logoalt Hacker News

emilycgtoday at 6:11 PM1 replyview on HN

The key problem is the audits and the auditors. I have independently verified for our vendors that they have the same templated SOC2 as all of the leaked reports, which is concerning because that shows the auditors did not actually validate the controls.

SOC2 is supposed to give you an INDEPENDENT evaluation of the compliance of a company "are they doing what they say they are"

If the SOC2 report is just a pre-populated template, it is meaningless.

It doesn't really matter the motivation of the "DeepDelver" - this has implications across all companies that rely on these vendors that have been "assessed" by Delve.


Replies

OsrsNeedsf2Ptoday at 8:29 PM

Really curious what you're going to do, going forward. Will you be rejecting compliance certified with Delve? Will you be forcing your vendors to redo compliance?