The FBI’s 2025 Internet Crime Report and How SOC 2 and ISO 27001 Can Help Keep You Safe

Cybercrime hit a new high in 2025: over 1 million complaints and more than $20 billion in reported losses, according to the FBI's latest Internet Crime Report. The biggest culprits weren't exotic zero-days. They were business email compromise and ransomware, attacks that exploit gaps in process, training, and access control. The good news? SOC 2 and ISO 27001 already include the controls that shut these attacks down. Here's how they map.

The FBI’s 2025 Internet Crime Report and How SOC 2 and ISO 27001 Can Help Keep You Safe

Each year the FBI’s Internet Crime Complaint Center (IC3) issues a report on cybercrime. According to the 2025 report (https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf), the IC3 received over 1 million complaints with over $20 billion in reported losses. 

How fraudsters are stealing from companies might be the most surprising stat. Investment fraud totaled $8.6 billion, Business email compromise totaled $3.05 billion, and tech support scams came in at $2.13 billion. 

Business Email Compromise

The FBI classifies Business Email Compromise as a scam targeting businesses or individuals working with suppliers and/or businesses regularly performing wire transfer payments. These sophisticated scams are carried out by fraudsters by compromising email accounts and other forms of communication such as phone numbers and virtual meeting applications, through social engineering or computer intrusion techniques to conduct unauthorized transfer of funds. 

SOC 2 and ISO 27001 both have controls that can make employees aware of the scam and provide other ways to identify bad actors.

Ransomware - Not Just an Enterprise Problem

When we talk about security incidents we often think of bots and ransomware. Ransomware accounted for $32 million in reported losses. The FBI notes that this number is low as it does not account for losses due to downtime, remediation, third-party recovery costs and that many organizations don’t report it at all. Many small and medium sized businesses may assume that ransomware is just an enterprise problem, the top reported industries were legal services (18%), contracting (17%), engineering/architectural services (10%), consulting (7%) and non-critical manufacturing (5%). 

What can organizations do to stop these threats? Here is a table of FBI (https://www.fbi.gov/investigate/cyber) recommendations for protection against Ransomware attacks mapped to SOC 2 and ISO 27001 controls:

The Takeaway

The  FBI’s Internet Crime Complaint Center tells a consistent story about how attacks cost business money. Business email compromises and ransomware don’t succeed because of a lack of technology. They succeed due to gaps in processes, training or access control that gave an attacker the opening they needed. 

The SOC 2 and ISO 27001 frameworks provide organizations with a structured way to build processes and habits. These frameworks do more than just unlock sales and get you out of filling out a vendor questionnaire, they help protect your customers, brand reputation and bottom line.

Ready to get started with compliance?

Get a proposal in 48 hours. Start your compliance journey today.

Related articles

Jan 17, 2023

SOC 2 vs. ISO 27001: Which to Choose

SOC 2 vs. ISO 27001: Which to Choose

SOC 2
ISO 27001

You're probably familiar with ISO 27001 and SOC 2. You may have also heard that they are similar, but there are critical differences between the two standards.

This post will examine these differences and help you decide which standard suits your organization.

What is SOC 2?

SOC 2 is a certification to help organizations establish and maintain a comprehensive ISMS. It's an independent audit, review, and attestation of the security controls in place at the company. The AICPA (Association of International Certified Public Accountants) maintains the standard. In other words, SOC 2 is a framework that guides how to build an effective Information Security Management System (ISMS).

The standard consists of three parts:

  • Part 1: Service Organization Controls
  • Part 2: Attestation Engagements
  • Part 3: Communication Processes

READ MORE:  What is a SOC 2 Attestation?

What is ISO 27001?

ISO 27001 is a risk management standard that specifies requirements for an Information Security Management System (ISMS). The goal of an ISO 27001 is to help organizations implement an information security policy and achieve compliance with requirements laid out in other international standards such as ISO 9001: 2000.

ISO 27001 (also known as ISO/IEC 27001:2013) is a process standard that outlines the steps needed to develop and maintain an ISMS. However, it doesn't include specific language on performing these tasks; you need to use other resources like the NIST SP 800-30 for guidance on how exactly to do them.

READ MORE: Key Differences Between ISO 27001 and 27002

Main Differences Between ISO 27001 and SOC 2

ISO 27001:

An ISO 27001 certification shows that an organization conforms to the standard's framework. A good auditor will check that your system includes all of its requirements and ensure compliance with each one.

  • This certification is well-known and respected around the world.
  • The controls framework is rigid and assumes that an organization will be large from its inception. This can make it difficult, but not impossible, for start-ups to comply with the framework's requirements.
  • Implementation of new procedures and policies can take between nine months to three years.
  • Some customers may accept a self-audit as a substitute for certification.
  • You will receive one page of confirmation from the auditor, outlining their findings and conclusions.
  • ISO 27001 certifications last up to 3 years. Organizations must perform recurring compliance activities such as internal and yearly surveillance audits to retain their certification.

