80% of Compliance has always been a performative box checking exercise. They delivered the product that every company wanted - make the box checking faster.
There is a legal liability that comes with the bow checking. Nobody cares about box checking. Everyone cares about legal liability.
Delve – Fake Compliance as a Service
281–290 of 327 posts
Re: Delve – Fake Compliance as a Service
#282Earlier quoted context omitted.
It has to work in with a bunch of organisations who are doing (or attempting to do) ITIL 4 and are fairly insistent on things like consistency across ITSM platforms. The things is, you know and I know, ITIL is like sex in high school. Everyone says they're doing it loads, everyone says they know all about it, everyone says they're really good at it, but no-one is any good at it, no-one knows anything about it, and no…
This is hilarious. I had to steal this for my Twitter post.
Re: Delve – Fake Compliance as a Service
#283Earlier quoted context omitted.
Trust me, you can lie and get away with it if you go through YC and dropped out of a top university. Garry Tan blocked me on X for pointing this out. It's a big club, and you ain't in it! Fortunately, some of the old-YC spirit seems to be alive here on HN still.
They likely barely had a product when they applied to YC. It's more interesting as to why this wasn't discovered (if it is even true) when they were raising their Series A.
Re: Delve – Fake Compliance as a Service
#284Earlier quoted context omitted.
>I had no idea this story existed and woke up to claims that I was obviously* suppressing it. To be fair, it seems you’re saying the submission was being suppressed, just not intentionally. Lots of props of course for transparency and reboosting the story
When people use the word "suppressed" they usually mean that we were personally intervening to do something suppressive. This being the internet, they say that with supreme confidence whether it's true or not. For example, the comment I was referring to, which was the first one I saw, said "It is being suppressed by @dang" ( https://news.ycombinator.com/item?id=47457010 ). You can't get more personal, definitive, or…
In my other comment, I actually did not mean to write “it is being suppressed by dang” but rather “it is being suppressed @dang”… Because my impression is that that alerts you somehow? I may be wrong about this.
Please give your long-time readers the benefit of the doubt. I was correct that it was being suppressed. I'm also very thankful for your moderation of the site. I know you do a lot of hard work on that front.
Re: Delve – Fake Compliance as a Service
#285Question: how likely is it that a number of 20-year olds have the passion of solving the problem of compliance auditing? I can hardly imagine that I'd even be interested in taking a look at the domain. It's just... so mundane. Or maybe the alpha-type overachievers don't care about the domain but the opportunity?
Re: Delve – Fake Compliance as a Service
#286[flagged]
Re: Delve – Fake Compliance as a Service
#287Earlier quoted context omitted.
> Not a single founder wakes up in the morning thinking to themselves: "oh I wish I could make my company XYZ-123 compliant!" Somehow I doubt that you are in the B2B/Enterprise space. When you're pitching demos and you hear from people "we really wish we could buy your product but we can't because Finance won't approve the expenditure unless you get XYZ-123", and you hear that over and over again because that is the…
I think we are confusing something here. > we really wish we could buy your product but we can't because Finance won't approve the expenditure unless you get XYZ-123 So you are not dreaming about XYZ-123 compliance, you are dreaming about being able to make sales to corporate entities. This is a subtle semantic difference. > there are founders who wake up in the morning wishing Wishing juicy corporate customers. Not…
Well guess what people told you they wanted? They wanted XYZ-123. And you're not going to find success until you learn to get obsessed about making something people want.
Re: Delve – Fake Compliance as a Service
#28880% of Compliance has always been a performative box checking exercise. They delivered the product that every company wanted - make the box checking faster.
There is a legal liability that comes with the bow checking. Nobody cares about box checking. Everyone cares about legal liability.
Re: Delve – Fake Compliance as a Service
#289Earlier quoted context omitted.
Okay, so who are we supposed to go to for SOC 2 compliance now if any number of the compliance automation companies might be charging 5 figures to do it fradulently?
Last time I went through SOC 2 we talked to our auditor about this. His view was that there are and basically always have been auditors/companies that will sign off on anything without verifying it if you're paying them. The rest of the industry knows who they are though. If you are taking things seriously and hire an auditor who does, that's one of the things that they look at when you're reviewing the reports from…
> But what do you do when the enterprise you are selling to asks you to show that pen-test report (which you never did despite paying for it, because Delve told you a pentest-tools.com vulnerability scan sufficed)? When they ask for your most recent risk assessment, do you just screenshot Delve’s pre-fabricated assessment and pray nobody will pay attention?
> It was that point where the realization sank in. We knew we messed up. We were unable to answer most questions honestly without jeopardizing the deals we were trying to land. We scrambled to get things done the proper way outside of Delve, in an effort to pretend to know what we were doing, but it ended up simply being too much work to get done quickly enough to save things.
Re: Delve – Fake Compliance as a Service
#290I hope that with LLMs, answering security questionnaires will be much less time consuming for companies and less would opt out to get a full blown SOC2 cert. But it will probably play the other way.