Transcript
Imagine you're trying to close the biggest deal in your company's history. You're at the finish line, but their legal team asks, "Are you SOC 2 compliant?" Suddenly, the door slams shut and you miss out on the deal. What I want to do here is zoom out and explain what a SOC 2 report is from a 30,000-foot view. Then at specific times, we'll zoom in to provide detailed insights. Now, I say we because Michael Yeager has performed over 1,000 SOC 2 audits, and he'll be jumping in and out of this video to provide additional insights. [music] You'll also see little tips from Mike pop up on the screen like this throughout the video, too. Lastly, any questions, feel free to comment below and Mike and his team will [music] do their best to answer them for you. What is a SOC 2 report? SOC 2 was created by accountants via the AICPA. You can think of it like a home inspection for your company's data. When you buy a house, you want a third-party inspector to check the electrical, plumbing, foundation, as well as any safety hazards. When a company buys your software or does business with you, the SOC 2 report tells them that you have great systems and controls in place that relate to the five trust service criteria, which is the entire focus of a SOC 2 report. The five trust service criteria are security, availability, processing integrity, confidentiality, and privacy. Now, you don't have to do all five, but security is a required criteria. I wanted to take a quick break from the video here and pull Mike in uh because you're the expert in this space, Mike, and what do you typically find for first-time SOC 2 goers? Like, what are they doing for their reports as far as trust and service criteria? What do you find? >> Yeah, as far as scoping in TSCs, I'd say 80% of our first-time SOC 2 goers just take on the security criteria. The security criteria requires plenty of subject matter to digest, design controls, implement those controls, and eventually practice them moving forward, right? Uh the next two criteria I would recommend would be availability and confidentiality. The subject matter here for these and the requirements are a rather short and sweet, especially when you compare them to privacy or processing integrity. But, to recap kind of all of this it and make sure you're doing it correctly, it it's most important to talk with the customer or prospect that's requiring this of you to make sure you're scoping in everything that they want to see. >> Here's an example of a SOC 2 report that shows how detailed the report gets. Here you can see the control is that the company performs background checks on new employees. Then the control test performed by the auditor is that they inspected the company's records to verify that a background investigation was performed on newly hired employees as permitted by local laws. Now, this example brings up a good question on the difference between a type one versus type two report. You can think of a type one audit like a snapshot of your company. The auditor looks at your company on a single day. Do you have a password policy? Yes. Is [music] the firewall on? Yes. Do you have a history of background checks being performed? Yes. Now, a type two report is more like a movie. This is the gold standard where an auditor watches you for 6 to 12 [music] months. They don't just ask if you have a background check policy, they check if an employee joined in June and if you actually ran their background check like you said you would. >> [music] >> Most companies opt for a type two report as some companies will require it in order to do business with you. I should mention too that Mike and his company offer a free SOC 2 introductory call to explain what your options are. You'll find a scheduling link in the description below so you can ask Mike any questions you may have. The big three things you'll actually do. So, what does the SOC 2 audit actually look like in terms of what is required from you? Policies. Writing down the laws of your company. For example, we use two-factor authentication. Procedures. The actual actions such as turning on two-factor for every single person and we revoked access to terminated employees within 24 hours. Evidence. This is the hard part. You need receipts. If you said you off-boarded an employee, the auditor wants to see the time-stamped log showing their access was revoked within 24 hours. Now, I'd like Mike to jump in and explain why a company should do a SOC 2 audit. Like, what are the advantages? All right, Mike. Why? Like, why go through the type 2 report right out of the gates? Why why would you advise somebody on that? >> Yeah, because it it's a blast. It's not it and everybody loves doing it, right? No, you you touched upon it earlier in the video here where, you know, you're closing deals with prospects and customers that you might not have a chance to do that [music] with before, right? On a day-to-day basis, your your marketing team and your engineers are going to thank you for no longer having to fill out security questionnaires. You can go ahead with that email from a prospect or customer and slap that SOC 2 down on their desk and say, "Here are the answers to all of your questions that you're wondering before doing business with us." The alternative perspective that I like to challenge our our customers to address it is kind of standardizing growth here. You now have policies and procedures for your sales intern all the way up to your CTO to follow for years to come, and that helps with employee onboarding. As you close these deals, as you generate more leads, and as you sign more customers, your five-person company becomes a 50-person company, becomes a 500-person company, and they can all lean on these procedures moving forward. >> Uh I've definitely been in businesses that, you know, grew quick and then those problems that were small problems become big problems. So, I think it's great for addressing that early on. >> Absolutely. I've I've seen it in my time here as well where new SOC 2 customers come in as as Jim and Joe with a startup and an idea and and now they're a thousand-employee company. >> Yeah, well, that's the dream, right? >> Yeah. >> All right. Cool. Thanks, Mike. Yeah, I'll probably cut out the part where I said that's the dream. >> [laughter] >> So, what are our next steps? As I mentioned earlier, every SOC 2 audit is different because companies are different. To get detailed insights, I'd highly suggest jumping on a call with Mike and his team via [music] the scheduling link in the description below. And in the next video, we're going to discuss how much a SOC 2 report costs. We'll catch you in the next video.