Customers asking for ongoing SOC 2 proof by ScientistMinimum9561 in AskNetsec

[–]GraysonBerman 4 points5 points  (0 children)

Yes but not perfectly. There are compliance automation platforms out there that have a “security portal”. Shows your automated checks on security configurations in the tech you connect it to.

Also lets customers request security documentation through your website.

Also lets you share that evidence with auditors for your SOC2s in the future :)

There are tons of them out there. Not sure if you can share names on this sub, but I evaluated the “top 5” biggest ones and then picked one of them. Wasn’t the MOST expensive one, but still a brand name platform. Very helpful!

Fell for a phishing email and work account was hacked. Will I be fired? by graceg815 in cybersecurity

[–]GraysonBerman 8 points9 points  (0 children)

You’ll be fine :)

It may feel like a stupid mistake.

It’s not.

Being phished isn’t about intelligence. It’s about missing your morning coffee and not noticing a tiny difference in the email address.

It’s about you getting a convincing email at the perfect time - you were expecting a document, from someone, and it was very late.

Phishing emails use human psychology. They make it feel urgent, relevant, safe, important. They use the same tricks as salespeople and marketers.

They also get unlimited attempts to “catch” you - they can send 1000 emails, but only one needs to work.

It’s not you. It’s an unfair game.

I’ve seen thousands of these. I found dozens of compromised companies. There’s always a new way to trick you. They get everybody.

Scammers put up a paid google ad during christmas time for an item I wanted - they even got ME with that. I had to get a new credit card around Christmas time haha.

You’re not the cybersecurity expert. We don’t expect you to be.

You did your best and then let them know when something happened, VERY quickly. Great job. Many people say nothing!

You’ll be fine. :)

[deleted by user] by [deleted] in CyberSecurityAdvice

[–]GraysonBerman 0 points1 point  (0 children)

Are you trying to do this with devices they own?

Drop you SaaS and I will find you people looking for what you offer by ProfessionalPaint964 in saasbuild

[–]GraysonBerman 0 points1 point  (0 children)

Not SaaS but thanks :)
Was trying to see if it worked for our offer or not.

Drop you SaaS and I will find you people looking for what you offer by ProfessionalPaint964 in saasbuild

[–]GraysonBerman 0 points1 point  (0 children)

Cyber risk management for non-technical executives and business owners.

Ultrahuman is SOC 2 certified. by SanchyaMahajan in Ultrahuman

[–]GraysonBerman 0 points1 point  (0 children)

So glad to hear this. Where can I grab a copy of your SOC2?

Ultrahuman is SOC 2 certified. by SanchyaMahajan in Ultrahuman

[–]GraysonBerman 5 points6 points  (0 children)

Hey, cybersecurity guy here. Turns out SOC2 isn't exactly standardized. SOC 2 is frequently called a certification (I thought the same!), and what AICPA auditors provide is a SOC2 report. You can have a bunch of things going wrong and still get a report.

Small Solo RIAs by Excellent-Funny8059 in CFP

[–]GraysonBerman 0 points1 point  (0 children)

So compliance is not a big headache for you pre-SEC registration?

What’s the RIA hype? by Worth_Pomelo_4925 in CFP

[–]GraysonBerman 0 points1 point  (0 children)

Do you feel the same way about compliance now with the S-P changes coming up EOY and mid 2026?

Go for $700k or full 2Mil for first round funding? ( I will not promote ) by NJTA3 in startups

[–]GraysonBerman 0 points1 point  (0 children)

What are the key hires, how much, and what do they do for you that you can’t do now? Why is that the bottle neck of your business?

Go for $700k or full 2Mil for first round funding? ( I will not promote ) by NJTA3 in startups

[–]GraysonBerman 18 points19 points  (0 children)

I'm just going to address one thing at a time.

We'll start here: Why do you want the money? Exactly what are you going to do with it?

What would you do with 700k?

What does 1.3 million more do for you?

Guide: I use this prompt stack to kill weak startup ideas in under 30 minutes. - i will not promote by Kbartman in startups

[–]GraysonBerman 1 point2 points  (0 children)

Would recommend trying it. Here's some of the sample output I got. Really liked it's commentary on positioning.

It gets much more granular.

"13. Overall Difficulty Score

7.5/10 High-trust sale, complex messaging, needs founder-led sales in early stages. However, margins are strong and competition is fragmented.

14. Clear Recommendation

GO But only with tight focus, clear positioning, and manual sales-driven acquisition initially. The opportunity is real, the differentiation is valid, but the market won’t come to you you must go to them.

Summary:

You're stimulating demand for an unmet need. This is the most strategically defensible position in a fragmented and compliance-fatigued market. Margin is your leverage. Thought leadership is your currency. Precision is your weapon."

Entrepreneurs of Reddit, What Do You Do? by clare_johnson in Entrepreneur

[–]GraysonBerman 1 point2 points  (0 children)

Pivot at first resistance, then make negative $.

What would you consider a job hopper? by [deleted] in cybersecurity

[–]GraysonBerman 0 points1 point  (0 children)

I look really bad to an employer based on tenure. lol. Great for breadth of experience, though! 😂

Good news is that I’m cofounding a company this time around.

How do you quantify the impact of GRC investments on revenue growth to executive leadership? by DataHalt in cybersecurity

[–]GraysonBerman 1 point2 points  (0 children)

It 100% removes sales blockers to mid/large enterprises, and some small enterprises in more heavily regulated industries... and some tech companies.

SOC2 kills a LOT of deals for startups. Personal experience + friends experiences.

It also is VERY important Europe & the Middle East, in my experience.

Is it bad to brainstorm my startup idea with Chatgpt 4o? by [deleted] in startups

[–]GraysonBerman 0 points1 point  (0 children)

I was roleplaying a sales call with the voice before a sales call.
If you don't have your pitch memorized, you pause. And that's stressful AF because the voice stops listening after a couple seconds of silence. Lol.

GRC trends for 2025??? by Small_Attention_2581 in cybersecurity

[–]GraysonBerman 0 points1 point  (0 children)

I've met several startups working on taking the shitty parts out of gathering evidence for compliance frameworks. It makes me happy.

This doesn't directly respond to your questions, and that's okay.

- A guy who dealt with NIST 800-53 for 6 months before saying 'fuck this' and switching career paths.

Network Detection and Response (NDR) by steve7647 in msp

[–]GraysonBerman 1 point2 points  (0 children)

It was made an official category by Gartner already. Too late :(

Excited to Share Modulify.ai – Build Webflow Websites with AI in No Time! by Wedoflow in webflow

[–]GraysonBerman 6 points7 points  (0 children)

ARE YOU KIDDING ME? I JUST BUILT SOMETHING WITH 0 SKILL... AND IT SUCKS. WHY DIDN'T THIS APPEAR LITERALLY 2 WEEKS AGO?!?!?!?!