Cyberwall Blog · October 6, 2024

Cyberwall Successfully Passes SOC 2 Type II Audit

Cyberwall has completed its SOC 2 Type II audit, a standard that evaluates how controls actually hold up in practice, not just on paper.

By Alex Plotkin, CEO

We’re confirming what a lot of our clients already ask us to prove: Cyberwall has completed its SOC 2 Type II audit. Unlike a Type I report, which checks whether controls are designed correctly at a single point in time, Type II evaluates whether those controls actually held up in practice over an extended review period, in our case, several months of continuous operation.

That distinction is the whole point of the standard. A Type I report is a snapshot: an auditor looks at the controls on the books on a given day and confirms they’re designed the way they should be. It’s a reasonable starting point, but it says nothing about whether those controls were actually followed the week after the audit, or the month after that. A Type II report requires evidence collected over the entire review period, not a single point-in-time check, which means the auditor is looking at whether access reviews actually happened on schedule, whether monitoring alerts were actually investigated, and whether the policies on paper matched what staff were actually doing month over month.

For clients, that distinction matters. It’s the difference between a vendor telling you they have good security practices and a vendor having those practices independently verified over time, including continuous monitoring, tested access controls, and mandatory security training among them. When an IT Director is evaluating a vendor as part of their own compliance program, a SOC 2 Type II report gives them something concrete to hand to their own auditor or their board, rather than relying on a vendor’s word for it. That’s especially relevant for organizations in regulated industries, where a vendor’s own certifications increasingly factor into the client’s own compliance posture and questionnaire responses.

It also changes what a vendor security review looks like in practice. Without a Type II report in hand, a prospective client is often left sending over a lengthy security questionnaire and waiting on written answers to dozens of individual questions about access control, encryption, incident handling, and change management, then having to take those answers largely on faith. A completed SOC 2 Type II report answers most of that questionnaire before it’s even sent, backed by an independent auditor’s testing rather than a vendor’s self-reported answers. For an IT Director already stretched across their own compliance obligations, that shortcut in vendor due diligence is often as valuable as the assurance itself.

The audit itself is built around a defined set of trust service criteria, security being the mandatory baseline, with availability, confidentiality, processing integrity, and privacy layered in depending on the scope an organization chooses. For an MSSP, the security criteria in particular cover things like how access is granted and revoked, how systems are monitored for anomalies, how incidents are detected and escalated, and how changes to production systems get reviewed before they go live. None of that is unique to Cyberwall; it’s the same framework any organization pursuing SOC 2 has to satisfy. What the report actually verifies is whether an organization’s day-to-day operations match its documented policies, consistently, across the whole review window.

This isn’t the finish line. Threats change, and so does what “sufficient” looks like, which is why we’re continuing to invest in additional certifications and stronger controls as we grow. A certification is a snapshot of controls that held up over a defined period, not a permanent guarantee, and maintaining it means going through the same rigor again at the next audit cycle rather than treating this as something to file away and forget. For a security-conscious buyer, that ongoing commitment matters as much as the certification itself: it signals that the controls are being maintained as a matter of course, not just prepared for whenever an audit is scheduled.

It’s also worth being precise about what a report like this does and doesn’t claim. A SOC 2 Type II audit verifies that a defined set of controls operated effectively over the review period it covers. It isn’t a guarantee against every possible future incident, and any vendor who frames it that way is overselling it. What it does provide is a documented, independently tested baseline: proof that the access controls, monitoring, and training programs a vendor describes on a sales call are the same ones actually running day to day, verified by someone with no stake in the answer coming back clean.

If you’re evaluating vendors as part of your own compliance obligations, we’re glad to share what this audit actually covers. It’s the same standard our compliance services are built around for clients, and it’s the same discipline we’d expect from any vendor we trusted with our own environment.

Related reading: What Credit Unions Should Ask a Managed Security Provider · Recent Privacy Breaches: A Wake-Up Call

Not ready to wait on a blog post?

Book a preparedness call and get a straight answer for your specific situation, no searching required.