VideoSecurity
August 19, 2026

Will Bengtson, CISO at C1, and the respected engineer | The Tabletop

Written by
Sarah Cottone
Sr. Content Marketing Manager
Reviewed by
No items found.

Accelerating security solutions for small businesses 

Tagore offers strategic services to small businesses. 

A partnership that can scale 

Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate.

Standing out from competitors

Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

Watch all episodes from The Tabletop on YouTube.

Episode Description

You're the CISO at Cendril, a 500-person AI-native company moving fast. Your principal engineer—a beloved early employee—is walking out the door for the last time on Friday. But at 5:12 PM Friday afternoon, your DLP fires: 14 gigabytes just left his laptop for a personal Dropbox. In this episode of The Tabletop, Will Bengtson takes the hot seat and works the problem in real time.

Will has spent his career at the intersection of security and engineering. He built and secured cloud infrastructure at Netflix and Capital One, led platform and security engineering at HashiCorp, and taught cybersecurity as a lecturer at UT El Paso. He's now CISO at C1 (ConductorOne), the AI-native identity platform.

In this episode, host Khush Kashyap drops Will into the following scenario: He's the CISO at Cendril when a departing star engineer, Jordan Reeves, transfers 14 GB to a personal Dropbox in the final 40 minutes of his last day. The files aren't random—architecture specs for Project Helix, a feature still six months from a stealth launch; internal QA test suites; and a customer segmentation model the data team built over 18 months. Jordan's access was still live, his laptop wasn't wiped, and HR didn't formally terminate his account until 5:30 PM, a full 18 minutes after the alert fired.

Then the picture sharpens. Six weeks later, a direct competitor—Ascendant AI—ships a feature that maps almost exactly to Project Helix, down to two edge-case decisions Cendril's engineers made in internal design reviews. A patent surfaces that predates Jordan's notice, muddying the water, and soon after, Jordan's LinkedIn lists him as a principal engineer at Ascendant. 

Will walks through cutting access that SSO alone doesn't actually cut, the gap that lets offboarding lag behind risk, whether to go loud with a preservation demand or go quiet and image the laptop first, how to manage a furious VP of product and a CEO who says "I don't care if we win—I care that every engineer sees that we fight," and what the evidence really supports versus what everyone wants it to say. At the end, he renders his verdict: real incident or constructed fiction?

Quotes

“I don't know why people wait until the last day or the last two weeks to start taking the data if they're gonna take it all at once.”

“The biggest mistake is thinking that by cutting their single sign-on, that it cuts all access.”

“Why don't we put the energy into making the product better—and prove that Jordan wasn't the secret sauce that got us to where we are today?”

“Look, were these your best ideas? Can we do better? I'd hate for something like this to really poison the culture.”

“The scenarios where we think, ‘oh, this is gonna be a nothing burger,' have been the ones where customers are like, ‘What? How did you not tell us?'”

Time Stamps

[00:00] Welcome to The Tabletop: Meet Will Bengtson, CISO at C1

[00:47] The Rules: You Are Now the CISO at Cendril, a 500-Person AI-Native Company

[01:20] The Scenario: A Model Engineer's Last Day and a 5:12 PM DLP Alert

[02:00] First Gut Check: “This Sounds All Too Familiar”

[03:15] Inject One - The Full Log: 14 GB, Three Sensitive Folders, Access Still Live

[03:50] Your Next Hour: Cutting the Access That SSO Doesn't Actually Cut

[04:50] The 18-Minute Gap and the Case for Phased Offboarding

[07:00] Do You Contact Jordan? Relationships vs. Legal Exposure

[08:50] Go Loud or Go Quiet: A Preservation Demand vs. Imaging the Laptop

[10:15] Inject Two - Six Weeks Later: A Competitor Ships Your Stealth Feature

[11:00] The Patent Twist: Filed Before Jordan Ever Gave Notice

[13:30] What Evidence Do You Actually Have? Building the Civil Case

[14:50] Calming the VP of Product Down from Going Nuclear on LinkedIn

[15:50] Inject Three - Values Tradeoff: Jordan Resurfaces at Ascendant AI

[16:40] Three Legal Paths and Why He Chooses to Slow the Roll

[17:20] The CEO's Real Motive: “I Care That Every Engineer Sees That We Fight”

[18:50] Three Months Later: The Retrospective and the Culture Question

[20:45] The Moment of Truth: Real Incident or Fiction?

