Why your SOC 2 controls fail their second year.
The first year of a SOC 2 is a sprint. The second is a system. Most programs collapse in year two because they were built to pass an auditor, not to run a business.
Short, plainly written observations from the practice — for operators, not compliance officers.
The first year of a SOC 2 is a sprint. The second is a system. Most programs collapse in year two because they were built to pass an auditor, not to run a business.
If your executive team cannot describe the top five entries on your risk register from memory, you do not have a risk register — you have a spreadsheet.
A good tabletop is uncomfortable. If everyone leaves the room feeling prepared, you designed it wrong. Here is what we look for.
Modern vendor DDQs ask 200 questions and answer none of them well. The three that actually matter never appear on the standard templates.
Directors will not admit they do not understand your compliance program. Design the briefing so they do not have to.
Most insider threat programs are built by security teams and read by lawyers. The people they are meant to protect against never see them, and that is the problem.
We publish a short letter each quarter. No promotions, no product pitches, no algorithmic sequences. Leave your address and you will receive one — and only one — email every three months.