Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →What pre-Series-A through Series-B startups are spending on security, what they are skipping, and the compliance gaps that still cost the most enterprise deals. Observation-based findings from our engagements, paired with cited industry data. Honest read; no vendor pitch.
The report below is a point-in-time analysis. This band is not. It is pulled automatically every hour from public security and regulatory feeds, filtered to what bears on a startup selling into an enterprise security review, and shown newest first. Headlines and summaries are each publisher's own words; follow the link for the full story.
Recurring in this batch: breach · hipaa · settlement · penalty
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) and the Aliso Viejo, California-based genetic (www.hipaajournal.com)
A 90-day period between hiring and onboarding is creating a blind spot in enterprise identity security, according to HYPR’s State of HR Identity Fraud Detection report. “Adversaries no longer need to breach a network when they... (www.helpnetsecurity.com)
Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware. (www.bleepingcomputer.com)
The Coast Guard confirmed evidence of malicious cyber activity on the VL Prosperity, but has not attributed the attack to Iran. (www.securityweek.com)
Modernizing Medicine, a Boca Raton, Florida-based company that provides cloud-based, AI-powered software and electronic health record systems for healthcare providers, (www.hipaajournal.com)
The Florida dermatology practice, Brevard Skin and Cancer Center, has agreed to a settlement to resolve class action litigation stemming (www.hipaajournal.com)
Most recent item 18 September 2026. Selection is automatic and unedited, so nothing here carries our opinion. For the version that does, we send a weekly read of what these stories mean for a Canadian company selling into the US. Get it here.
The figures below come from our own engagements and from the control libraries behind traztech Workspace. Each links to where the detail lives.
If you are running security at a startup in 2026, three things are different from the prior decade. Compliance is now table stakes for enterprise sales, AI features have created an entirely new attack surface, and the talent market for senior security leadership is impossibly tight. Founders are responding by combining lightweight in-house ownership with embedded operators and ruthless tool consolidation.
This report distils what we have seen across our engagements over the past 18 months. We do not present this as survey data. There is no survey. These are observations from hands-on engagements at startups ranging from pre-seed to Series B, supplemented by publicly available industry benchmarks where appropriate (citations inline).
Of the startups we engaged with in the past year, roughly two-thirds already had at least one enterprise deal in flight. In every one of those engagements, the customer's procurement team requested a SOC 2 report or, in its absence, a 200-question security questionnaire as a substitute. There is no version of the future where this gets less common. The trajectory is the opposite.
Founders consistently underestimate the timeline. A common pattern: founder closes verbal agreement on a $150K ACV deal, customer's security team kicks the questionnaire over, deal stalls for 90 days while founder scrambles. By the time the founder is audit-ready, two of three things have happened: the deal pricing has eroded, the customer's quarter has rolled and the stakeholder has moved on, or a competitor with a SOC 2 report on hand has quietly closed it instead.
We have run this engagement at over 30 startups. Average time to audit-ready is around 9 weeks; fastest was 6. If a deal is gating on it, that is the conversation to have; book a call and we'll scope it.
By our count, every startup we onboarded in 2025 had shipped at least one AI feature in production. The fraction that had performed any kind of adversarial testing on it: under 20%. The fraction that had a documented threat model for the AI surface: under 10%.
We performed initial AI security assessments on a subset of these in 2025 and 2026. The most common findings were not exotic. They were the same authorization and input-validation failures that have plagued web applications for two decades, surfacing in new wrappers:
None of these are theoretical. We have seen working exploits for each at production startups. The reason they ship is structural: AI feature teams move fast, security review is not in the loop, and the surface looks novel enough that traditional pentest scope doesn't cover it.
The startups handling this well share a structure: AI features have a documented threat model before they go GA, an external adversarial assessment within 60 days of launch, and a mid-engagement check-in three months later. The cost is small relative to the cost of a public incident; the goodwill with enterprise security buyers is large.
We bundle our remediation strategy with adversarial testing from our global and Canadian testing partners, whichever gives you the best value on the scope. Two firms, one engagement. Most AI assessments run 2 to 4 weeks.
The single most common security gap we walk into: no documented incident response plan. Or more precisely: a plan written for a SOC 2 audit that has never been tested and no one on the team has read.
According to the IBM & Ponemon Cost of a Data Breach Report 2024, organizations with a tested IR plan reduced breach cost by an average of $2.66M compared to those without. For a 50-person startup, that delta is more than the entire engineering payroll for a year.
Despite this, IR is consistently de-prioritized at the seed and Series A stage. Founders rationalize the deferral on three grounds:
Among our 2025 and 2026 engagements, the fastest-growing service line was incident response retainers, typically $1K to $3K/month for guaranteed response SLA, runbook ownership, and quarterly tabletops. The economics make sense: a single avoided escalation pays for years of retainer fees, and customer security teams now ask about IR retention status and ongoing vulnerability management during diligence.
