That was the reassuring security language displayed alongside both SOC 2 and ISO 27001 badges.
And yet two independent researchers accessed a production platform using the password “123456.” The account had been active since 2019—with no MFA, no monitoring, and no access review. The breach exposed 64 million records.
For an organization promoting two of the most recognized security certifications in the world, this represents a significant lapse in basic security hygiene.
Board-Level Takeaway
I’ve had a number of recent discussions with executives and boards about third-party vendor compliance programs. Nearly every organization makes the same mistake:
They ask: “Are you SOC 2? Are you ISO 27001?” The vendor says yes. And the conversation ends.
But here’s what this incident makes clear:
SOC 2 + ISO 27001 together do not guarantee operational security.
They confirm that specific controls, in a specific environment, were reviewed at a moment in time. They do not confirm that:
- every system is in scope,
- password policies are enforced consistently,
- identity governance is functioning,
- dormant accounts are removed,
- or controls are monitored continuously.
The vendor publicly displayed both certifications — and yet a forgotten 2019 test account using one of the most common passwords on the internet was still sitting in production.
That is not a certification failure. It is a governance and oversight failure.
And it highlights a larger problem across the industry:
Organizations treat certifications as conclusions, when they should be treated as the starting point.Even McDonald’s — a global brand with a mature vendor management program — had this slip through.
That’s why boards must go beyond the badges and start asking deeper, higher-value questions:
- What exactly was in scope for SOC 2 and ISO 27001?
- Which systems were excluded?
- When were the audits performed, and by whom?
- How are controls maintained between audits?
- How do you detect dormant or weak accounts?
- Show us the operational evidence, not just the certification.
Certifications reinforce trust. They do not replace due diligence.
Don’t stop at SOC 2 and ISO 27001. Validate. Verify. And keep asking questions.