SOC 2:

A SOC 2 is an attestation report on how well your organization has implemented various security, confidentiality, availability, and privacy standards. A SOC 2 report is well-respected in the United States and increasingly respected throughout Europe.

  • You can test any controls you want—a flexibility that makes it suitable for organizations just starting with security.
  • It also includes non-security measures that help make your customers feel safe.
  • SOC 2 reports are typically completed within 45 days.
  • Security is one area the audit covers; it also examines corporate governance and vendor management. The report may include sections on confidentiality, availability processing integrity, and privacy.
  • Your SOC 2 auditor will test the design of your system and, in addition, whether or not controls are operating effectively.
  • After the audit, you will receive a detailed report from the auditor that demonstrates your customers' data is secure.

How SOC 2 and ISO 27001 are similar

SOC 2 and ISO 27001 are similar in that they provide a framework to help organizations establish and maintain an ISMS.

Similarities:

  • Both are auditing standards requiring an independent third-party audit to ensure your products or services conform to a set of standards preventing providers from falsely claiming compliance with a given standard when they have not met that standard's requirements.
  • Both offer guidance on how to create and implement an Information Security Management System (ISMS).

Which Is Best Suited for Your ISMS Needs?

The difference between SOC 2 and ISO 27001 is that neither one is a one-size-fits-all proposition.

The two standards differ in their scope, focus, and compliance requirements. While both measures are designed to safeguard confidential data, they have different approaches that make them more or less suitable for various organizations.

Industries that benefit from ISO 27001 Certification:

ISO 27001 certification is used in:

  • Information technology
  • Finance
  • Telecommunications
  • Healthcare


READ: Ready to get your ISO 27001 certification? Get a quote today.

Industries that benefit from SOC 2 audits:

For any organization, regardless of size or income, this route is typically faster than ISO 27001 certification and just as respected.

Industries that benefit from SOC 2 audits are:

  • Technology
  • SaaS
  • Healthcare
  • Financial, banking, and crypto
  • Education

A risk advisory CPA can help you determine which standard best suits your ISMS needs. They will evaluate your company profile and security measures before recommending a SOC 2 audit or ISO 27001 certification.

READ MORE:    Are you sure you're ready for a SOC 2 audit? Here's a SOC 2 Pre-Audit Checklist to help you prepare.

SOC 2 and ISO 27001 are similar in that they provide a framework to help organizations establish and maintain an ISMS. However, some key differences between the two may make one more suited for your organization.

If you need help determining which one is right for you or more information on how they compare, contact Johanson Group, LLC. today!

At the end of the day, SOC 2 and ISO 27001 are similar in that they both provide a framework to help organizations establish and maintain an ISMS. However, there are some key differences between the two that may make one more suited for your organization. If you’re not sure which one is right for you or need more information on how they compare, contact our experts today!

May 2, 2023

3 Essential Steps for Choosing the Right SOC 2 Risk Advisory Professional for Your Compliance Needs

3 Essential Steps for Choosing the Right SOC 2 Risk Advisory Professional for Your Compliance Needs

SOC 2

Conducting a SOC 2 audit can be intricate and difficult, which is why numerous organizations seek help from SOC 2 risk assessment providers to navigate the process.

However, it's important to choose the right provider to ensure that your audit is successful and meets your organization's specific needs.

In this article, we will outline three key steps your organization should follow when hiring a SOC 2 risk advisory provider for SOC 2 compliance audit.

  • Step 1: Understand the scope of your SOC 2 audit
  • Step 2: Align your PSCRs with relevant TSC
  • Step 3: Research and compare potential SOC 2 audit risk assessment providers based on specific qualifications

Step 1: Understand the Scope of Your SOC 2 Audit

Defining the scope of your SOC 2 audit is a critical first step for businesses navigating SOC 2 compliance and risk assessments.

Here's how:

Identify regulatory requirements, risk factors, and compliance standards specific to your industry

It is essential to conduct thorough research into the regulatory requirements and industry-specific compliance standards that apply to your organization.

This can involve consulting with industry associations or regulatory bodies and reviewing relevant legal and regulatory documents.

In addition to understanding the regulatory requirements and compliance standards, it is also critical to identify and assess the specific risk factors that may impact your business.

This can include factors such as the type of data your organization collects and stores, the security measures you have in place, and the vendors or third-party providers you work with.

Identify the specific services or systems in scope for your SOC 2 audit

Defining the scope of the audit, including the systems, applications, and data flows, can also assist in selecting the appropriate SOC 2 risk advisory professional.

For example, suppose your organization provides cloud-based accounting services to clients. In that case, you would need to identify the specific systems and services in scope for the SOC 2 audit. This might include your cloud infrastructure, software applications, and data storage systems.

