Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
The Compliance Brief · Issue 5

Court records, driver's licences, and an FTC bill

Free weekly email

Published September 8. Get the next one.

One email every Tuesday: what changed in security and compliance that week, and what it means if you sell to enterprise buyers.

Free. Unsubscribe in one click, and replies reach Jacob directly. Read the latest issue or browse the archive.

Four of the five things worth reading this week were somebody else's vendor getting breached, which tells you where the pressure is going in security reviews. The fifth was the FTC collecting money from a Canadian payments company for what its merchants did. If you sell software into the US and you hold or process anything on a customer's behalf, all of it lands on you eventually.

Thomson Reuters court software breached in March, disclosed in September

Source: The Hacker News

Thomson Reuters disclosed that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing unit, in March 2026. The company said it discovered the activity on June 30, 2026. Affected courts include at least 11 US states, the US Virgin Islands and Ontario, and a subset of the records could contain individuals' names and other sensitive data.

Our take

The number that matters here is not the state count, it is the four months between intrusion and detection, followed by another two before public disclosure. Every enterprise security questionnaire you fill out asks how quickly you detect and notify, and buyers are getting better at asking whether your clock starts at intrusion or at discovery. If your incident response policy commits to a 72 hour notice and you have no realistic way to know you were breached in the first place, that commitment is decoration.

An ID verification vendor appears to be the source of 153 million licence scans

Source: Krebs on Security

A new dark web identity theft service is selling digital scans of more than 153 million driver's licences belonging to people in the United States and Canada. Interviews with affected individuals suggest the images were siphoned from a widely used identity verification company based in Louisiana. The FBI's New Orleans field office opened a formal inquiry.

Our take

Anyone doing KYC has an identity verification vendor, and most founders I talk to have never asked that vendor how long it keeps the document images after the check comes back clean. Retention is the control that would have made this a much smaller story, and it costs nothing to shorten. I would go find out this week what your provider's retention period is, get it in writing, and be ready to answer the same question when a US bank's third party risk team asks you.

FTC takes $4.85M from Nuvei over who it let onto its rails

Source: FTC

Nuvei will pay $4.85 million to settle FTC charges that it opened and maintained payment processing accounts for merchants it knew or should have known were running deceptive schemes, including tech support scams that took millions from US consumers. The settlement also requires the company to put merchant screening practices in place. The complaint names the Canada-based parent and several subsidiaries.

Our take

The FTC is right on this one, and the useful detail for our readers is that being headquartered in Canada bought Nuvei nothing. If your platform onboards merchants, moves money, or resells payments as a feature, the standard the FTC is applying is what you should have known, not what you actually looked at. Screening and ongoing monitoring evidence belongs in the same folder as your SOC 2 artifacts, because that is where a US enterprise buyer's legal team will eventually go looking.

McKesson tells the SEC it was hit through third-party applications

Source: Help Net Security

McKesson disclosed a cybersecurity incident in which attackers got into third-party applications and stole data, with the intrusion detected on August 25, 2026. The SEC filing says the investigation is in its early stages and the company has not determined the incident is material or likely to be material. ShinyHunters has claimed the theft of 284 million records.

Our take

Read that filing from the other side of the table. You are the third-party application in somebody's stack, and when a customer of yours writes their own version of this disclosure, your name goes in it. What I would take from this is that the "not yet determined to be material" holding pattern is now the norm for the buyer, which means your contract notice obligations will keep getting shorter while theirs stay vague.

AI coding agents are pulling packages nobody registered

Source: Schneier on Security

Researchers scanned 6,214 live domains belonging to defence contractors, Fortune 500 and large tech companies and found 8,265 llms.txt and llms-full.txt files. Of those, 120 on different sites pointed to code packages or domain names that were not registered. The researchers registered some of the unclaimed names and hosted packages there to see what agents would do with them.

Our take

This is dependency confusion with a new delivery path, and the old defences still apply. Pin your dependencies, keep an internal registry that fails closed on unknown names, and make sure an agent cannot install anything that a human would not have been allowed to install. Worth checking whether your change management evidence still holds up now that some of your commits were written by a tool that resolves its own dependencies.

Nothing this week changes what a US security review will ask you, but three of these stories change how hard the follow-up questions will be. I will keep watching the Thomson Reuters notifications to see how the Canadian side is handled.

Jacob

Share this issue LinkedIn X Email

Free weekly email

Get the next issue on Tuesday

One email a week from Jacob Masse: the security and compliance stories that changed something that week, and what each one means if you sell software to enterprise buyers. Five stories, a take on each, five minutes to read.

Free. Unsubscribe in one click, and replies reach Jacob directly.

Go deeper

Every past issue · RSS feed