#grc
5 posts · Last used Aug 03
Basecamp Briefing for Monday, August 3rd.
#InfoSec | #GRC | #CTI news and resources you may have overlooked.
Curated by Sherpa Intelligence: Your Guide Up a Mountain of Information.
https://sherpaintelligence.substack.com/p/basecamp-briefing-august-3-2026
Basecamp Briefing: July 29th 🦈 Shark Week Special
🦈 Legal Research Resources
🦈 Community Updates
🦈 #InfoSec/#GRC/#CTI News
https://sherpaintelligence.substack.com/p/basecamp-briefing-july-29-2026
Subscribe now and don't miss the Shark Week version of Basecamp Briefing featuring international law news & #OSINT resources for #InfoSec, #GRC, and #CTI. 🦈🤖⚖️ https://sherpaintelligence.substack.com/p/basecamp-briefing-shark-week-2026
Boosted by @welcome@friends.deko.cloud
Hello Mastodon! 👋 First post here.
Head of IT & Cybersecurity Infrastructure and USAF veteran diving into the fediverse. Expect posts on cybersecurity operations, GRC, risk management, and building resilient network architectures. Let’s connect!
#Cybersecurity #InfoSec #CyberOps #GRC #Introduction
Man #Vanta is so bad...
Their Entra MFA enforcement check is horrible. It only checks if a conditional access policy exists, and if it has 'MFA' in the builtinControls. If it does, it's a pass.
But it doesn't check...
- if any users are excluded from the policy
- if any groups are excluded
- if the policy covers all users even after exclusions (e.g. if the exclusions are service accounts for any reason)
- if the geoblocking is functional
- if any of the excluded users are privileged
Vanta is a tool designed to mislead auditors, presenting as a third-party authority with their 'trust center' and all the flashy shiny dashboards.
Yet the core is rotten.
I haven't been this insulted since I found out that #vanta has a barely functional risk API (was trying to sync our risk register from our internal repo... long story).
Just... I lack words.
#infosec #cybersec #grc #privacy #compliance #fintech #informationsecurity #audit #soc2
You've seen all posts
