Who Actually Verifies the Vendor's Control?
Just over 180,000 meeting records from tl;dv recently leaked into the wild. The cause wasn't a failure of their own internal perimeter but a security failure at one of their vendors. Here is the kicker: they had a SOC 2 certification.
Whenever I see a company describe its compliance programme as 'mature', my instinct is to check the locks on the back door. In audit speak, 'mature' usually means you've stopped asking questions because the auditor stopped asking them three years ago. You’ve reached a state of comfortable stagnation where the process has become an exercise in document collection rather than risk management.
The tl;dv leak is a textbook example of the gap between a certificate and a control.
Most firms treat Third-Party Risk Management (TPRM) as a procurement hurdle. The workflow is simple: you ask the vendor for their SOC 2 Type II report, you save the PDF in a folder, and you check a box. You've 'verified' the vendor.
But that isn't a control. It's a filing exercise.
If I'm sitting across from you on a Tuesday afternoon, I don’t care about the PDF. I want to know what happens when that vendor changes their API or rotates their keys. I want to see the evidence of your ongoing monitoring. If your only proof of 'due diligence' is a document dated last October, you aren't managing risk; you're archiving it.
The real failure here usually lies in the Complementary User Entity Controls (CUECs). Every SOC 2 report has a section detailing what the *customer* must do for the vendor's controls to actually work. These are the 'you do this, or our security is useless' clauses. Most compliance teams skip straight to the opinion letter at the end and ignore the CUECs entirely.
The strongest objection I hear from CISOs is that they can't possibly audit their vendors' internals. They’re right. You can't walk into a SaaS provider's data centre and count the servers.
However, you can—and should—audit your own adherence to those CUECs. If the vendor says 'the customer is responsible for managing access permissions,' I want to see a quarterly review of who has access to that vendor’s platform. That is a tangible piece of evidence. A PDF from the vendor is not.
The second-order effect of this laziness hits the insurance market first. We're seeing a shift where cyber insurers are starting to look past the certifications. If you claim a 'mature' control environment but can't produce the logs showing you actually monitored your critical vendors, don't be surprised when your premiums spike or your coverage shrinks. The regulators aren't far behind. Just look at the €225 million in GDPR fines handed out in the second quarter of this year; a fair chunk of those stem from 'trusted' third parties who weren't actually trusted, just certified.
We have to stop pretending that a SOC 2 is a security strategy. It’s an opinion on a point in time. It's a snapshot of a house before the storm hit.
If you want to know if your vendor management is actually working, ask yourself this: if your primary SaaS provider went dark tomorrow, could you prove to an assessor—on a Tuesday—exactly how you were monitoring their security yesterday?
If the answer involves opening a folder of PDFs, you're just waiting for your own leak.
Sources
The reporting this piece was written from. Check the originals before relying on anything here.
- PLDT Inc. (PHI) to amend 2025 Form 20-F after material control weakness and pulled audit opinions - Stock Titan PCAOB
- SEC charges former execs of auto subprime lender giant Tricolor with fraud, falsifying loan documents - Compliance Week Compliance Week (Google News)
- tl;dv Leaked 181,874 Meeting Records: SOC 2 and the Vendor Problem - Machine Brief InfoSec Compliance (Google News)
- SEC lays groundwork for crypto issuers to raise flexible capital with new rules proposal - | Governance Intelligence Compliance Week (Google News)
- Medusa Ransomware Group Has Attacked 500+ Critical Infrastructure Orgs - The HIPAA Journal InfoSec Compliance (Google News)
- Nasdaq warns SAGTEC Global (Nasdaq: SAGT) over sub-$1 shares, with delisting risk - Stock Titan Compliance Week (Google News)
- Utah governor says he’s ‘deeply troubled’ by Flock cameras, calls for review to protect privacy - Utah News Dispatch Data Privacy (Google News)
- EHang (EH) replaces PwC as 2026 auditor, names new audit firm - Stock Titan Compliance Week (Google News)