and yes I do understand there is a IRL-auditing authority piece to all of this too.
Perhaps there this is a play here in the market to create a new auditing firm that 99% automates all this for startups? sans fraud certs of course.
71–80 of 164 posts
and yes I do understand there is a IRL-auditing authority piece to all of this too.
Perhaps there this is a play here in the market to create a new auditing firm that 99% automates all this for startups? sans fraud certs of course.
Don't. You are exactly the wrong kind of firm to be pursuing SOC2. SOC2 is like the corporate GPL of security. It's an infectious secret handshake company security teams swap in lieu of filling out security questionnaires. Nobody savvy takes it seriously. There will come a time where your business will grow to the point where it makes sense to pay for the secret handshake. The overwhelming most likely scenario in whi…
Isn't that no longer an issue in AI era?
Don't. You are exactly the wrong kind of firm to be pursuing SOC2. SOC2 is like the corporate GPL of security. It's an infectious secret handshake company security teams swap in lieu of filling out security questionnaires. Nobody savvy takes it seriously. There will come a time where your business will grow to the point where it makes sense to pay for the secret handshake. The overwhelming most likely scenario in whi…
Plus, even when you have SOC2 (+pen test, +ISO 27001), you'll still have to fill out questionnaires!
Don't. You are exactly the wrong kind of firm to be pursuing SOC2. SOC2 is like the corporate GPL of security. It's an infectious secret handshake company security teams swap in lieu of filling out security questionnaires. Nobody savvy takes it seriously. There will come a time where your business will grow to the point where it makes sense to pay for the secret handshake. The overwhelming most likely scenario in whi…
Don’t make anything harder on yourself before you have to and then at the point that you have to (like needing an authority to operate certificate for a classified network) you’ll have the resources to be able to get what you need
Avoid it for as long as you can. I worked at a startup that sold to enterprises. We had 6 employees. The CEO / sales was able to work around the SOC2 requirement every time.
I had no choice - we had so many security assessments spreadsheets sent by potential customers, that getting SOC2 saved us time in the long run.
Avoid it for as long as you can. I worked at a startup that sold to enterprises. We had 6 employees. The CEO / sales was able to work around the SOC2 requirement every time.
My company had 6 employees, I was the CTO and I can't imagine getting SOC2 certified without using Vanta - that was back in their early access/beta days. I had no choice - we had so many security assessments spreadsheets sent by potential customers, that getting SOC2 saved us time in the long run.
The problem is, Vanta will ask (suggest? come perilously close to demand?) you do a lot of engineering work that is absolutely not necessary for a SOC2 attestation. Worse still: whatever controls you attest in your SOC2, you're practically locked into. If Vanta has you set up some cloud detection capability, and it turns out as you mature your security organization that it wasn't necessary or even useful, you have a fight on your hands with your Type II auditor about why you stopped doing it.