Security leaders are being asked to manage a growing set of risks while giving customers, boards, executives, insurers, and business partners greater confidence in how those risks are controlled. That pressure is especially pronounced for mid-market companies, where the complexity of the technology environment can grow faster than the security and GRC teams responsible for overseeing it.
Customers are giving vendors access to sensitive data and increasingly interconnected technology environments, often while depending on those vendors for critical parts of their own operations. Each relationship creates exposure that security and risk teams have to evaluate, and companies increasingly need credible evidence that they can manage the responsibility that comes with that access.
The 2024 cyberattack on Change Healthcare demonstrated just how quickly a cybersecurity failure can become a business crisis. Change Healthcare is deeply embedded in the U.S. healthcare system, processing a massive volume of claims, payments, prescriptions, and other transactions. When its systems were disrupted by a ransomware attack, the impact extended far beyond the company itself. Hospitals, physicians, pharmacies, insurers, and patients experienced disruptions to critical business and healthcare operations. The incident ultimately became the largest healthcare data breach reported in the United States, affecting an estimated 190 million people.
What makes the incident particularly relevant for businesses today is not simply the scale of the breach. It is the degree to which one company’s risk became everyone else’s risk.
That is increasingly the reality of doing business in a connected economy. Companies depend on technology providers, software platforms, cloud infrastructure, payment processors, logistics providers, and other third parties to operate their businesses. When one of those organizations experiences a significant control failure, the consequences can quickly move through the ecosystem.
Cybersecurity risk has therefore become business risk. And as companies grow, that connection becomes increasingly important. More customers, more data, more technology, and more third-party dependencies create more opportunities for risk to enter the business—and more potential consequences when controls fail.
Large incidents create obvious financial consequences, but security failures can also change how customers, partners, boards, and other stakeholders assess an organization. Lost confidence can affect commercial relationships long after the immediate incident is resolved, which makes the strength of a company’s security controls relevant well beyond the security organization.
Learn more: Healthcare Cybersecurity in 2026: Why HIPAA Readiness Now Requires Proof
Cybersecurity controls are business controls
A mature cybersecurity program gives leaders a structured way to identify risk, establish controls that reflect the organization’s environment, and understand whether those controls continue to operate as intended. A rigorous security audit adds another layer of scrutiny by testing the evidence behind that program and identifying weaknesses that internal monitoring may not have surfaced.
Written policies alone offer limited insight into how a control performs under real operating conditions. The disconnect between policy and execution exposed a much larger issue: security leaders need visibility into whether the controls they depend on are consistently working across the organization.
I’ve spent much of my career looking at risk through this lens. Before Thoropass, I spent more than 20 years in risk management for a major bank, where my work included IT controls, compliance, and vendor management. That experience reinforced how sophisticated risk organizations evaluate security. They want to understand the control environment, see evidence that it operates consistently, and have confidence that weaknesses will be identified before they create larger exposure.
That expectation now extends deep into the third-party ecosystem. Mid-market companies may be vendors themselves while also depending on hundreds of technology providers to operate their businesses. Security and GRC leaders sit at the center of both sides of that equation: evaluating the risk introduced by their own vendors while demonstrating to customers that their organization can be trusted with the same responsibility.
Learn more: High-Growth Companies Move Fast. Risk Management Has to Keep Up
Customer trust increasingly depends on evidence
Enterprise security and third-party risk teams rarely rely on a vendor’s description of its security program alone. They review audit reports, examine the controls being tested, evaluate exceptions, and consider whether the assurance provided reflects the risks they care about.
The quality of that evidence can shape the diligence process. I’ve seen situations where the quality of a SOC 2 report influenced how an enterprise viewed the organization presenting it, particularly when the scope, testing, or control environment suggested that the report provided less assurance than the buyer expected.
For CISOs and GRC leaders, this creates a direct connection between the security program and the commercial side of the business. Credible evidence can give prospective customers more confidence in their risk decisions, reduce unnecessary cycles of follow-up during security reviews, and provide a stronger foundation as customer relationships expand.
That becomes increasingly valuable as a company grows. Larger customers, regulated industries, and more complex partnerships tend to bring greater scrutiny. Security leaders need an assurance program capable of supporting that scrutiny without forcing their teams to repeatedly reconstruct the same evidence for every customer request.
