Who Actually Checks the Sub-Processor?
The tl;dv leak is a perfect example of why we need to stop treating compliance certificates like holy relics. The company leaked over 180,000 meeting records. The kicker? They had a SOC 2 certification.
If you’re running a small firm and you’ve been told that collecting a vendor's SOC 2 report is "the way" to manage risk, you've been sold a lie. A SOC 2 isn't a security guarantee. It's an auditor's opinion on whether a set of controls existed at a specific point in time. In the tl;dv case, the failure happened further down the chain—a vendor-related security failure.
Most small business owners treat that PDF as a "get out of jail free" card. They file it in a folder and assume the risk is transferred. It isn't. When data leaks, the regulator doesn't care that your vendor had a shiny certificate from last year. Just look at the GDPR fines for the second quarter of 2026—they hit just over €225 million. Regulators are looking for actual outcomes, not a collection of PDFs.
The real danger here is the sub-processor. Your vendor uses another vendor, who uses another vendor. Somewhere in that chain, someone left an S3 bucket open or used a password like 'Password123'.
You might argue that you can't possibly audit your vendor's vendors. You aren't a multinational bank with a thousand-person risk team. That’s true. But there is a difference between doing a full audit and actually reading the report you already have.
Every SOC 2 report has a section called "Complementary User Entity Controls" (CUECs). This is the most ignored part of the document. CUECs are the specific things the vendor expects *you* to do to make their security work. If the vendor says, "We secure the data provided you rotate your API keys every 90 days," and you never rotate them, the SOC 2 is worthless. You've broken the chain.
If you haven't checked the CUECs, you haven't implemented a control; you've just archived a document.
The second-order effect here hits your insurance. When a breach happens—like those involving the Medusa group, which hit over 500 organizations recently—the first thing the cyber insurer does is look at your due diligence. If they see you relied solely on a static certificate without verifying the CUECs or asking about sub-processor risks, they'll argue you were negligent. They might not pay out, or they'll hike your premiums so high you'll wish you'd just bought more hard drives and stayed offline.
Don't let anyone tell you to "simply implement" a vendor management framework. Those frameworks usually cost five figures and require a full-time employee to maintain. They are designed for people who like spreadsheets more than they like their business.
Instead, focus on the gaps. If a vendor can't tell you who their critical sub-processors are or how they monitor them, that’s your red flag. You don't need a dashboard for this. You need a blunt email asking: "Who is hosting our data, and when was the last time you verified their access controls?"
Some will say this slows down procurement. It does. But it's faster than dealing with a material control weakness that forces you to amend your filings or face SEC charges for falsifying documents—something former executives at Tricolor just found out the hard way.
The uncomfortable question is this: if your primary software vendor went under tomorrow, or leaked everything they had on you, do you actually know where your data lives? Or are you trusting a PDF that was signed off by an auditor who probably spent three days on-site and missed the same things you did?
Check the "Complementary User Entity Controls" section of your most critical vendor's last SOC 2 report. If you can't find that section, or if you realize you aren't actually doing the things listed in it, write a list of those gaps today.
Sources
The reporting this piece was written from. Check the originals before relying on anything here.
- PLDT Inc. (PHI) to amend 2025 Form 20-F after material control weakness and pulled audit opinions - Stock Titan PCAOB
- SEC charges former execs of auto subprime lender giant Tricolor with fraud, falsifying loan documents - Compliance Week Compliance Week (Google News)
- tl;dv Leaked 181,874 Meeting Records: SOC 2 and the Vendor Problem - Machine Brief InfoSec Compliance (Google News)
- SEC lays groundwork for crypto issuers to raise flexible capital with new rules proposal - | Governance Intelligence Compliance Week (Google News)
- Medusa Ransomware Group Has Attacked 500+ Critical Infrastructure Orgs - The HIPAA Journal InfoSec Compliance (Google News)
- Nasdaq warns SAGTEC Global (Nasdaq: SAGT) over sub-$1 shares, with delisting risk - Stock Titan Compliance Week (Google News)
- Utah governor says he’s ‘deeply troubled’ by Flock cameras, calls for review to protect privacy - Utah News Dispatch Data Privacy (Google News)
- EHang (EH) replaces PwC as 2026 auditor, names new audit firm - Stock Titan Compliance Week (Google News)