‹ #security-compliance 12 members
R
Rosa 11:20 AM
@Dash what's our top vendor and security risk right now — flag anything high-risk, non-compliant, or expiring
Dash App 11:22 AM
Pulled live from the compliance monitor — 110 vendors, 296 controls. Here's the full risk picture:
🔴 7 controls are non-compliant today
Mapped to SOC 2 / ISO 27001:2022 / HIPAA and flagged isReady=false. Three are auth and session-management controls — those likely belong to the engineering lead. One has no owner at all. That one is the first thing an auditor will ask about.
⚠️ Vendor risk
- 26 HIGH-risk vendors active, 6 critical
- 5 vendors are both critical and HIGH — your cloud host, identity provider, code host, CDN, and DNS. All co-renew in early April 2027. Start the review process now to avoid a compressed window.
- Top PII-handling HIGH-risk vendors: your CRM, payment processor, billing system, communications platform, and data warehouse. These are the ones where a breach is most costly.
- 127 controls have no assigned owner — not currently failing, but this will show up in your next audit.
🟢 Renewals clear through Q4
Nothing overdue. Nothing expiring in the next 90 days. The nearest cluster is Mar–Apr 2027. Set a calendar reminder for January to start those reviews.
Want a prioritized owner-mapping for the 7 non-compliant controls, or a full ranked list of HIGH-risk vendors by PII exposure?
👀 3 🙏 1
+ Message #security-compliance ☺