[21:30] Off the Table: The Biggest Mistake Companies Make Offboarding Trusted Employees

[22:25] Off the Table: Building a Security Culture That Trusts People and Still Protects What Matters

[23:50] Off the Table: The Strangest “Nothing Burger” That Blew Up

Transcript

Khush: Hi, I'm Khush Kashyap, senior director of GRC at Vanta. I'm your host today at The Tabletop. Today I'm joined by Will Bengtson. Will has spent his career at the intersection of security and engineering. He has built and secured cloud infrastructure at Netflix and Capital One, led platform and security engineering at HashiCorp, and previously a cybersecurity lecturer at UT El Paso.

Will is now CISO at C1, the AI native identity platform. But today, Will's in the hot seat playing CISO at Sendril. Will, here are the rules. You are now the CISO at Sendril. Okay. It's a 500 people fast-scaling company that runs a hot AI native platform. A scenario will unfold with multiple injects. You will give your live reaction.

At the end, you'll decide: Is this a real incident, or is it fiction? Will, are you ready for The Tabletop? 

Will: I'm ready. Let's do it.

Khush: It's 4:47 PM on a Friday, and it's the last working day for Jordan Reeves. Jordan is a highly respected and model principal AI engineer who's been with the company from its earliest days. Jordan's been professional throughout the whole transition. He gave his two weeks' notice, put together thorough hand-off docs, sent a goodbye post on Slack to all of his peers, et cetera. Did all of it. But at 5:12 PM, your DLP system flags an alert. You notice that an unusually large volume of files have been transferred to a personal Dropbox account from Jordan's work laptop in the last 40 minutes of his last day. What's your gut telling you? 

Will: This sounds all too familiar. As you were s- presenting the scenario, I just...I was like, "I know where this is going." Which is always kinda funny, and I think every security leader out here is gonna shoot me for saying this or get really upset, is, like, I don't know why people wait until the last day- ... or the last two weeks to start taking the data if they're gonna take it all at once.

But, but I mean, I think instantly it's like, doesn't surprise me. I've seen it before. You know, last day last week, starting to take some things. Whether it's malicious or not, they wanna take their portfolio or, or something that they can use to either remember what they've done or use it to present forward, uh, for the next, next gig, right?

And so, you know, instantly I'd say, "Okay, let's take a look and see what it is. Do some a- analysis. Let's first make sure that the access is cut. Should it have been cut at 5:00?" What could be improved in the beginning? But first, you know, just making sure that we can cut off any- anything else so that, one, the DLP alerts stop.

Two, we can start figuring out, okay, what's next? We need to get legal involved. We need to start issuing a stop, uh, order or, like, a legal notice to him. Is he in office? Is he still there? Are they a remote employee? I think there's a lot of situations that, you know, I'd be asking the team, "All right, where are we?"

Khush: I like where your gut is heading. So the first inject, your security team jumps into action. They pull the full log, a transfer of fourteen gigabytes started at four twenty-nine PM. The files included three folders your team considers highly sensitive One folder includes the architecture specs of a feature called Project Helix, which is still in stealth development and not scheduled for release for another six months.

One folder has internal QA test suites, and the last one includes a customer segmentation model your data team built over the last 18 months. Jordan's access was still live at the time of transfer. His laptop had not been wiped yet. HR formally terminated his account at 5:30 PM, 18 minutes after the DLP alert fired. What do you do within the next one hour? I

Will: think within the next one hour it'd be verifying that access has truly been cut off. Has the laptop truly been locked? A lot of people say, "Oh, let's cut Okta, let's cut Google access," and not realizing that still keeps quite a broad set of access out there. You know, Notion session might still be active, Slack session might be active.

