Security Confidential S2 E3 Jordan Graham

This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon welcomes Jordan Graham, the head of Project Management and Compliance at Dark Rhino Security, Inc. Jordan Graham discusses SOC2 compliance, what it is, and What it is not, the new SOC2 Plus compliance attestation, and tips on the journey to getting the certification from a practical perspective.

00:00 Intro (About Jordan)

00:51 What is SOC2?

02:42 Does SOC2 Make us more secure?

07:24 How does SOC2 work?

13:31 SOC2 High Trust

15:18 Preparing for SOC2

21:06 SOC2 in the Cloud

24:49 A Practical Example

27:33 Compliance in a Box

29:48 What makes you unique?

31:29 The cost

35:24 Challenges we face

Transcript

Manoj Tandon: Hello everyone. Welcome to another episode of Security Confidential. This is Manoj Tandon, your host. Today we are joined by Jordan Graham. Jordan heads up our project management team and also shares responsibility in operations. He’s a jack of all trades around here at Dark Rhino, and we love him for it. We’re going to talk a little bit about SOC 2 today. Jordan, welcome to the show. Thanks for joining us.

Jordan Graham: Manoj, thanks for having me, man. It’s been good. I haven’t been on here too much lately, but I’m looking forward to talking and sharing some information.

Manoj Tandon: We’re going to change that a little bit now. I know everyone listening probably thinks SOC 2 sounds like an ultra-boring topic, but it’s an important one. We’ll try to keep it as interesting as possible without getting into all the low-level weeds. Let’s start with some basics here, Jordan. What the heck is SOC 2? Security Operation Center controls?

Jordan Graham: No, that’s actually a very common misconception. The SOC audit in and of itself—and there are three types, which we’ll cover—is actually a financial audit. It was designed to help financial institutions audit their security posture to ensure they were transacting securely with clients internally and externally. Much like HIPAA, HITRUST, and other compliance frameworks, SOC 2 is meant to ensure organizations are working securely and have processes in place to protect data.

Manoj Tandon: Let me make sure everybody understood that. This is not like the NIST framework or the MITRE ATT&CK framework. It didn’t come out of the cybersecurity industry—it came out of accounting. For those playing Trivial Pursuit, SOC stands for System and Organization Controls. So how does this fit into cybersecurity? Everybody seems obsessed with SOC 2 these days. A lot of customers insist on it. Do you think it actually makes companies more secure?

Jordan Graham: As a security company, my answer is yes and no. It absolutely helps because it forces organizations to formalize and document processes. Before SOC 2, we already had security controls in place, but the audit forced us to document them and create hard, repeatable processes. It helped us become much more operationally fluent internally. So yes, it improves security because now we have a framework and measurable procedures that must be followed to maintain compliance.

Jordan Graham: There are multiple types of SOC audits. The most recent one we completed was SOC 2 Type 1. Then there’s SOC 2 Type 2, and more recently SOC 2 Plus. Type 1 and Type 2 are closely related. In both cases, the assessor comes in and reviews your documentation, policies, procedures, onboarding, offboarding, HR processes—everything inside the company.

Manoj Tandon: Is there any part of the company it doesn’t touch?

Jordan Graham: No. Everything is in scope because almost every part of an organization can impact security in some way, whether it’s leaking PII or creating operational vulnerabilities. The only major thing generally not included is financial reporting itself.

Jordan Graham: The main difference between Type 1 and Type 2 is that Type 1 is an “as-is” attestation. The assessor validates that your documented process occurred correctly one time. If your onboarding process says someone submits a request, it gets approved, and then access is granted, the assessor verifies that happened properly once.

Manoj Tandon: And Type 2?

Jordan Graham: Type 2 measures consistency over time. Usually that’s over six months to a year. The assessor validates that you consistently follow the process over that entire period. So instead of onboarding happening correctly once, they’re looking for it to happen correctly repeatedly. They want consistency. You can have occasional failures, but you generally need at least an 85 percent success rate.

Manoj Tandon: One thing I was thinking about is SLAs. If you’re SOC 2 compliant, it seems like you’re putting additional operational pressure on yourself because if you miss too many SLAs, that probably impacts your compliance posture too.

Jordan Graham: Absolutely. That’s a very good point. If we’re failing SOC 2 controls, we’re probably also missing SLAs, dropping projects, or failing milestones. Everything intertwines operationally. SOC 2 is much more than a piece of paper. Businesses should treat it as a framework for operational maturity, not just a certification exercise.

Manoj Tandon: So what’s SOC 2 Plus?

Jordan Graham: SOC 2 Plus is essentially SOC 2 combined with another framework such as HIPAA or HITRUST. The assessor validates that the processes inside your SOC 2 controls also align with the requirements of that additional framework. You’re not necessarily certified under HIPAA or HITRUST, but your controls are validated against those standards.

Manoj Tandon: So oversimplifying a little bit, SOC 2 Plus is kind of like HIPAA Lite or HITRUST Lite?

Jordan Graham: Exactly. That’s actually a pretty accurate way to describe it.

Manoj Tandon: When we went through this process, it was a non-trivial exercise. It took a lot of time and effort. If a company wants to prepare for SOC 2, what would you recommend?

Jordan Graham: First, engage your assessor early. Find the right assessor because they’ll shape a portion of how your audit is approached. Second, document everything. Put your processes on paper. Define onboarding, offboarding, escalation procedures, disaster recovery, business continuity—all of it. Third, define your “system.” Especially for MSSPs, you need to understand exactly how your management systems work, how data flows, what connects to what, and what access controls exist.

Jordan Graham: One of the biggest areas where companies fail is admin access. SOC 2 expects detailed processes around who gets access to sensitive customer data, how that access is approved, and how it’s monitored. You can’t just hand out admin rights casually.

