LexisNexis pulled products offline over a third-party vendor incident
August 11, 2026. From issue 1 of The Compliance Brief, 2 stories for Canadian companies answering customer security reviews.
Issue 1 of The Compliance Brief went to subscribers on August 11, 2026. 2 of its 5 stories bear on security reviews, vendor diligence and trust, and they are below in short form. The full issue, with every take in full, is on traztech.ca.
Free weekly email
Get the next issue on Tuesday
One email a week: what changed in security and compliance, and what it means for Canadian companies answering customer security reviews.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.
Source: BleepingComputer
LexisNexis took several services offline, including Diligence and the Metabase API, in response to unusual activity on servers hosted and managed by a third-party vendor it has not named. The company treated the shutdown as part of its incident response.
Our take, in short
Taking the service down was the right call, and it is also the version of vendor risk that most SaaS companies have never modelled. Your subprocessor list probably names the screening or data provider, and almost certainly says nothing about who runs their infrastructure, so an outage two layers out becomes your degraded onboarding flow and your customer notification.
Read the full take on traztech.ca
New York fined a money transmitter for a weak program, not a breach
Source: DataBreaches.net
The New York Department of Financial Services announced that Order Express, a licensed money transmitter, will pay a $250,000 penalty for violations of the DFS cybersecurity regulation, 23 NYCRR Part 500. DFS investigators identified deficiencies in the company's cybersecurity program.
Our take, in short
For fintech readers this is the enforcement pattern that matters most, because the penalty attached to program gaps rather than to a headline incident. When your customer is covered by Part 500, its obligations arrive on your desk as contract language about access controls, risk assessments and notification windows, and their examiners are the reason they will not negotiate on...
Read the full take on traztech.ca
Related on TrustCenter
- Trust center versus a security page
- Trust centers for fintech suppliers
- A trust center before your first report
- Data residency statements for Canada
Also in issue 1
Outside security reviews, vendor diligence and trust, but in the same email:
- The Snowflake extortion case ends with a guilty plea in Kitchener
- Gunra ransomware is getting in through firewalls, per a joint advisory
- Hidden prompt injection is showing up in "Ask AI" buttons on marketing pages
All issues on TrustCenter Newer: issue 3
Free weekly email
Get it every Tuesday
The next issue goes out Tuesday morning. Read it in your inbox instead of finding it here a week later.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.