Another example might be a healthcare organization that provides medical record storage and management services. In this case, the scope of the SOC 2 audit would include the specific systems and services that manage and store patient health information. This might include electronic health record (EHR) systems, data storage systems, and other applications for managing patient health information.

*It is important to note that not all systems and services within your organization will be in scope for the SOC 2 audit.

HIPPA Compliance Audit & Attestation Services? Learn more.

Evaluate the risks and prioritize controls

By prioritizing controls based on the level of risk, organizations can ensure that they are adequately prepared for the SOC 2 audit and demonstrate their commitment to maintaining strong data security practices. This can help to build trust with customers and partners and provide a competitive advantage in the marketplace.

One example of this process in action might be for an organization that processes credit card payments. In this case, the organization would need to evaluate the potential risks associated with storing and transmitting credit card data and prioritize controls to mitigate those risks. For example, the organization might prioritize implementing strong encryption protocols, multi-factor authentication, and access controls to protect against unauthorized access to credit card data.

Another example might be a cloud-based software company that provides customer relationship management (CRM) services. In this case, the organization would need to evaluate the risks associated with the storage and management of customer data and prioritize controls to mitigate those risks. For example, the organization might prioritize implementing strict access controls, data encryption, and regular security audits to ensure that customer data is protected.

READ More: Why SOC 2 auditing is essential for SaaS businesses

In both of these examples, the organization would need to prioritize controls based on the risk associated with the systems and services in scope for the audit. This might involve conducting a risk assessment to identify potential vulnerabilities, evaluating the effectiveness of existing controls, and developing a plan to address any identified gaps.

Once you've determined the scope of your SOC 2 assessment, move on to Step 2: aligning your PSCRs with relevant TSC.

2. Align Your PSCRs with Relevant TSC

As businesses navigate SOC 2 compliance and risk assessments, it is critical to review customer commitments outlined in Privacy and Security Control Requirements (PSCRs) to identify the precise controls relevant to the services or systems provided and align those requirements with SOC 2 compliance requirements, like the Trust Services Criteria (TSC).

Review your customer commitments and know what they expect from you—and what you've promised

This involves thoroughly reviewing contracts, service level agreements (SLAs), and other documents that outline the specific security and privacy requirements your organization has committed to providing.

By aligning with these requirements, organizations can demonstrate their commitment to maintaining strong data security practices and building customer trust.

Ensure that your audit aligns with the specific requirements of SOC 2 compliance, including the Trust Services Criteria (TSC)

The TSC outlines the specific criteria that organizations must meet to demonstrate their adherence to the principles of security, availability, processing integrity, confidentiality, and privacy.

By aligning with the TSC, organizations can ensure that they are adequately prepared for the SOC 2 audit and can effectively demonstrate their commitment to maintaining strong data security practices.

Now that you've reviewed your customer commitments and the specific requirements for your organization, you may be ready to start the process of finding a SOC 2 risk advisory professional to complete your SOC 2 audit and provide a certificate of compliance.

However, finding the right auditor is not as simple as just conducting a quick search for a local SOC 2 auditor.

It's important to conduct thorough research to ensure that you find an auditor who is a good fit for your organization and who has the expertise required to conduct a successful SOC 2 audit.

In the following section, we will discuss some key factors when selecting a SOC 2 risk advisory professional.

READ MORE: SOC 2 Controls: What they are and how they help you stay compliant

3. Research and compare potential SOC 2 audit risk assessment providers based on specific qualifications

When choosing a third-party SOC 2 risk assessment audit provider, making an informed decision is important.

You don't want to pick a provider out of a hat without first understanding who you're hiring and whether they suit your company's needs.

When investigating a company, pay close attention to these factors:

  1. Experience:

Look for a provider with experience in your industry and the specific services or systems in scope for your SOC 2 audit. They should also have experience with the type of SOC 2 report you need, whether a Type I or Type II report.

  1. Expertise:

Choose a provider with expertise in the specific controls that are in scope for your SOC 2 audit. They should be able to evaluate those controls thoroughly and provide recommendations for improvement if necessary.

  1. Quality of work:

Look for a provider with high-quality work and a good track record of delivering accurate and comprehensive reports. Check their references and read reviews from other clients to understand their reputation.

  1. Cost:

While cost shouldn't be the only factor you consider, choose a provider that fits your budget. Compare prices from different providers and ensure you get a fair price for their services.

  1. Communication:

Choose a provider that communicates well and is responsive to your needs. They should be able to answer your questions and provide regular updates on the progress of the audit.

By considering these factors when choosing a third-party SOC 2 risk assessment audit provider, you can make an informed decision and select a provider that is right for your company's needs.

