
August 3, 2026
Hacker Hub - August 2026
Small businesses aren't too small to be targeted. They're often the preferred target. Here's why the 'we're too small' mindset is one of the most dangerous in business.
Read MoreYou can now buy a guaranteed pass. Not through some dodgy back channel, just openly advertised. Compliance platforms will sell you the software, the policy templates and, conveniently, an auditor from their partner network. Some go as far as promising you will pass.
Think about that for a second. An assessment where the outcome is guaranteed before anyone has looked at anything is not an assessment. It is a receipt.
I have worked with security standards and auditors for more years than I care to admit, and I have never seen the market lean this hard towards the badge over the outcome. So let's look at why it is happening, why it matters, and what to do about it.
Because for most businesses, certification is not a security decision. It is a sales decision.
A prospect's procurement team asks for SOC 2 or ISO 27001. No certificate, no contract. Certification becomes a hurdle between you and revenue, and when something is a hurdle, the natural instinct is to clear it with the minimum effort possible.
The market has responded exactly how markets do. If businesses want the badge fast and cheap, someone will sell them the badge fast and cheap. Automation platforms, pre-written policy packs, auditors who partner with the platform that prepared you for the audit. The whole pipeline is optimised for one outcome: the pass. Whether you are actually more secure at the end of it is almost incidental.
SOC 2 is where this is most visible. There is no independent accreditation body sitting above SOC 2 in the way UKAS sits above ISO 27001 certification in the UK. In practice, the depth and quality of a SOC 2 assessment is largely down to the firm you pick.
And increasingly, you do not pick. The compliance platform picks for you. The auditor is a commercial partner of the software that prepared your evidence, and their pass rate is part of the sales pitch. That is a fairly obvious conflict of interest, and it shows in the reports. I have seen SOC 2 reports where it is hard to believe anyone looked beyond the screenshots the platform generated.
None of this means SOC 2 is worthless. It means a SOC 2 report tells you very little on its own. Who did the audit, what was in scope and what they actually tested matters far more than the logo on the cover.
Partly, yes. ISO 27001 has real structural advantages. Certification bodies are accredited by UKAS in the UK, so someone is watching the watchers, and the standard forces you to think about security across the whole business rather than just the controls a customer asked about.
But I will be honest, because I have sat through more of these audits than most: the level of auditing varies massively from auditor to auditor, even within the same certification body. Some auditors will genuinely test whether your ISMS works. Others will accept a well-formatted document and move on. From experience, the trend is towards light touch, because certification bodies are commercial businesses too, and thorough audits are expensive and unpopular.
There are excellent auditors out there. But if your security strategy is "we passed the audit", you are betting your security on which auditor turned up.
Here is the thing the tick box crowd have backwards. Compliance does not create security, but security creates compliance.
If you understand your data, know your risks, control access properly, patch your systems, test your defences and train your people, you are already doing the substance of what every major framework asks for. ISO 27001, SOC 2, Cyber Essentials, NIST, most of PCI-DSS: they all describe roughly the same set of sensible practices in different language.
Do the security work properly and the audit becomes an exercise in evidencing what you already do, not a scramble to manufacture proof of things you don't. That is also when certification starts paying you back, because the controls you are being audited against are the same controls stopping a real incident.
Build it the other way around, minimum viable compliance with a friendly auditor, and you get a certificate that protects you from precisely nothing. Attackers do not check your Trust Centre before they phish your finance team.
If you are being pushed towards certification by a customer or procurement, fine, that is how most of it starts. Just approach it in the right order.
Start with a genuine look at your risks and your current security, not a gap analysis against a checklist. Fix the things that would actually hurt you. Then map what you are doing to the framework you need, and pick an auditor with a reputation for being thorough, not one advertised on a pass-rate guarantee.
A hard audit is a free security assessment. An easy one is an expensive PDF.
No. Certification means a company met an auditor's interpretation of a framework at a point in time. Depending on the auditor, that can mean a lot or very little. Treat certification as a starting point for security questions, not the answer to them.
The platforms themselves can be useful tooling for evidence collection. The problem is the incentive model when the platform, the preparation and the auditor are all commercially aligned around you passing. Use the tooling if it helps, but choose your auditor independently.
Absolutely. Certification is proof for other people, not protection for you. Plenty of well-secured businesses hold no certificates, and plenty of certified businesses get breached. If nobody is asking you for a badge, spend the money on actual security.
If you are heading into ISO 27001 or facing customer security demands and want it done in a way that leaves you genuinely more secure, not just certified, that is exactly how we approach it at Vorago Security. Get in touch and we will tell you honestly what you need, and what you don't.

August 3, 2026
Small businesses aren't too small to be targeted. They're often the preferred target. Here's why the 'we're too small' mindset is one of the most dangerous in business.
Read More
August 3, 2026
You can now buy a guaranteed audit pass. Here's why the tick box approach to compliance is a false economy, and why security done properly makes compliance the easy part.
Read More
July 16, 2026
Supply chain attacks are one of the fastest growing cyber threats. SMEs are frequently the entry point attackers use to reach larger targets. Here is what you need to know and what to do about it.
Read More