Earlier quoted context omitted.
If your goal is to maximize your posture against cyber threats, spending your time on SOC 2 compliance with Vanta (or similar) is a waste of time if you consider the amount of time spent compared to security gained. It's incredibly easy to get SOC 2 audited and still have terrible security. > forces you to go through a very useful exercise of risk modeling Have you actually done this in Vanta, though? You would have…
Probably the most useful aspect of SOC2 is that it gives the technical side of the business an easy excuse for spending time and money on security, which, in startup environment is not always easy otherwise (Ie “we have to dedicate time to update our out of date dependencies, otherwise we’ll fail SOC2”). If you do it well, a startup can go through SOC2 and use it as an opportunity to put together a reasonable cyberse…
Mercor says it was hit by cyberattack tied to compromise LiteLLM
31–40 of 62 posts
Re: Mercor says it was hit by cyberattack tied to compromise LiteLLM
#32Earlier quoted context omitted.
I am not defending Delve or anything and I hope they get what they deserver but there is no correlation between SOC2 certification and the actual cyber capability of a company. SOC2 and ISO27001 is just compliance and frankly most of it is BS.
It might feel like BS, and I'm inclined to agree with you because of the security theater aspect. (For example, Mercor had their verification done by what appears to be a legitimate audit firm.) But it's not useless. It still forces you to go through a very useful exercise of risk modeling and preparation that you most likely won't do without a formal program.
Because there's no adversarial pressure as a check and balance to the security, and AICPA is clearly just happy to take the fees, it's a hollow shirt. It's like this scene from The Big Short. https://youtu.be/mwdo17GT6sg?si=Hzada9JcdIPfdyFN&t=140
As usual, it's only people that care that force positive change. The companies that want good security will have good security. Customers who want good security will demand good security.
Re: Mercor says it was hit by cyberattack tied to compromise LiteLLM
#33Re: Mercor says it was hit by cyberattack tied to compromise LiteLLM
#34Earlier quoted context omitted.
I am not defending Delve or anything and I hope they get what they deserver but there is no correlation between SOC2 certification and the actual cyber capability of a company. SOC2 and ISO27001 is just compliance and frankly most of it is BS.
Delve and Emdash. Are there more products or companies with similar names?
Re: Mercor says it was hit by cyberattack tied to compromise LiteLLM
#35Earlier quoted context omitted.
It might feel like BS, and I'm inclined to agree with you because of the security theater aspect. (For example, Mercor had their verification done by what appears to be a legitimate audit firm.) But it's not useless. It still forces you to go through a very useful exercise of risk modeling and preparation that you most likely won't do without a formal program.
It doesn't force you go through risk modelling because by now most SOC2 platforms have templates you just fill in the blanks and sign off. Conversely, the auditors are paid by the company, so their incentive is to pass the audit so the client can get what it wants. Because there's no adversarial pressure as a check and balance to the security, and AICPA is clearly just happy to take the fees, it's a hollow shirt. It'…
Re: Mercor says it was hit by cyberattack tied to compromise LiteLLM
#36> The incident also prompted LiteLLM to make changes to its compliance processes, including shifting from controversial startup Delve to Vanta for compliance certifications. This is pretty funny. The leaked excel sheet with customers of Delve is basically a shortlist of targets for hackers to try now. Not that they necessarily have bad security, but you can play the odds
I am not defending Delve or anything and I hope they get what they deserver but there is no correlation between SOC2 certification and the actual cyber capability of a company. SOC2 and ISO27001 is just compliance and frankly most of it is BS.
A) I tie the cybersecurity activities to business revenue enabling outcomes (unblocked contracts), and second to reduced risk (as people react less to this when spending the buck).
B) with the political capital from point A) I actually operate a cybersecurity program, justify DevSecOps artefacts, threat modeling, incident response exercises, etc.
What this SOC2 reports, ISO27k certificates are, more like a standardization for communicating the activities of the org to outside people, and getting an external person to vet that the org doesn't bulls*t too much. but at the end of the day, the organization is responsible for keeping their house in order.
Re: Mercor says it was hit by cyberattack tied to compromise LiteLLM
#37Re: Mercor says it was hit by cyberattack tied to compromise LiteLLM
#38I am genuinely wonder if anyone have had success landing gigs at Mercor.
Re: Mercor says it was hit by cyberattack tied to compromise LiteLLM
#39Re: Mercor says it was hit by cyberattack tied to compromise LiteLLM
#40I am genuinely wonder if anyone have had success landing gigs at Mercor.