You know, what do we have? Are we so small that we don't have Grid yet so that we don't have the ability to, when the SSO goes dead, that Slack goes deactive? And just really start thinking, okay, do we have our bases covered there? And then I think from then, start digging into, okay, let's do some deeper analysis of the data.

How, how bad is this? Do we think it's malicious? Working with the people team to, to understand, is Jordan going to a competitor? You know, is this gonna be a, a Waymo-Uber-type scenario, right? Do we need to get legal involved right away? I think initially it would [00:05:00] be, um, letting the co-founders know, since Jordan's been there from the beginning, likely a close confidant of them.

Can they call him to understand what is going on? It kinda reminds me of the Log4j. You know, everyone spent hours patching the first patch, and then they're like, "Ha, just kidding. That didn't actually work." Everyone had to do it again. I, I don't want teams to have to spend that much time, especially going into a weekend, redoing analysis.

Khush: You talked a little bit about the pros- people process side going wrong there. Um, the DLP alert fired 18 minutes before off-boarding was done. What does that gap tell you about your process? 

Will: Typically, if, if the process says, you know, terminate employee at 5:00- Mm ... I think the... It doesn't say anything about a gap. I think if we think about a typical last day of an, of an employee, are they really working at the end of the day? And so maybe the, the gap in the process is, should critical systems be cut off much sooner?  And so should Jordan still have access to those critical components on their last day of work?

Yeah. And should that have potentially been cut off a week prior, one day before? Which could potentially have said, "Okay, well, you can still access your payroll and things like that, that you might wanna download some of your pay stubs for, you know, maybe you're buying a house or whatever you might need for the, the next, next role."

Mm. But not necessarily have access to the secret sauce, right? It all depends on the, the various different shapes of the company and what technologies are in play. Uh, is any sort of local compute allowed? Is everything in the cloud? And so what kind of controls could you actually do? Or maybe, you know, at previous companies, we put in, like, heightened alerts- Mm on people on their last two weeks. that they were actually giving notice versus being terminated. That's when new DLP rules went into effect. And which is kind of to my point earlier, it's always kind of funny when the last two weeks, that's when things happen, right? You know, a month before downloading, you know, 20 Git, Git repos might not be a, a flag, but on your last two weeks when it's not typical- Mm that, you know, that's a flag. So those would be the kind of things that would be jotting down to think about, okay, could we improve this in the future? You know, kind of to the, should they still have access to these things at the very end? 

Khush: Jordan is technically no longer an employee. Do you try to reach him directly, or does that create legal exposure before you know what you're dealing with?

Will: I think it depends on how confident we are on what data they have in the beginning. As I mentioned earlier, you know- Being an early employee there for all along, likely has really good relations with the co-founders, perhaps worked with them many companies before that. And so I think it's like, okay, you know, let's... You know, maybe it's, hey, it's, you know, CEO, whoever it is, can you reach out to Jordan and just ask like, "Hey, was this malicious? What is the intent?" But I think it depends also, do we have internal legal? Do we have to go to outside legal counsel? If it's outside legal counsel on a Friday, are they in the same time zone?

Are they still working? Can we get a hold of them? I think there's a lot of potential, you know, what if, you know, to see how the stars align. In previous scenarios where we've had this happen, um, we've reached out to them personally.  The, the person agreed that, "Oh, sorry, I didn't mean to do this," or, you know, "I didn't think anything of it when I was doing it."

Obviously, they meant to do it 'cause they did the downloading themselves. But we followed up with a legal letter to them, and then asked them to send the drive in that they downloaded it to. In, in the, in the case of that one, it was a USB drive, and then we destructively destroyed the, the data at that point.

So we can kinda check our boxes to say they sent the data in. You know, in the case of cloud days, w- was uploaded to their Dropbox or a Google Drive or something, you know, there's not... There's only things but them to sign like an attestation form- Mm ... that, "Yes, I did, I did comply with your order." I would believe at this point that the, the relationship is there with the CEO or CTO or whose... If some early employee that we could kinda get a feel and ask them. Otherwise, you know, I think there obviously should be some sort of legal letter mailed, regardless of if like, "Hey, you know, Jordan's my good friend, I trust him completely." Just to cover the bases in, in the future I'd be pushing for legal to send some sort of notice.