How SOC 2 supports a mature assurance program
SOC 2 can play an important role in that program. The AICPA’s Trust Services Criteria provide the basis for evaluating and reporting on controls related to security, availability, processing integrity, confidentiality, and privacy.
A strong SOC 2 audit gives customers an independent assessment of the controls they’re being asked to rely on. It can help address questions that an outside customer has limited ability to answer on its own: Are the controls appropriate for the organization’s environment and risks? Are they operating consistently? Does the evidence support what the company says about its security program?
Those same questions are useful internally. A well-run audit can give CISOs and GRC leaders another view into the health of the control environment, highlight areas that deserve attention, and strengthen the evidence they use when communicating with executives, customers, and other stakeholders.
The usefulness of the report depends heavily on the work behind it. Since its launch in 2010, SOC 2 has become widely adopted, and audit approaches can vary considerably. Experienced security teams can recognize the difference between testing that reflects the complexity of the organization and an approach built primarily around a standardized set of controls.
For a security leader, that distinction has practical consequences. An audit report may eventually sit in front of a sophisticated customer’s security team, procurement organization, regulator, insurer, or board. The organization needs to be confident that the work supporting the report will hold up to that level of scrutiny.
Your auditor becomes part of your assurance program
Security and GRC leaders already apply significant discipline when evaluating critical technology providers. The audit firm responsible for assessing their controls deserves the same level of consideration because the auditor’s methodology and judgment directly influence the quality of the resulting assurance.
Audit quality depends on the firm’s methodology, professional judgment, and the rigor with which evidence is evaluated. In risk-based frameworks such as SOC 2, auditors also need enough understanding of the organization to assess whether its controls are appropriate for the risks created by its actual business model, systems, data, and operating environment.
That becomes more important as organizations grow. A mid-market company may have multiple products, cloud environments, business units, integrations, geographies, and regulatory obligations. Its control environment often contains dependencies and exceptions that don’t fit neatly into a generic audit playbook. Security leaders need auditors who can understand that context and apply sound judgment without creating unnecessary complexity for the teams doing the work.
My co-founder Sam and I have written previously about how shallow or highly standardized SOC 2 audits can reduce the commercial value of the resulting report. The concern for a CISO or GRC leader is broader than the report itself: weak testing can provide less useful information about the control environment while leaving the organization with assurance that may not stand up as well under customer scrutiny.
AICPA Peer Review provides another useful source of information when evaluating a CPA firm. The program examines accounting firms’ quality systems and is an important mechanism for maintaining audit quality and confidence in the profession. Organizations choosing a SOC 2 auditor should understand whether the firm participates in the appropriate peer review process and review its latest result. Thoropass Assurance completed its second AICPA Peer Review in 2025 and again received the highest possible Pass rating.
Trust is becoming a business asset
Security leaders have long understood the relationship between controls and risk. More executive teams are now seeing how the strength of those controls can influence customer confidence, business relationships, and the organization’s ability to grow.
High-profile breaches have given customers more reason to examine how their vendors protect data and manage cybersecurity risk. Enterprise buyers have also become more sophisticated about the evidence they accept. Strong controls supported by credible assurance give security leaders a way to respond with evidence that reflects how the organization actually operates.
For mid-market companies, that capability can become a competitive advantage. A mature security and assurance program can make it easier for customers to evaluate the organization, give business leaders greater confidence entering demanding markets, and help security teams scale trust without turning every new customer into another bespoke diligence exercise.
A rigorous audit contributes to that program by testing whether controls are working, surfacing weaknesses that deserve attention, and providing customers with credible evidence they can use in their own risk decisions. The quality of the audit determines how much confidence security leaders and their stakeholders can place in the resulting assurance.
Trust takes years to build and carries real economic value. CISOs and GRC leaders who treat audit quality as part of their broader risk strategy can strengthen the evidence behind their security program, give stakeholders greater confidence in the organization, and help the business compete from a stronger position.
Related Posts
Stay connected
Subscribe to receive new blog articles and updates from Thoropass in your inbox.
Want to join our team?
Help Thoropass ensure that compliance never gets in the way of innovation.










.png)