Compare SOC 2 Risk Assessment Providers

Once you've identified potential SOC 2 risk assessment providers, compare them based on their:

  • Pricing and billing practices
  • Customer support and responsiveness
  • Approach to risk management and Mitigation
  • Ability to offer customized solutions
  • Reviews or testimonials

Evaluating these factors will help you choose a provider that meets your unique business needs and goals.

Finalize Your Selection

After comparing SOC 2 risk assessment providers, finalize your selection by scheduling consultations with the shortlisted providers.

During these consultations, evaluate the provider's communication skills and rapport, review their service level agreements (SLAs) and contracts, and decide based on the provider's fit for your business needs.

READ MORE: 7 things to look for in a SOC 2 auditor

Conclusion

Choosing the right SOC 2 risk assessment provider ensures a successful SOC 2 audit and compliance. Following the steps outlined in this article, you can make an informed decision and select a provider that aligns with your business needs and goals.

Remember: take your time, research, and ask questions to ensure a smooth and stress-free SOC 2 risk assessment process.

Johanson Group: Your SOC 2 risk assessment provider

Our team of experts can guide you through the entire compliance and attestation process. Ensure you select the right provider to meet your business needs and goals with Johanson Group LLP.

Contact us today to see if we're the right fit for your SOC 2 compliance needs.

Feb 14, 2024

SOC for Cybersecurity vs. SOC 2: What’s the Difference?

SOC for Cybersecurity vs. SOC 2: What’s the Difference?

Cybersecurity & IT
SOC 2

Cybersecurity breaches are an ever-present threat to organizations of all sizes. A Clark School study at the University of Maryland is one of the first to quantify the near-constant rate of hacker attacks of computers with Internet access— every 39 seconds on average, affecting one in three Americans every year.

In response to this growing concern, the American Institute of Certified Public Accountants (AICPA) has developed SOC (Service Organization Control) reports to assist organizations in achieving compliance and securing sensitive data. Two common types of SOC reports are SOC 1 and SOC 2, each serving distinct purposes within the realm of cybersecurity and compliance.

The Relationship Between SOC for Cybersecurity and SOC 2

While both SOC for Cybersecurity and SOC 2 are geared towards enhancing cybersecurity practices within organizations, they serve different purposes and cater to different audiences. SOC for Cybersecurity focuses specifically on an organization's cybersecurity risk management program, providing stakeholders with assurance regarding the effectiveness of these measures.

On the other hand, SOC 2 evaluates the design and effectiveness of controls relevant to security, availability, processing integrity, confidentiality, and privacy, with a broader scope encompassing overall service delivery.

READ MORE:  The 5 Benefits of SOC 2 Reporting for Your Organization

Differences Between SOC for Cybersecurity and SOC 2

Scope: SOC for Cybersecurity assesses an organization's cybersecurity risk management program, including policies, procedures, and controls related to cybersecurity. SOC 2, however, evaluates controls relevant to security, availability, processing integrity, confidentiality, and privacy, with a focus on service delivery.

Control Criteria: SOC for Cybersecurity primarily follows the AICPA's cybersecurity risk management reporting framework, while SOC 2 adheres to predefined criteria based on the Trust Services Criteria (TSC) established by the AICPA.

Audience: SOC for Cybersecurity reports are intended for a broader range of stakeholders, including boards of directors, investors, and business partners, seeking assurance on an organization's cybersecurity posture. SOC 2 reports, on the other hand, are typically requested by customers and stakeholders concerned with data security and privacy in outsourced services.

Third-Party Risks: SOC for Cybersecurity evaluates an organization's ability to manage cybersecurity risks internally, whereas SOC 2 assesses the controls implemented by service organizations to mitigate risks associated with outsourced services.

Sensitive Information: SOC for Cybersecurity focuses on protecting sensitive information related to cybersecurity risks and threats, while SOC 2 evaluates controls related to the security, availability, processing integrity, confidentiality, and privacy of data processed by service organizations.

Check out these resources to help you get started on your SOC 2 audit:

Improve Your Controls with Johanson Group

As organizations strive to enhance their cybersecurity posture and achieve compliance with industry standards, partnering with a trusted advisor like Johanson Group can provide invaluable support. With expertise in SOC attestation and cybersecurity risk management, Johanson Group offers comprehensive solutions tailored to your organization's specific needs. From conducting readiness assessments to implementing robust controls, Johanson Group is committed to helping you achieve SOC 2 attestation and bolster your cybersecurity defenses.

While SOC for Cybersecurity and SOC 2 both aim to strengthen cybersecurity practices within organizations, they serve distinct purposes and cater to different stakeholders. Understanding the differences between these two frameworks is essential for organizations seeking to enhance their cybersecurity posture and achieve compliance with industry standards. Partnering with a reputable firm like Johanson Group can streamline the attestation process and provide assurance to stakeholders regarding the effectiveness of your cybersecurity controls.