How is it bigger than the auditors that Delve was using. Surely Delve wasn't there only client. Delve is just a drop in the bucket.
We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical
21–30 of 83 posts
Re: We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical
#22Is SOC 2 legit? I have this on my roadmap but now I’m wondering if it’s just security theatre?
We were considering getting certified, but it only really makes sense if your customers require you to have it.
Re: We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical
#23There's a fair amount of boiler plate language in these reports, and a bunch of re-stating the SOC 2 controls. I'd expect two reports (same auditors, same platforms) to be nearly identical. If they're both using AWS, Github, Stripe, Vetty, they're subbing a lot of the exact same thing out to the same companies, referencing the same set of internal controls.
Reading ours. There's a section titled $Company's Controls, followed by 20 pages listing the various SOC 2 controls. e.g.
---
CC9.0 Common Criteria Related to Risk Mitigation
CC9.1 The entity identifies, selects, and develops risk mitigation activities for risks arising from potential business disruptions.
IR-01 A Security Incident Response Plan that outlines the process of identifying, prioritizing, communicating, assigning, and tracking confirmed incidents through to resolution is accessible to all relevant employees and contractors and is reviewed annually.
---
Then there's another 20 pages of those same controls being listed, some language about how they tested the controls, and hopefully "No Exceptions Noted".
That's not going to change much between companies.
Re: We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical
#24> "We may receive compensation from vendors listed below. All recommendations are based on independent research." this + new HN account? couldn't be more obviously a competitor. not to defend delve, but can’t be pushing this like some noble effort with the goal of transparency also lol @ the fake realtime "just searched for" toasts on a setInterval in the bottom left.
https://trustcompliance.xyz/_next/static/chunks/17psh0.nytnh...: 404 Not Found
Re: We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical
#25Is SOC 2 legit? I have this on my roadmap but now I’m wondering if it’s just security theatre?
It's complicated. In theory, SOC2 forces you to do some important stuff, like define your threat model and say "I can mitigate against the threats and prove that my mitigations are in place". The problem is always that the companies that care don't need it but are burdened with it while the companies that don't care will just checkbox their way through it. It sort of enforces a very baseline security posture, in theo…
The idea that SOC2 forces you to do important stuff gets it backwards; SOC2 documents your existing practice, and demands only extremely high-level controls that you can deliver in any number of ways. Your security practice should (minimally) inform your SOC2, not the other way around.
Re: We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical
#26Is SOC 2 legit? I have this on my roadmap but now I’m wondering if it’s just security theatre?
Re: We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical
#27Earlier quoted context omitted.
Genuinely curious: if you just need an independent audit report to check a box, do you really care how good a job the auditor did?
"You" probably don't, but it's not just "you". There's also the counterparty who's asking to see that report. Maybe they're doing it for paper-pushing purposes of their own, but ultimately, somewhere up the chain, there's someone thinking "I can't personally audit all my suppliers, and I can't be sure they're doing the right thing, so I'm going to ask them to get an independent audit". Of course, this shows that the…
Is it true, though? Or has everyone just been psyched into asking for that certification out of a vague fear of "consequences" or of being left behind?
Re: We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical
#28Is SOC 2 legit? I have this on my roadmap but now I’m wondering if it’s just security theatre?
It's security theater. Friendly plug for Oneleet, who actually talked us out of getting it. We were considering getting certified, but it only really makes sense if your customers require you to have it.
Re: We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical
#29Just know that alot of startups with all star founders are closer to delve than not. Its mostly marketing, "look at this MIT genius that noticed something about legacy xyz industry that no one else did" Truth is venture funds are allocating a limited pie of what is really societies capital to people that dont deserve it
Something bad happens because of lack of regulation -> People strive for regulation -> Govt's actually regulates and sets some norms/procedures -> system works for a while -> Then someone takes the same idea and molds it into something else to bypass the regulation -> they get promoted because they are "clever" and get rewarded -> Then something bad happens as the tool is used by public.
From Prediction markets to Buy now, pay later to Delve to so many other things.
Is there a name to this particular phenomenon, because this just keeps on repeating in multiple industries.
Re: We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical
#30Looking at our SOC 2 report (we don't use Delve, our auditor isn't on their list) I don't think this is quite the smoking gun it might look like if you're not reading SOC 2 reports for a living. There's a fair amount of boiler plate language in these reports, and a bunch of re-stating the SOC 2 controls. I'd expect two reports (same auditors, same platforms) to be nearly identical. If they're both using AWS, Github,…