Khush: So let's set the stakes. You have got the alert, the file list, and the 14 [00:09:00] gigabytes now sitting in a personal Dropbox you have zero control over. Jordan's been off the clock under an hour. Do you either go loud, have legal fire off a preservation and return demand tonight, which means you have tipped Jordan off, and if this was an innocent portfolio grab, you have declared almost like a war on a beloved engineer over the weekend. Or do you go quiet, lock your own logs, image the laptop, build the picture before you ever contact Jordan, knowing that every hour you wait you can empty that Dropbox and you're left with nothing? 

Will: Interesting. So I can only choose one? Um, I think from a security scenario w- we're likely pushing towards, let's just image the laptop, let's make sure we capture our evidence. And we can actually... You know, do we have CrowdStrike or something that can actually show the data flowing, or is it NetScope or something that's actually... What is the DLP that actually flagged the alert? Make sure we have those logs captured, documented, so if there is a case in the future and, well, like Uber Waymo, we have everything that we could bring forward to show that this person stole the data, and that data rep- is very close to what we're seeing now. And then potentially follow up.

Khush: So here is your second inject. Let's speed forward a bit. Six weeks pass. Your team has been monitoring quietly. Then at 7:00 a.m. on a Tuesday, your VP of product sends you a Slack message. It has a screenshot and four dreaded words: "Did you see this?" It turns out that Ascendant AI, your direct competitor, just announced a new feature.

Their blog describes a capability that maps almost exactly to your project helix. It has the same technical approach, same UX framing, and two of the same edge case handling decisions your engineers made during internal design reviews. You don't have proof that Jordan shared anything. You do have a DLP alert and a competitor product release that looks like, let's be honest, wild coincidence.

Then your most junior analyst flags something nobody wants to hear. Ascendant filed a patent application eight months ago, before Jordan ever gave notice, describing this exact approach at a very high level. The broad strokes are arguably already theirs, but the patent doesn't mention the two edge case decisions your engineers made in internal review, and those match exactly.

Your engineering leadership is furious. Your CEO wants to brief the board this week. Your legal team wants to know if this rises to litigation. What do you do, and what do you say to each of them? 

Will: I think, you know, given that eight months ago, you know, probably is, you know, a long time of work, perhaps Jordan is being, you know, wooed by a said competitor, maybe putting feelers out and interviewing, talking about things- violating, you know, non-disclosures and, you know, privacy agreements that he's had with, with, with our company. You know, it is coincidental, so it'd be really like, do we really think that that data Was verbally communicated at a high level, which allowed them to do the patent. We'd... I'd probably wanna go look and see was there any previous indication that other data was taken. Whether it was that big of a time, and if that was the case, why would Jordan take it at the end? If we're, like, one, two in, in the space, my guess is, you know, the board is gonna push for a legal notice and action-  just to cover them, and that's what the investors are gonna want. Meanwhile, we'd be trying to figure out, okay, is there any other evidence that we could point to to say, yes, the, this is highly coincidental, and it's just unfortunate that we've been spending as much time they have as well.

And I think it depends on what the evidence we're pointing based on, you know, from a security standpoint, what we, what we'd be doing. But I think it ultimately it'd be, okay, what is the CEO's approach? 

Khush: Yeah. 

Will: Do we double down and say, "Okay, who cares? We still have the better company, the better tech. We have the..." I can't remember if you said the two edge cases w- weren't met in the patent that we've done differently. They, they were not were not included in the patent. And so we still have that advantage over them-: uh, which is enough probably to make that patent unenforceable. Work with their comps team and PR to try to figure out what is the shape that we actually wanna take, because that'll affect us in the future for recruitment and a bunch of other things.

And so unless we have really hard evidence, should we just double down and become the better company? Write it off as a loss. I'd be looking at those and giving those as m- my recommendation, or here are the scenarios that I'd lay out for them and give the board, "All right, what are your options? What are you gonna choose?"