Five years ago a fractional security leader was largely a bridge solution: a placeholder until the startup could hire the full-time role. In 2026, we are seeing the model entrench permanently for a specific category of startup. Those founders are strong on domain expertise but lack a peer technical co-founder, and they need senior judgment on architecture, security posture, and engineering culture.
Three observations from our portfolio:
The pattern that breaks these engagements is predictable: founders who hire a fractional CISO expecting them to implement the controls themselves end up disappointed. The role delivers judgment, ownership and accountability to buyers, not throughput. It works when the engineering capacity to act on it already exists or is bought alongside it.
The "best of breed" SaaS sprawl that defined 2018 to 2022 has reversed. Across our engagements, the average startup we walked into had fewer security tools in 2026 than in 2023, and the dollar value spent had reallocated toward fewer, deeper integrations.
Three drivers:
The net: a typical 30-person startup we audit in 2026 runs roughly 8 to 12 security/DevOps SaaS tools, down from a 2023 baseline of 15 to 20. The dollar spend per tool is up; the total spend is roughly flat.
Buyers treat the readiness quote as the variable cost and the audit fee as a fixed market rate. Our engagement record says the reverse is closer to the truth.
On one engagement we took a single, identical scope to four audit firms. The highest quote was 2.1 times the lowest. Same company, same systems, same criteria, same observation window. The spread was not explained by firm size or by brand: it was explained by how much uncertainty each firm believed it was pricing, and by how much of the work each assumed it would have to do itself.
That has a direct consequence. On a separate engagement, an audit firm revised its own quote down by $11,000 after the client's readiness position was documented and a preparation firm was confirmed. Nothing about the company changed between the two numbers. What changed was the amount of unknown work the firm was pricing against.
What this means in practice. Get audit quotes before committing to a readiness budget, take the same written scope to every firm, and tell them what state your programme is in. A first-time buyer comparing proposals side by side sees none of this, which is why the audit is the largest number most companies control least.
Detail in the four-firm pricing comparison and the vetting engagement.
Compliance automation is sold as the starting point. In our engagements it is more often the last thing that should be bought, and occasionally it should not be bought at all.
One client had a five-figure annual compliance platform subscription priced, approved and budgeted. They ran the entire programme in our workspace instead, kept the evidence at the end, and paid nothing for the licence. The platform was a real option that had been genuinely evaluated. It simply was not the thing that produced the report.
This tracks what the tooling does and does not do. Automation is good at continuous evidence collection, which is a real cost saver once you are maintaining a report across years. It does not decide what your controls should be, write them, fix what is broken, or answer an auditor. Those are what consume the calendar on a first programme, and they are the reason a dashboard full of green ticks does not equal a passed audit.
Detail in the platform cost engagement.
A venture-backed security company with fifteen people and no compliance programme reached a SOC 2 Type II across 76 controls with zero exceptions, holding 99.9% uptime through the observation window while serving millions of daily requests.
The instructive part is what produced that result. It was not more effort during the window. It was building controls whose evidence is a by-product of how people already work. The change-management control was a five-layer pull request approval flow where the safe path was also the fast path, so the audit trail existed without anybody remembering to create it. Any control that depends on somebody logging something manually will eventually produce an exception, because the week it matters is the week everyone is busy.
The second lesson is about ordering. On that programme the policy set was written before the asset inventory was finished, and several policies had to be revised once the real scope was known. The inventory is the cheapest work in a compliance programme and it constrains everything downstream. It should come first.
Detail in the full walkthrough.
Companies sequence frameworks because sequencing feels lower risk. Our engagement data suggests it is the more expensive path.
A data centre operator ran SOC 2 Type II across Security, Availability and Confidentiality alongside ISO 27001:2022 including the Climate Action Amendment, with physical and environmental controls in scope at three separate sites. A large share of Annex A maps onto the SOC 2 common criteria, so the overlapping control and evidence work was done once rather than twice. What ISO adds on top is the management system: risk methodology, Statement of Applicability, internal audit and management review.
The same engagement produced a second finding worth more than it sounds. The client was placed with a single firm that was both a licensed CPA firm and an accredited certification body. That meant one engagement letter, one evidence request process, one set of scheduling constraints and one relationship, instead of reconciling two assessors with two sampling approaches and two views of what evidence is sufficient.
Detail in the dual-framework engagement.
Adding Availability to a SOC 2 report brings A1.2 and A1.3 into scope, which means backups, recovery infrastructure and recovery testing all get sampled. Most companies decide this in a five-minute conversation and then live with it for years.
