3 ms·
Some thoughts having just completed this: * It costs $40k in year one and $30k/year in subsequent years if you do the now typical stack of Vanta, pen test, vul
by sbinthree 6y ago
Some thoughts having just completed this:
* It costs $40k in year one and $30k/year in subsequent years if you do the now typical stack of Vanta, pen test, vulnerability monitoring and audit fees. This makes ROI pretty straight forward to figure out.
* There's really no benefit to getting Type 1, you just need to get the Type 1 posture and then wait out the monitoring period in order to get type 2. If the customers actually care, they are smart enough to know that it's a lot harder to fudge it for 6 months than it is for one four hour Zoom call.
* You can definitely get to about 60% of SOC2 just doing obvious best practice (code reviews, SSO, HTTPS only, database alerting). The next 20% is worthwhile but not intuitive, the final 20% is neither.
Agreed with the top comment about infosec teams being reasonable. At this point I think it would be pretty hard to do deals with public companies without having Type 2, and our domain isn't even that security focused.
- marcinzm 6y ago>At this point I think it would be pretty hard to do deals with public companies without having Type 2, and our domain isn't even that security focused. Even if you avoid SOC2, the security questionnaires (mostly avoidable if you have SOC2) from large companies can be so onerous if you're doing any sensitive work for them that SOC2 would be cheaper and less effort than the time spent on the questionnaires and infrastructure changes to meet them.
- rficcaglia 6y agoDefinitely paying too much @ $40K/$30K. Audit firms will cut their costs - don't take their first offer, it's a negotiation. Renegotiated down every year...they will want to reduce churn. Also, there are open source versions of Vanta and similar but those aren't really necessary - helpful - but not necessary. Same for pentests - I have had this conversation many times with SOC2 auditors to show me where it says you must have a pentest - many SOC2s later, never had to have one. That said customer contracts may require it, and some even specify the firms or onerous requirements for the chosen firms. We often argue Red Teaming exercises are better and win with that. I'll post a list of cost saving ideas up if anyone is interested. As for ROI - SOC2 is really only a sales enablement tool, nothing more. So it's really how many enterprise deals you will lose without SOC2 vs. how many you will win, and at what revenue. You can also negotiate transparently with your customer - most will say they want SOC2 but then if you add in extra cost to cover it, they back off. Until you have a 100K+ recurring (3 year ideally) deal ready to walk away, push back hard and be transparent with them on the added costs for paperwork. Offer to have a call with their security team and walk through your real security processes instead. Most customers are reasonable once you get past the outsourced procurement team. Helps to have a business sponsor who can cut through the red tape.
- masonhensley 6y agoYes, can you please share your list. > open source versions of Vanta ... not aware of anything in this field. This has been on my "one day if I have time" lists to build.
- rficcaglia 6y agook will do - I will also post an actual (sanitized) Type 2 IRL so we can dispel the mystery and the need for experts. It's all straightforward stuff. But give me 24 hours since my family is giving me cross looks at spending more time online than with them on a holiday weekend ;)
- senorsmile 6y agoReminder on this.
- tptacek 6y agoI've worked with multiple organizations through their entire SOC2 process and interviewed security teams from a bunch of other SOC2'd companies and the impression I'm left with is that you can get 100% of SOC2 just doing obvious best practices. Part of the reason I wrote this is to encourage engineering teams to push back on SOC2 processes that demand them to do new weird things. I have kind of a meh opinion about Vanta, for what it's worth.
- christinac 6y agoChristina, Vanta founder here. Very much agree with you about SOC 2 == obvious best practices if done reasonably! That’s one of the “secrets” of SOC 2: if you speak some compliance, you can make most of the SOC 2 work for you, implementing best practices, getting the rest of the org to prioritize them, etc. (This is what we like about SOC 2 at Vanta: it can turn meaningful, difficult-to-measure security work into high-pri sales collateral.) If you don’t speak compliance and have a SOC 2 consultant who doesn’t speak engineering, you’re more likely to end up with absurd arguments and bookkeeping (“but you have to use a WAF there’s just no other way!” etc.)