181k Meeting Records Leaked Despite SOC 2 Certification
Stop treating a SOC 2 certificate like a health insurance policy. It isn’t one. It doesn’t pay out when things go wrong, and it certainly doesn’t stop a leak.
The recent breach at tl;dv is the perfect example of why we need to stop worshiping the PDF. Despite having a SOC 2 certification, the firm leaked north of 180,000 meeting records because of a failure at the vendor level. For a small business owner, this is a warning about where you're placing your trust. You likely have a folder full of these certificates from every SaaS tool you use, thinking they've shifted the risk away from you.
They haven't.
When a vendor fails, the regulator doesn't fine the certificate; they fine the data controller. Look at the GDPR fines for Q2 2026—they hit just over €220 million. A huge chunk of that pressure comes from firms that thought they were covered because their subcontractors had the right badges on their website.
The second-order effect here is a looming crisis for professional indemnity insurers. As these "certified" failures mount, insurers are going to stop taking SOC 2 at face value when calculating premiums for small firms. If you can't prove you actually verified your vendors, expect your premiums to climb or your coverage for third-party breaches to vanish.
The common pushback is that a small firm with no compliance team can't possibly perform deep audits on every vendor. That's true. You don't have the headcount to fly to a data center and check if the locks work.
But you also don't need to.
I distrust any advice that tells you to "simply implement" a vendor risk management framework. Those frameworks are usually just expensive ways to collect more PDFs. Instead, use cheap controls that actually produce evidence.
Instead of asking for a certificate, pick one critical control—like how they offboard employees or how they encrypt backups—and ask the vendor's lead engineer for a five-minute screen-share. If they can't show you the setting in real-time, the SOC 2 report is probably just theatre. It costs nothing but ten minutes of your time and provides more certainty than a hundred-page audit report written six months ago.
This isn't just about meeting records. The Medusa ransomware group has already hit over 500 critical infrastructure organizations by finding these exact gaps in the supply chain. They aren't hacking the front door; they're sliding through the side door of a "certified" vendor who left a port open.
We've reached a point where the certification industry has become a shield for the vendors and a blindfold for the customers. The SEC is already starting to tear this apart in the public markets, evidenced by recent moves against firms with material control weaknesses that their auditors missed. It won't be long before that same scrutiny hits the small-business sector through the back door of regulatory fines.
You can keep collecting certificates and hope for the best. Or you can start asking for screenshots.
One thing to check this week: pick your most critical data vendor and ask them to send a screenshot of their current MFA enforcement policy for all administrative accounts. If they send you a PDF certificate instead, you have your answer.
Sources
The reporting this piece was written from. Check the originals before relying on anything here.
- PLDT Inc. (PHI) to amend 2025 Form 20-F after material control weakness and pulled audit opinions - Stock Titan PCAOB
- SEC charges former execs of auto subprime lender giant Tricolor with fraud, falsifying loan documents - Compliance Week Compliance Week (Google News)
- tl;dv Leaked 181,874 Meeting Records: SOC 2 and the Vendor Problem - Machine Brief InfoSec Compliance (Google News)
- SEC lays groundwork for crypto issuers to raise flexible capital with new rules proposal - | Governance Intelligence Compliance Week (Google News)
- Medusa Ransomware Group Has Attacked 500+ Critical Infrastructure Orgs - The HIPAA Journal InfoSec Compliance (Google News)
- Nasdaq warns SAGTEC Global (Nasdaq: SAGT) over sub-$1 shares, with delisting risk - Stock Titan Compliance Week (Google News)
- Utah governor says he’s ‘deeply troubled’ by Flock cameras, calls for review to protect privacy - Utah News Dispatch Data Privacy (Google News)
- EHang (EH) replaces PwC as 2026 auditor, names new audit firm - Stock Titan Compliance Week (Google News)