Khush: I like that. I really like the grounded approach as a CISO that you're taking to- towards each of the stakeholders and what's motivating them or what's keeping them behind, et cetera. I do have a few follow-ups on certain stakeholder tangents here. So let's first talk about the legal ones. Your legal team asks whether you have enough to pursue a civil claim. What evidence do you actually have right now, and what do you still need? 

Will: We definitely have the evidence of the last day of work, the 14 gigs downloaded and what they, what those contained Uh, would likely have already requested, depending on if we had the ability or if we... Assume we're using Slack or Teams or something, whether we have the ability to go do an e-discovery on everything Jordan did, so we can actually understand what else they accessed or were talking to others about.

Mm. Where, where maybe that could lead to some other evidence to support that. And then based on that, give, come back to the legal team and say, "Here's what we have. You know, I'm not the lawyer, so I can't tell you whether we have enough for a civil case, but you could decide, right?" Okay. 

Khush: So what I'm hearing is definitely go beyond the DLP alert and the logs that you have there, and start looking into communications with their peers and anything else that you find on the internet.

Will: I think if I was Jordan's defense- Mm. If, if it did come to something, it'd be like, "Well, what evidence do you have to point that no one else did this," right? Yeah. And were you just so focused on Jordan being the, the person that you were so blinded by, you know, Michelle over there. You know, Steve. Mm. And they were the actually the ones that were doing the thing. 

Khush: Second stakeholder I want to ask you about is the VP of product. The VP of product wants to go nuclear and call out the feature similarity on LinkedIn publicly. How do you calm them down? 

Will: You know, I think, I think it's almost one of those, like, challenge scenarios for the, the VP of product. It's like, "Look, were these your best ideas? Can we do better?" 

Khush: Mm. 

Will: You know, and try to get them not to focus on the past and focus on the future. Like, how do we, how do we get better? How do we make it so that in the future, uh, you know, they can't catch up to us? So I'd really be pressing the, the product person to really just, "Hey, let's take a deep breath, step back."

Mm. "Let's get in a room and strategize. Get some other people, and let's just, let's start talking about it and lay out the different scenarios. Do a tabletop, right? And say, 'Okay, if this is truly our, our, the only thing that will, will make us successful, then let's figure out the right way  to show how we did it first.'" I think the last thing I would want as an executive on this company is for one situation handled poorly to turn a lot of people against us, 'cause that'll affect recruiting, image, everything in the future.

Khush: Let's go on our inject three.  So if your team wasn't fired up before, now they are. 

Will: Oh, boy. 

Khush: Jordan's LinkedIn profile has been updated. He is now listed as a principal engineer at Ascendant AI, and he started three weeks ago. Your legal term has identified these three paths. One is send a cease and desist to Jordan and Ascendant AI.

It signals you are serious, but it could go public fast and may spook your customers before you've controlled the narrative. Option two, file a civil suit immediately. It's aggressive, expensive, and a long road, and let's be honest, your evidence is still circumstantial, to your point as well. Option three is investigate further, document everything, wait for a clearer picture before acting externally.

That option buys time, but risks Ascendant AI shipping a second feature before you move. Which path do you decide to take? 

Will: You know, immediately, I, uh, I like option three better because it's, okay, let's really just slow our roll. I'd really be wanting to make sure we had a s- open and shut case- Mm ... before really pushing forward.

Khush: One stakeholder that we haven't talked about before is the CEO. So Jordan has said nothing publicly. Ascendant AI has said nothing publicly either. But your CEO tells you, "I don't care if we win. I care that every engineer thinking about leaving sees that we fight." 

Will: Hmm. 

Khush: How do you answer when business strategy is steering a legal call?

Will: Yeah, I think I'd, I kind of point back to the, the similar, like, strategy I'd have with the product person. Yeah. It's like, "Look, can we not do better?" Like, and really, and I think it's r- it's really rallying the troops, right? Mm. It's really, it's like, do you think what we shipped is the best, and us fighting is going to change that outcome? Why don't we put the energy into making the product better, adding new features, new advancement, new secret sauce that is gonna further set us apart and prove that Jordan wasn't the secret sauce that kept us or got us to where we are today. Mm. Really, I'd, I'd hate for something like this to really poison the culture.

