Live data from Hacker News

Delve – Fake Compliance as a Service

deepdelver.substack.com

321–327 of 327 posts

Re: Delve – Fake Compliance as a Service

#321
post #317

Earlier quoted context omitted.

Yes, I know it first-hand. At least in cybersecurity, there are no certifications that "certify" that you are secure. There are plenty of them that will assess your processes, their execution, etc., but the reality of the risk is next door. This is typically the case for ISO 27001, which has ISO 27002 (the ex British Standard from the 90s) that theoretically governs the controls you should have in place. But it simpl…

can you please explain what is the wrong approach and how it would be correct/good?

I am speaking from the perspective of someone who has been running cybersecurity for 30 years in very large companies. It will be different from smaller-sized entities, where both the risk landscape and the capabilities differ.

This is really a two-layered approach: you need to have a mechanism to manage your processes, and a real-life risk assessment. This last part is usually what fails most because there are not many people who can build a comprehensive risk analysis.

The problem with risk analysis is that you either have consultants who read books about risk but never operationally managed cybersecurity (and they provide "high level" risks which as useless without the "low level" part), or tech people who understand their part very well and see it as the most important. Having a very good CISO is what helps.

This CISO should also have politico-socialo-whatever leverage to make things happen. Put them in a position where their words are not the words of god and you fail immediately.

A large company is absolutely not homogeneous - as opposed to what reports will state. There is usually a core that is well known, and then 10 or 100 tentacles of semi-controlled systems where bad things happen. This blindness to the reality of the company is what hits the hardest.

How to manage a complex system is not for a HN comment, this requires time, resources and know-how. And leverage.

Re: Delve – Fake Compliance as a Service

#322
post #86
post #3

Forbes 30u30 pipeline remains undefeated. How did none of this come up during diligence? Feels like a prime example of too good to be true.

Dishonesty is high signal for VC Like no one characterizes it like that, but this is the same business where you can tell a story about hiring a bunch of college friends to pretend to be your employees so a client comes to your "office" and thinks you're a legitimate business. And instead of looking in horror at how casually you'll lie to get business it's seen as scrappy and whimsical.

They probably saw good results with this back when everyone could take a piece of Craiglist's business and make a billion bucks. Now you're just left with the ethos of cheating your way to the top without a real business to attach it to.

Re: Delve – Fake Compliance as a Service

#323

Earlier quoted context omitted.

> 80% of Compliance has always been a performative box checking exercise. You're making the same mistake as most people do: it's 80% box checking but that doesn't make it performative, the box checking is here so that the dude who checked the box become legally responsible for what's happening if they haven't done what they said they did. If you didn't check that box you could always claim you didn't know you weren't…

Not really, and I kinda envy you that you haven't really worked up close with compliance-related people. A lot of compliance is basically corruption - while in country A, you might fall out of a window if you don't buy from the right people at 10x prices, but in 'civilized' country B, you have to buy from vendor X (who has the necessary paperwork), at 10x prices, or you wont be able to sell the product - and there ar…

You are confusing two things:

- the requirements.

- the compliance process that makes sure the company members at all level follow the requirements.

Yes, in many topics, particularly in IT, there's no good requirements being enforced, because the people suggesting them are mostly grifters. But that's not a problem with compliance proper, it's simply a garbage in garbage out process.

Re: Delve – Fake Compliance as a Service

#327

Earlier quoted context omitted.

> 80% of Compliance has always been a performative box checking exercise. You're making the same mistake as most people do: it's 80% box checking but that doesn't make it performative, the box checking is here so that the dude who checked the box become legally responsible for what's happening if they haven't done what they said they did. If you didn't check that box you could always claim you didn't know you weren't…

Not really, and I kinda envy you that you haven't really worked up close with compliance-related people. A lot of compliance is basically corruption - while in country A, you might fall out of a window if you don't buy from the right people at 10x prices, but in 'civilized' country B, you have to buy from vendor X (who has the necessary paperwork), at 10x prices, or you wont be able to sell the product - and there ar…

> certification TP conditional on using the software

You’re saying auditors are requiring you to use specific software, or something like that? Sounds like your company picked bad auditors. Compliance auditors don’t normally mandate things like that.

A compliance auditor’s job is to ensure processes meet compliance requirements, not dictate specific tools.

Post reply on HN