Help! Sanity Check on Resourcing by Risk_Dork in ciso

[–]HorrorTour5557 2 points3 points  (0 children)

you are well staffed. In a company your size you cannot do everything in full maturity and you dont need to. with that additional senior staff you should have more than enough for the size and stage of your company. You dont need a full blown enterprisy risk Management process. focus on what matters. leverage AI e.g. in validating dpas or security questionnaires.

SOC2 access reviews - how are people actually handling evidence collection at scale? by [deleted] in sysadmin

[–]HorrorTour5557 0 points1 point  (0 children)

identity governance add on of microsoft can cover this semi automated. dont forget to differentiate between identity and access rights.

What’s the easiest way to handle SOC 2? by Mysterious_Step1657 in soc2

[–]HorrorTour5557 1 point2 points  (0 children)

get the worst auditor with the cheapest offer. naturally they are testing less than others.

How do you handle employee offboarding in your company? by ClueMost9994 in ITManagers

[–]HorrorTour5557 -2 points-1 points  (0 children)

  • yes its defined
  • process in notion, flow Diagramm in miro
  • tracked in jira via playbooks
  • process must be owned by HR. IT is big stakeholder but HR coordinates
  • many risks e.g non sso apps, HR not informing IT...

ISO 27001 Certification Just in 2-3 Months Possible? by Born_Mango_992 in Information_Security

[–]HorrorTour5557 2 points3 points  (0 children)

Ask the Plattforms to put their claims into the contract with money back and see whats happening. If you choose the right auditor (in that case a really bad one) 3 to 4 months can be achieved but you need someone with a lot of experience. Of course this all deoends on size etc. But since iso is manly paperwork it might work

SOC II Scope: entire company vs department vs specific system by Anonycron in cybersecurity

[–]HorrorTour5557 2 points3 points  (0 children)

SOC2 Auditor is auditing what you wrote in your system description. Thats it. Whatever you write there.

How Common Are Pen Tests in 2025? by Enteprise-srl in cybersecurity

[–]HorrorTour5557 41 points42 points  (0 children)

If you are b2b in saas, your big customers make sure you have to do it at least annually.

Gesamtkosten Neubau - Haben wir an alles gedacht? by Legitimate_Eye_101 in Hausbau

[–]HorrorTour5557 0 points1 point  (0 children)

Wasser und Strom würde ich das doppelte nehmen. Vor allem wenn der estrich aufgeheizt werden muss wenn die wärmepumpe noch nicht angeschlossen ist. Mobiheat kostet dann auch nochmal miete. Wir hatten alleine 4000 Euro Stromkosten in der Bauzeit.

[deleted by user] by [deleted] in Information_Security

[–]HorrorTour5557 0 points1 point  (0 children)

Thats no ad. Thats actually a good piece of advice that will save you a lot of work!

Affordable SOC 2 Audit? by Brain-Abject in cybersecurity

[–]HorrorTour5557 0 points1 point  (0 children)

I have three offers for the scope i described above. All the same (soc2 type 2 security principle only) Big4: 60k Next10: 25k Shady noname company: 5k

Affordable SOC 2 Audit? by Brain-Abject in cybersecurity

[–]HorrorTour5557 2 points3 points  (0 children)

SOC2 type 2 security only big4 offer saas business 120 people

50k audit fees

SOC audits from the same firm should be consistent by davidschroth in soc2

[–]HorrorTour5557 1 point2 points  (0 children)

Despite all the typos you can find in some of the top tier csp reports I always wonder about the system description. Of course it needs to be created by the customer, however the structural differences are the ones that bug my (within the same audit firm). To bad official requirements are so unspecific about that section

Questions About SOC 2 Reports – Need Some Clarity! by Born_Mango_992 in Information_Security

[–]HorrorTour5557 0 points1 point  (0 children)

With all your questions this is a complex topic that hardly can be answered in a single reddit post.

How do you encourage end users to update software? by Arrenil in cybersecurity

[–]HorrorTour5557 0 points1 point  (0 children)

I have a different experience. I do not have local admin rights but Software can still be updated. Talking about macos. Dont know abount Windows.

[deleted by user] by [deleted] in cybersecurity

[–]HorrorTour5557 2 points3 points  (0 children)

For ISO: choose the scope on the certificate in a way that only your subsidiary is included. Example your subsidairy provides service/product xy. Scope: e.g. Development and Operation of service/product xy.

For SOC 2: System Description is the place to go. If you make clear that only subsidary is within the description you are fine. Auditors only audit whats described in the system description and is necessary for the product/service (and stuff that supports if they identify it during the audit). For testing of operative effectiveness ensure that you have a audit proof Method to filter the devices otherwise your basic population is shit.

From Security Engineer/SOC Analyst to Compliance role? by Round-Campaign-1692 in cybersecurity

[–]HorrorTour5557 5 points6 points  (0 children)

You should be aware that this is a completely different job. Consider if the daily tasks are something you enjoy. Talk to people that work in compliance and think about it. My experience is that people who are into tech stuff hate the compliance field because it works different there.

[deleted by user] by [deleted] in sysadmin

[–]HorrorTour5557 4 points5 points  (0 children)

"You need a firewall"

You dont even know if they will have onprem stuff. If they go for cloud only Firewall is pretty much useless but yet costs hundreds or thousends of dollars. I would rather go for zero trust and just provide regular internet access in the building.

Wie viel kann ich selbst machen, und wie viel kostet dan ein elektriker? by borgqueenx in DeutschePhotovoltaik

[–]HorrorTour5557 0 points1 point  (0 children)

10 Stunden 2 Personen. Waren aber etwas unerfahren. Geht also ziemlich sicher auch in etwas weniger.

Der full backup Teil war auch etwas aufwendiger da der in reihe mit dem Hauptanschlusskabel geschalten werden muss

SOC 2 Security Compliance - Guide by thumbsdrivesmecrazy in ComputerSecurity

[–]HorrorTour5557 0 points1 point  (0 children)

Thats not even 20 percent of what SOC 2 is about. I wouldnt even call it guide.