Hacker News new | ask | show | jobs
by robshippr 71 days ago
Second major supply chain compromise in a week after the axios npm attack. 40 minutes and 500k machines affected. SOC2 won't catch this. The real question is whether your CI pipeline would have flagged a dependency change that happened between your last build and the one going to prod. Most teams have no visibility into that window at all.
1 comments

> SOC2 won't catch this

Cybersecurity professionals and their certification treadmill crack me up because of this

They get paid less, require more certifications to be marketable, all to simply show actual “computer wizards” where all the blind spots are

I am not disagreeing with your main point, but want to clarify that SOC2 is not an individual certification that a person achieves.