It is frequently the right call. For infrastructure and platform products, leaving Availability out invites the buyer question of why it was left out, and a narrow scope that prompts a question is worse than a wider scope that answers it. Processing Integrity is the opposite case: it applies to systems processing transactions on a customer's behalf, and stretching it to fit adds ongoing evidence obligations with no buyer asking for them.
The rule we apply: add the criteria your buyers ask about and leave out the ones they do not, because every criterion added is a set of controls somebody operates every week for the life of the report.
The readiness work and the audit are two separate costs. Readiness sprints start from $2,500 and a fixed-scope SOC 2 track is published on our pricing page; the audit itself is billed by an independent CPA firm. Audit quotes vary widely: across four firms quoting one identical scope, the highest was 2.1 times the lowest, so compare assumptions rather than headline numbers.
Our SOC 2 track is 75 days of preparation, a window we have hit every time we have run it. For a Type II the binding constraint is usually the observation period rather than the control work, because the report attests that controls operated across a period and that period has to elapse.
A Type I attests that controls are suitably designed at a point in time. A Type II attests that they operated effectively across a period. Type I gets a defensible artefact into a sales conversation now; the same control set then runs through an observation window and becomes the Type II, provided the controls were designed to produce evidence.
If your customers are mostly North American, SOC 2 is usually the shorter road. Once European or Middle Eastern buyers are involved, or you are selling into enterprises that work from an approved standards list, the ISO certificate does work the attestation does not. Running both together is frequently cheaper than sequencing them, because a large share of ISO 27001 Annex A maps onto the SOC 2 common criteria.
Artefacts a control produced, not documents describing a control. A first document request list commonly runs to around 84 items covering governance, people, identity and access, change management, monitoring and response, and data and vendors. A policy saying access is reviewed quarterly evidences nothing; the completed review, dated, with the reviewer named, evidences the control.
Not for a first or second readiness programme. Automation genuinely covers a minority of controls, and they tend to be the ones companies already pass. What fails audits is organisational: reviews that never ran, controls nobody owns. traztech Workspace is free and holds the control sets, evidence register, policy templates and readiness scoring, and you keep it when an engagement ends.
No. An audit firm has to stay independent of what it assesses, so it cannot design your controls, write your policies or build your evidence register. That constraint is what makes the report worth handing to a buyer, and it is why preparation and audit are two different firms.
The observation window being chosen after the work starts rather than before it. A Type II covers a period, so evidence has to exist across that period, and a control implemented last week cannot produce three months of history.
More than buyers assume. Across four firms quoting one identical scope on a recent engagement, the highest number was 2.1 times the lowest. On another, the firm reduced its own quote by $11,000 once the readiness position was documented, because there was less uncertainty left to price. Take the same written scope to every firm and tell them what state your programme is in.
Usually not on a first programme. One client had a five-figure annual subscription priced and approved, ran the programme in our workspace instead, kept the evidence and paid no licence fee. Automation is good at continuous evidence collection, which earns its cost once you maintain a report across years. It does not decide, write or fix anything.
Generally yes. A large share of ISO 27001 Annex A maps onto the SOC 2 common criteria, so overlapping control and evidence work happens once. We have run both in parallel across three physical sites. What ISO adds is the management system: risk methodology, Statement of Applicability, internal audit and management review.
Add the criteria your buyers ask about. Availability brings A1.2 and A1.3 into scope, so backups, recovery infrastructure and recovery testing get sampled. For infrastructure products it is usually right, because leaving it out invites the question of why. Every criterion added is a set of controls somebody operates every week for the life of the report.
This report draws on:
This is not survey research. We do not claim representativeness beyond our portfolio. Where we present a percentage, it reflects the share of our engagements exhibiting a behaviour, not the broader market.
Compliance is no longer a moat; it is table stakes. AI features have created a serious, under-tested attack surface that will produce its first wave of public incidents this year. Incident response remains the most underpriced investment a startup can make. And the fractional leadership model has graduated from stopgap to durable structure.
The startups that win on security in 2026 are not the ones with the largest team. They are the ones who got the systems in place early, kept the tooling tight, and bought senior judgment in the right shape (embedded, fractional, or retainer) for their stage.
Want a designed PDF version to share with your team or include in board materials? Drop your details and we'll email it within one business day.
Two-thirds of the founders we engage with start with one of the gaps in this report. The first conversation is free; the diagnosis is honest; the path forward is concrete, with clear pricing for every engagement.
Free templates
The SOC 2 readiness checklist, ISO 27001 gap checklist, incident response plan and vendor security questionnaire. Free, no card.
From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.