
Delve faked SOC2. That's worse than SOC2 itself.
Source: YouTube · Zack Korman · published Mar 28, 2026 · 15:53
The speaker strongly condemns the cybersecurity community's tendency to blame SOC 2 compliance frameworks for Delve's fraudulent actions, arguing that fraud is inherently worse than flawed compliance standards 0:00.
Key Takeaways:
• While the speaker acknowledges that SOC 2 and ISO 27001 are annoying and have significant flaws as compliance standards, these issues do not excuse or explain corporate fraud 0:11.
• The core argument is that committing fraud is fundamentally worse than dealing with the friction of security compliance frameworks 0:20.
• A subset of the infosec community is criticized for prioritizing "edgy" hot takes about their personal pet peeves with SOC 2 rather than focusing on the actual crime committed by Delve 0:30.
Ultimately, deflecting blame onto compliance standards distracts from holding fraudulent actors accountable for their deliberate misconduct.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Compliance & GRC. Commonly maps to: Security and Risk Management, Asset Security. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Are you guys so desperate to have a hot take that you're not willing to say the obvious thing? This person here writes, "Dolve isn't the problem. Sock 2 is." The [ __ ] are you? What do you mean? I have a lot of complaints about sock 2 and I have a lot of complaints about ISO 271. They're compliance standards. They have problems. They're annoying as hell. You know what I don't like even more? Fraud. Broad is worse. And I I don't know why I'm having to argue this. There is some subset of the compliance infosex cyber security community that has just lost their minds on this issue. They have this desire to be so edgy that they have to hit you with this hottake about how their personal pet peeve with sock 2 is somehow underlying Delve committing fraud. Like why why are you guys like this? It's…