We Worry About Security So You Don’t Have To.

A vendor publicly displayed both SOC 2 and ISO 27001 certifications — yet a five-year-old account protected by the password “123456” led to the exposure of 64 million records. This post examines why certifications alone don’t equal security and why boards must push beyond compliance checkboxes when overseeing third-party risk.

That was the reassuring security language displayed alongside both SOC 2 and ISO 27001 badges.

And yet two independent researchers accessed a production platform using the password “123456.” The account had been active since 2019—with no MFA, no monitoring, and no access review. The breach exposed 64 million records.

For an organization promoting two of the most recognized security certifications in the world, this represents a significant lapse in basic security hygiene.

Board-Level Takeaway

I’ve had a number of recent discussions with executives and boards about third-party vendor compliance programs. Nearly every organization makes the same mistake:

They ask: “Are you SOC 2? Are you ISO 27001?” The vendor says yes. And the conversation ends.

But here’s what this incident makes clear:

SOC 2 + ISO 27001 together do not guarantee operational security.

They confirm that specific controls, in a specific environment, were reviewed at a moment in time. They do not confirm that:

 

  • every system is in scope,
  • password policies are enforced consistently,
  • identity governance is functioning,
  • dormant accounts are removed,
  • or controls are monitored continuously.

 

The vendor publicly displayed both certifications — and yet a forgotten 2019 test account using one of the most common passwords on the internet was still sitting in production.

That is not a certification failure. It is a governance and oversight failure.

And it highlights a larger problem across the industry:

Organizations treat certifications as conclusions, when they should be treated as the starting point.

Even McDonald’s — a global brand with a mature vendor management program — had this slip through.

That’s why boards must go beyond the badges and start asking deeper, higher-value questions:

 

  • What exactly was in scope for SOC 2 and ISO 27001?
  • Which systems were excluded?
  • When were the audits performed, and by whom?
  • How are controls maintained between audits?
  • How do you detect dormant or weak accounts?
  • Show us the operational evidence, not just the certification.

 

Certifications reinforce trust. They do not replace due diligence.

Don’t stop at SOC 2 and ISO 27001. Validate. Verify. And keep asking questions.

RELATED POSTS

Discover more from Stasiak

Subscribe now to keep reading and get access to the full archive.

Continue reading

[mailpoet_form id="5"]
[mailpoet_form id="1"]