Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
The Compliance Brief · Issue 4

What CISA's two red teams say about your SOC 2

Free weekly email

Published September 1. Get the next one.

One email every Tuesday: what changed in security and compliance that week, and what it means if you sell to enterprise buyers.

Free. Unsubscribe in one click, and replies reach Jacob directly. Read the latest issue or browse the archive.

Quiet week for regulators, busier week for anyone who owns a build pipeline or a vendor list. The through line in most of what landed is detection and third parties, which happens to be where most US security reviews spend their time too. Five things worth your attention, and my read on each.

CISA red-teamed two organizations and only one saw it coming

Source: CISA

CISA ran simultaneous red team assessments at two organizations and published the comparison. In both cases the red team reached full domain compromise and touched sensitive business systems and cloud resources. Organization A never detected or contained the activity, while Organization B spotted the initial compromise attempts and isolated the affected systems.

Our take

Both were breached, so the difference was entirely in response, and that is the same argument I make when a founder asks why we care so much about their logging and alerting before a SOC 2 audit. Your auditor will accept a screenshot of an alerting policy, your enterprise buyer's security team increasingly will not, and this advisory is a free, citable explanation of why. Read the Organization B side and ask honestly whether your on-call would have noticed any of it at two in the morning.

McKesson breach came through third-party applications

Source: BleepingComputer

McKesson disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft. The ShinyHunters extortion group claims it took 284 million patient records, a figure that comes from the attackers and not from McKesson.

Our take

Ignore the record count, which is unverified and usually inflated, and look at the entry point. Connected SaaS applications with broad OAuth scopes keep being the way into large healthcare and finance environments, which is exactly the risk your prospect is thinking about when they classify you as a critical vendor. If you handle PHI or process payments, expect the questionnaire section on your own subprocessors and token scopes to get longer this autumn, and have a real answer about how you would revoke access across every integration in an afternoon.

Two arrests in the TeamPCP open-source supply chain spree

Source: Krebs on Security

The Australian Federal Police arrested two men in Western Australia, aged 21 and 23, over alleged membership in TeamPCP. The group is blamed for what Krebs describes as the longest running spree of software supply chain attacks, built around malicious open-source packages that hit thousands of businesses globally.

Our take

Arrests are good news and change nothing about your dependency tree, because the packages that were published are still out in caches and lockfiles. What I would do this week is confirm you can produce an SBOM for your production build on demand and that someone reviews new transitive dependencies before they ship. That capability also happens to answer one of the harder questions in a US enterprise vendor review, so the work pays twice.

JFrog Artifactory flaw lands in the KEV catalogue

Source: CISA

CISA added three actively exploited vulnerabilities to the Known Exploited Vulnerabilities catalogue: an ownCloud authentication flaw, an unspecified Linux kernel issue, and a path traversal issue in JFrog Artifactory. The catalogue is tied to CISA's binding directive on prioritizing security updates by risk for federal agencies.

Our take

Artifactory is the interesting one for this audience because it usually sits inside the build environment with credentials to everything downstream. You are not a US federal agency, but plenty of your customers now write KEV remediation timelines into their vendor contracts, and auditors have started asking how you learn a KEV entry exists at all. If the honest answer is that someone reads a newsletter, that is a gap you can close cheaply with an automated feed into your ticketing system.

Cyber claims are fewer and far more expensive

Source: Infosecurity

Chubb reported that average losses per cyber claim are rising even though the number of claims has fallen. Growing privacy litigation in the United States is a significant contributor to the increase in claim costs.

Our take

This matters to you as a buyer of insurance, since your US contracts probably specify a cyber liability limit and renewal quotes are being priced off exactly this trend. Underwriters will ask harder questions about MFA coverage, backup isolation and incident response retainers, and the answers you give them are mostly the same evidence you already assembled for SOC 2. The privacy litigation angle is the part I would watch in fintech, because the exposure is drifting from breach response costs toward how you collect and share data in the first place.

Nothing this week forces a change in plan, though the CISA advisory is worth twenty minutes if you own detection. I will be watching whether the privacy litigation trend starts showing up in the contract language coming back from US buyers.

Jacob

Share this issue LinkedIn X Email

Free weekly email

Get the next issue on Tuesday

One email a week from Jacob Masse: the security and compliance stories that changed something that week, and what each one means if you sell software to enterprise buyers. Five stories, a take on each, five minutes to read.

Free. Unsubscribe in one click, and replies reach Jacob directly.

Go deeper

Every past issue · RSS feed