The Trust Services Criteria never mention a pentest by name, yet auditors expect one for every SOC 2 report. Here is what actually drives that expectation.
Tag:
SaaS security
-
-
A single attacker has spent 17 months scraping Salesforce and ServiceNow customer portals worldwide, not by exploiting a flaw but by using guest user permissions exactly as they were configured.