Delve faked SOC2. That's worse than SOC2 itself.

Delve faked SOC2. That's worse than SOC2 itself.

Source: YouTube · Zack Korman · published Mar 28, 2026 · 15:53

Compliance & GRC
No ratings yet Log in to rate
Transcript Available
Description

The speaker strongly condemns the cybersecurity community's tendency to blame SOC 2 compliance frameworks for Delve's fraudulent actions, arguing that fraud is inherently worse than flawed compliance standards 0:00.

Key Takeaways:
• While the speaker acknowledges that SOC 2 and ISO 27001 are annoying and have significant flaws as compliance standards, these issues do not excuse or explain corporate fraud 0:11.
• The core argument is that committing fraud is fundamentally worse than dealing with the friction of security compliance frameworks 0:20.
• A subset of the infosec community is criticized for prioritizing "edgy" hot takes about their personal pet peeves with SOC 2 rather than focusing on the actual crime committed by Delve 0:30.

Ultimately, deflecting blame onto compliance standards distracts from holding fraudulent actors accountable for their deliberate misconduct.

Sources:

  • 0:00 Introduction of the hot take blaming SOC 2 over Delve
  • 0:11 Acknowledging flaws in SOC 2 and ISO 27001
  • 0:20 Stating fraud is worse than annoying compliance standards
  • 0:30 Criticism of the edgy cybersecurity community

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Compliance & GRC. Commonly maps to: Security and Risk Management, Asset Security. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Are you guys so desperate to have a hot take that you're not willing to say the obvious thing? This person here writes, "Dolve isn't the problem. Sock 2 is." The [ __ ] are you? What do you mean? I have a lot of complaints about sock 2 and I have a lot of complaints about ISO 271. They're compliance standards. They have problems. They're annoying as hell. You know what I don't like even more? Fraud. Broad is worse. And I I don't know why I'm having to argue this. There is some subset of the compliance infosex cyber security community that has just lost their minds on this issue. They have this desire to be so edgy that they have to hit you with this hottake about how their personal pet peeve with sock 2 is somehow underlying Delve committing fraud. Like why why are you guys like this? It's…