The Compliance Brief for ISO 27001 teams
Every Tuesday, the supplier incidents, AI risk stories and security events from the past week that belong in an ISO 27001 or ISO 42001 risk register.
An ISMS is only as current as its risk register, and most registers are updated once a year. The Compliance Brief is a weekly prompt: the supplier breaches, AI agent incidents and supply chain attacks that a surveillance auditor would expect you to have noticed.
Below are the stories from recent issues that bear on ISO 27001 and ISO 42001, each with the short version and a link to the full take.
Free weekly email
Get the next issue on Tuesday
Join the list and the next issue arrives Tuesday morning. Or read a few below first.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.
Latest on ISO 27001, ISO 42001 and supplier risk
- Your AI agents are logging in as humans and SOC 2 cannot tell
A vendor-authored piece argues that AI agents often operate through human credentials, so actions taken by an agent look identical to actions taken by the person whose credentials it borrowed. - A regulator has now logged an AI agent as the attacker
The Spanish data protection agency received a breach report describing an attack carried out by an AI agent running on a known large language model. - Trezor's supplier breach keeps growing, and it was never Trezor's system
Trezor says a breach at its supplier ShipMonk is considerably worse than first reported, now affecting around 81,000 customers. - AI coding agents are pulling packages nobody registered
Researchers scanned 6,214 live domains belonging to defence contractors, Fortune 500 and large tech companies and found 8,265 llms.txt and llms-full.txt files. - McKesson tells the SEC it was hit through third-party applications
McKesson disclosed a cybersecurity incident in which attackers got into third-party applications and stole data, with the intrusion detected on August 25, 2026. - McKesson breach came through third-party applications
McKesson disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft. - The LiteLLM fallout is a CI credential problem, not an AI problem
A 153GB archive stolen in the LiteLLM supply chain attack has surfaced, containing 433,909 files. - Hidden prompt injection is showing up in "Ask AI" buttons on marketing pages
Researchers observed production websites embedding hidden prompt injection payloads inside pre-filled deep links behind "Ask AI" buttons, including on marketing and competitor comparison pages.
Every issue on ISO27K
- Issue 8: Your AI agents are logging in as humans and SOC 2 cannot tell
- Issue 7: A regulator has now logged an AI agent as the attacker
- Issue 6: Trezor's supplier breach keeps growing, and it was never Trezor's system
- Issue 5: AI coding agents are pulling packages nobody registered
- Issue 4: McKesson breach came through third-party applications
- Issue 2: The LiteLLM fallout is a CI credential problem, not an AI problem
- Issue 1: Hidden prompt injection is showing up in "Ask AI" buttons on marketing pages
Every issue in full, including the stories outside ISO 27001, ISO 42001 and supplier risk, is in the archive on traztech.ca. Issues with nothing on ISO 27001, ISO 42001 and supplier risk are listed there and not here.
Questions
How often does The Compliance Brief arrive?
Once a week, on Tuesday morning. Each issue covers the past week in five stories or so, with what happened and a short take on what it means for teams running an ISO 27001 or ISO 42001 management system.
What does it cost?
Nothing. It is written by Jacob Masse, Principal at TrazTech Inc., which operates ISO27K. There is no paid tier.
Will signing up here send me anything else?
No. The form on this page adds you to The Compliance Brief and nothing else. Downloading a checklist elsewhere on the site is a separate signup, and it says what it sends before you give an address.
How do I stop it?
Every issue ends with a one-click unsubscribe link, and it is honoured immediately. Replying to any issue also reaches Jacob directly.
Free weekly email
Get it every Tuesday
One email a week on ISO 27001, ISO 42001 and supplier risk. Free, and one click to leave.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.