Manoj Tandon: We’ve spent a lot of time on that internally. Even non-admin access requests have to go through formal processes with logging and approvals.

Jordan Graham: Exactly. Our clients’ data is one of our most valuable assets, so we invested significant effort into making those controls secure and auditable.

Manoj Tandon: Let’s talk about cloud-first environments. A lot of SMBs today run entirely in the cloud. They’ll say, “All of our vendors are SOC 2 Type 2 certified, so by proxy we’re SOC 2 compliant.” Is that valid?

Jordan Graham: It’s partially true. If all your tools are SOC 2 certified, you’re operating within compliant ecosystems. But you are not officially attested until you go through your own audit. There’s no way around that. The controls around how your company uses those tools still need to be validated.

Jordan Graham: One of the major advantages MSSPs can provide is helping customers inherit secure operational practices. By working with Dark Rhino Security, clients benefit from our controls and the fact that we strategically choose SOC 2 compliant tools. However, customers can still choose to disable those controls, which would then shift the responsibility back to them.

Manoj Tandon: Let’s talk about “compliance in a box.” Early on, we looked at vendors promising easy SOC 2 solutions where you buy software, answer some questions, and magically become compliant.

Jordan Graham: Terrible idea. We considered it too early on, and I’m almost embarrassed to admit it. The problem is that if someone else writes your policies for you, those policies probably won’t reflect how your organization actually operates. SOC 2 requires operational reality, not boilerplate templates.

Jordan Graham: When your assessor shows up, they can ask for proof of anything in your policies. If your organization isn’t actually operating that way, you’re going to fail. Companies need to take a very personal, hands-on approach to their SOC 2 process.

Manoj Tandon: You also lose what makes your company unique if you simply copy generic templates. Your operational processes and value propositions are part of your differentiation.

Jordan Graham: Exactly. One thing I learned during our SOC 2 journey was that the framework can actually enhance your organization’s value proposition if you tailor it properly. We aligned our policies with the way Dark Rhino operates and serves SMB clients, which made the process much more valuable.

Manoj Tandon: It’s also not cheap.

Jordan Graham: No, it’s definitely a financial investment. But trying to save money by outsourcing everything or buying cheap “compliance in a box” solutions usually ends up costing more in the long run because you’ll eventually need to redo everything properly.

Jordan Graham: The biggest recommendation I can give is to learn the process yourself and operationalize it internally. Make sure your policies make sense operationally. If somebody else writes policies that don’t fit your environment, you’ll spend even more money trying to fix them later.

Manoj Tandon: So it’s basically “pay me now or pay me later.”

Jordan Graham: Exactly.

Jordan Graham: One thing I’ll add is that going through SOC 2 was actually valuable for us organizationally. It helped us mature. It forced us to improve operationally. If companies approach SOC 2 as an opportunity to grow instead of just a checkbox exercise, they’ll come out much stronger.

Manoj Tandon: Once the policies were written, what were the biggest operational challenges?

Jordan Graham: Operationalizing the controls was the hardest part. Once you get the certification, you can’t relax. Everybody has to follow the policies consistently, including executives. That’s where communication and awareness become critical.

Jordan Graham: You have to create a culture where people understand both the “how” and the “why” behind the controls. There also has to be accountability. Sometimes the answer is simply “no” when someone wants to bypass a process.

Manoj Tandon: And you have to be comfortable saying “no” to executives too.

Jordan Graham: Absolutely. Compliance requires testing and validation. You need checks and balances to ensure the controls are actually working and that deficiencies are corrected quickly.

Manoj Tandon: Are there any resources you’d recommend for people who want to learn more?

Jordan Graham: Honestly, Google is still a great place to start. Search for SOC 2 requirements and you’ll find a wealth of information. I also recommend looking at the HITRUST framework because it’s more granular than SOC 2. If you can meet HITRUST requirements, SOC 2 becomes much easier by comparison.

Jordan Graham: And again, work closely with your assessor early. If your assessor isn’t helping guide you through the process, find a new assessor.

Manoj Tandon: On those kind words, Jordan, thank you for joining us. I appreciate you taking your Friday morning to be here.

Jordan Graham: Thanks for having me. I think we’re definitely going to need a Part 2 because we’ve only scratched the surface of SOC 2.

Check out the other episodes in Season 2:

Ep. 0 Luis Martin – The Origins of Artificial Intelligence

Ep. 1 Ida Abdalkhani – Grow your career, quit your job, and laughter yoga

Ep. 2 Phil Rich and Kevin Swift – Do you have the Chutzpah to be an entrepreneur?

Ep. 3 Jordan Graham – SOC2 Compliance, can it be done on the cheap?

Ep. 4 Matt Castonguay – Gamer to Millionaire

Ep. 5 Jay Sheehan and Jordie Kern – How to Hire Heros

Ep. 6 Ethan Nicholas – Successfully Network and Achieve Success

Ep. 7 Nick Potts – GiftHealth

Ep. 8 Warner Moore – Risks in Cybersecurity

Ep. 9 Chris Gerritz – Prevention Paradox

Ep. 10 Karen Hough – New Year New Beginning Leverage Improv

Jordan Graham's profile picture for Dark Rhiino Security's Security Confidential podcast

Jordan has been in the cybersecurity business for over 3 years and a Lean Six-Sigma black belt.

He is a former Marine with an extensive background in process management. Jordan is an avid Bowhunter and is a participant on the podcast “The Bowhunters Heritage”.

Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.

For inquiries, please email media@darkrhiinosecurity.com

Share and spread the word!

Leave a Comment

Your email address will not be published. Required fields are marked *

Chat Icon
Scroll to Top