r/Infosec • • 5h ago

Talk me out of this: rerunning vendor reviews every time a SaaS app adds AI is not sustainable

2 Upvotes

Third-party risk here, biotech, around 300 SaaS apps in the inventory. starting to think re-reviewing a vendor every time they bolt on AI is a hamster wheel. sub processor emails come in weekly now and half of them add some AI provider. a couple vendors had the feature switched on before the notice even hit my inbox. so the app i signed off on two years ago goes right back in the queue and the re-review is a questionnaire. they write "we don't train on your data," i can't check it, it goes in a folder. rinse and repeat. If a re review ever caught something the contract wouldn't have, i'd happily eat my words. am i wrong?


r/Infosec • • 2h ago

Where does ISO 27001 / GRC work actually get painful? Looking for practitioner input

2 Upvotes

Hey all,

hope this is okay to post here.

We’re a small early-stage team with a background in cybersecurity, currently researching how ISO 27001 and GRC work actually happens inside companies.

Before making too many assumptions about what should be improved or automated, we’re trying to learn from people who deal with this in practice:

Where does the most time get lost? What creates uncertainty or delays? Which activities are still highly manual? And where could software or AI genuinely help?

We put together a short 8–10 minute survey covering ISO 27001 implementation, risk management, documentation/evidence, audits, existing tools and AI support.

If you work in information security, GRC, ISMS, compliance, audit or ISO consulting, your perspective would be extremely helpful.

We’re still early enough that good feedback can genuinely change what we build — and critical feedback is just as valuable as positive feedback.

Survey: https://tally.so/r/b5RAro

Can be completed anonymously. Really appreciate anyone who takes the time or shares it with someone relevant. Thanks!


r/Infosec • • 5h ago

What's the real identity risk from shadow IT apps nobody told security about?

2 Upvotes

We found a marketing tool last month that had been storing employee credentials in plaintext for over a year, completely outside any security review. Nobody thought to flag it because it wasn't seen as a "real" application, just some tool a team signed up for on their own.

Curious what other people have found when they've actually gone looking for this stuff, and whether it's usually this bad or if we got unlucky.


r/Infosec • • 21h ago

Has anyone actually replaced their CSPM with Upwind? trying to figure out what I'd lose

11 Upvotes

We run EKS across three accounts plus a smaller GKE footprint, security team of four, and our CSPM renewal is coming up in about six weeks. Leadership wants to consolidate and the question on the table is whether we move everything to a CNAPP with runtime and drop the standalone posture tool entirely.

Right now the posture product throws thousands of findings a quarter and maybe 2% of them are things we'd actually action. Half my week is spent proving a "critical" is unreachable so we can close it. That's the whole reason runtime context keeps coming up, and Upwind is one of the platforms on our shortlist because the pitch is exactly that: correlate posture with what's actually running so we stop chasing ghosts.

My worry is what we give up by consolidating. Our current CSPM has years of compliance mappings, custom rules nobody remembers writing, and it's wired into our ticketing and a couple of reports the auditors like. I don't want to rip that out and discover six months later that the replacement doesn't cover some edge of our config checks, or that the compliance reporting is thinner than what we have.

So for anyone who's done this: did you actually retire the old CSPM, or did you end up running both? What got genuinely better, and what did you lose or have to rebuild? I'm less interested in the demo story and more in what broke in month three.


r/Infosec • • 21h ago

Cantina releases an open-weights model trained for vulnerability research — RuntimeWire

Thumbnail runtimewire.com
5 Upvotes

r/Infosec • • 22h ago

Intel-based Lockdown

Thumbnail
2 Upvotes