Khush: Mm. 

Will: Especially you're in a probably a hyper-growth phase. Uh, you obviously don't want attrition, but I'd really be focusing on, okay, how can we use this positively and really focus on- You almost like, attaboy, you know, the whole feed the egos of the engineers and show them and prove to them that, hey, this is what got us to where we are today. This is why they're copying us, 'cause obviously we're doing it the best.  We can do more and greater things and figure out how do we leverage technology or whatever to get to the next step. 

Khush: Let's fast-forward, and let's take the temperature down a bit.  Fast-forward three months, legal proceedings are underway.

Your access management policy has been overhauled. DLP alerts now route in real time. Looking back at the full arc, the trusted engineer, the last day transfer, the competitor feature, what was the single decision or non-decision that put Cendril on this path? 

Will: Yeah, I think, I think, you know, with any scenario like this, it, it, it should trigger some retrospectives in all areas.

How could we improve the off-boarding people process, access controls, as I mentioned earlier, like should we have cut access to certain systems earlier? And your off-boarding should be a phased approach, so you can still hand things off. But, you know, in your... I don't know. When I've left company, I've been working to the last minute.

But, you know, a lot of people, the last week is kind of goodbyes. And we schedule some one-on-ones. And so how could we improve that and even set expectations? As you go through your last two weeks, here's what you can expect. Uh, 'cause that could potentially improve some things. Maybe it sets some new, you know, baselines that everyone should be following so no other company falls into this. Essentially, once again, the culture. How do we want the culture to evolve? 

Will: Cause if you go to like a lockdown defensive nature as if you're working the, you know, Pentagon or something, a lot of people aren't gonna like that. But there are, there are ways that you could keep it free, open, fully transparent with increased monitoring and things that, better automations and actions that could prevent, you know, entire data leakage like what we had.

Khush: Will, I have one last question for you. You have spent the past few minutes in the hot seat debating the motives of Jordan, an ex-star employee, managing a CEO who wants answers before you have them, and staring down competitive features that are uncannily familiar to your own. Does this feel like something that actually happened or something that we invented?

Will: I feel like it's something that happened. 

Khush: So your final answer, is this real or fiction? 

Will: I think it's real. 

Khush: Here's what I'll say. I know it felt very real, which is the point. The scenario in itself is fictional, but it's built from patterns security leaders are living right now. You yourself would have lived it for super long, especially in AI with the race to ship, and the war for senior talent is so high, we're just seeing more and more of these patterns emerge.

Will: Through this whole scenario, I'm like Uber, Waymo, Wiz, Orca. It's like there's so many pieces of like... I was like, "Is this the Silicon Valley episode?"

Khush: Now let's do a quick round of Off the Table, our opportunity to get off-the-cuff answers on big security questions. What's the single biggest mistake companies make when off-boarding trusted employees? 

Will: The biggest mistake is thinking that by cutting their single sign-on that it cuts all access. Uh, I think time and time again, I've experienced myself when my access has been cut at, at previous companies when I've left and/or seeing down the line when going through and cleaning up systems like, "Oh, this... Why is this person's account still here?" Of that thinking that you cut SSO, it cuts it all. Depending on if y- how early of a stage company you are, you might not be paying for, uh, you know, the, the tier that actually gives you control for how long sessions can be or control mobile sessions or whatnot. And so that's the unfortunate bit, which it makes it even harder.

Khush: How do you build a security culture that treats people as trustworthy and still protects what matters? 

Will: For me, it's giving context to everyone to understand, like, okay, here's our mission. What are the things we care about? Why do we care about them? Give them some examples of impact, and then, you know, really prove to them that, hey, we're n- we're not here to be, you know, the, the bad person. You know, we wanna be partners. I've tried to build organizations that are very technical- so that, especially when working alongside probably the closest partner of any security team is engineering, is that you're treated as a peer to them and not just some security team that they've had bad experiences with in the past.

You understand exactly the problems that they're facing, uh, and you can talk the same language. Conversely to that as well, the rest of the organization, which is likely bigger than engineering, being able to talk those languages as well, understand what they're trying to solve as well, 'cause if you're only focused on a single problem, you haven't built a, a culture that fits the entire company.

