2021 policy statement on health app data breaches. They shifted the goalposts while firms are still trying to find the pitch, and it shows that the rules we rush to follow are often just temporary expressions of a regulator's mood.
Meanwhile, the paperwork piles up for companies that can't keep their heads above water, and hub Group is facing a potential Nasdaq delisting because it failed to file SEC reports on time. Waldencast is trying something different; they plan to exit the Nasdaq entirely while cutting costs by more than $18 million.
It’s a messy time to be in charge of a balance sheet.
We could keep collecting certificates like Pokémon cards; we can cheer about our "maturity" while some staff member gets fooled by a fake.gov email (which is a bit embarrassing). As long as we think having a rule is the same thing as actually following it, we're just painting the walls while the back door stays wide open.
The next wave of enforcement probably won't care if you're missing policies. It'll be about willful blindness toward how things actually work, and will the ICO or other agencies start penalizing firms for a security framework that looks great on paper but fails in practice? I'm watching.
Until then, keep an eye on those government emails. Especially if they seem particularly urgent.
Sources
The reporting this piece was written from. Check the originals before relying on anything here.
- Personal, Financial Info Exposed in Revolut Data Breach - SecurityWeek Data Privacy (Google News)
- FTC Rescinds 2021 Policy Statement on Health App Data Breaches - The HIPAA Journal InfoSec Compliance (Google News)
- SEC Proposes Rescinding Investment Adviser Pay-to-Play Rule, but Compliance Risks Remain - WilmerHale Compliance Week (Google News)
- Revolut Confirms Data Breach Through Fake Government Requests - Infosecurity Magazine Data Privacy (Google News)
- Revolut data breach as scammers 'used government email' to steal Irish user data - Dublin Live Data Privacy (Google News)
- Fine-tuning medical AI can improve diagnosis but also creates privacy risks - Medical Xpress Data Privacy (Google News)
- Revolut customer data breach after fake govt requests - rte.ie Data Privacy (Google News)
- Hacking Incident Affects 46,000 Hawaii Family Dental Patients - The HIPAA Journal InfoSec Compliance (Google News)