You've built one, the small subset. And so I really think it's really just driving home that, like, hey, we're not here to, to prevent work and make it even harder. If you find a scenario that, you know, we're... what we've done is friction, come talk to us. Let's work together and solve it together. And then I think that's b- that's when you become the approachable security team and people start coming to you versus trying to avoid you in all the things, and it creates that really nice security culture. And do they understand the why- Mm ... and what, and then that, that really helps you expand your security team 'cause then everyone's looking for it and become that security champion, if you will. 

Khush: My last Off the Table question for you is, every security leader has one incident that still makes them shake their head, something strange, unexpected, or almost too absurd to believe. What's yours, if you can share? 

Will: I think it's back to the access. You get to a certain size of a company, you've got 400 plus applications in SSO, and you think, oh, everything's really great, and you've been spending years building an identity team and identity products internally, and then you get hit with some silly, like- credential exposure from some info stealer from six months ago, or this one system that doesn't have anything sensitive in it was accessed by a security researcher.

And you go look, and it has SSO on it, but it's not enforced, right? And it's, it's kinda like just the, the dumb scenarios that are just like, they're not dumb 'cause they're, they're serious. Mm-hmm. But it's one of those where it's like, I thought we just did an overhaul, and we went and looked over everything.

But we forgot to mention like, oh, make sure this one checkbox is checked. Mm-hmm. In my experience, the, the scenarios in the past where we think, oh, this is not g- this is gonna be a nothing burger, as I call it, have been the ones where like customers are like, "What? How did you not tell us?" And it's like, this isn't you know, this is a personal matter, you know, like th- marketing dataa or something. It's, uh... And so I think, yeah, the scenario around that is, is one that has been just one of the silliest ones to me that ultimately was nothing. But it blew up to be much bigger. Yeah. And ultimately, it, you know, for me it was actually really insightful, 'cause it's like wow, we actually had contracts that said we needed to mail notices.

Like what... And certainly having to dig deep into contracts to actually figure out what have we promised before security became a thing as part of this company for like previous MSAs and preceding the security team. 

Khush: Will, you survived the tabletop. Thank you so much for being here.

Will: Thanks for having me. This was great.

Access Review Stage Content / Functionality
Across all stages
  • Easily create and save a new access review at a point in time
  • View detailed audit evidence of historical access reviews
Setup access review procedures
  • Define a global access review procedure that stakeholders can follow, ensuring consistency and mitigation of human error in reviews
  • Set your access review frequency (monthly, quarterly, etc.) and working period/deadlines
Consolidate account access data from systems
  • Integrate systems using dozens of pre-built integrations, or “connectors”. System account and HRIS data is pulled into Vanta.
  • Upcoming integrations include Zoom and Intercom (account access), and Personio (HRIS)
  • Upload access files from non-integrated systems
  • View and select systems in-scope for the review
Review, approve, and deny user access
  • Select the appropriate systems reviewer and due date
  • Get automatic notifications and reminders to systems reviewer of deadlines
  • Automatic flagging of “risky” employee accounts that have been terminated or switched departments
  • Intuitive interface to see all accounts with access, account accept/deny buttons, and notes section
  • Track progress of individual systems access reviews and see accounts that need to be removed or have access modified
  • Bulk sort, filter, and alter accounts based on account roles and employee title
Assign remediation tasks to system owners
  • Built-in remediation workflow for reviewers to request access changes and for admin to view and manage requests
  • Optional task tracker integration to create tickets for any access changes and provide visibility to the status of tickets and remediation
Verify changes to access
  • Focused view of accounts flagged for access changes for easy tracking and management
  • Automated evidence of remediation completion displayed for integrated systems
  • Manual evidence of remediation can be uploaded for non-integrated systems
Report and re-evaluate results
  • Auditor can log into Vanta to see history of all completed access reviews
  • Internals can see status of reviews in progress and also historical review detail
FEATURED VANTA RESOURCE

The ultimate guide to scaling your compliance program

Learn how to scale, manage, and optimize alongside your business goals.