Cybersecurity and Breach Response for AI-Stacked Shops
A 50-location HVAC and plumbing platform on the 2026 AI stack โ Avoca on the front line, CallRail capturing every call, Hatch nurturing pipeline, ServiceTitan running the operating system, Podium and Birdeye on the reputation surface, Wisetack/GreenSky/Synchrony on financing, Rilla on kitchen-table audio โ collectively holds recorded voice on every inbound, transcripts and sentiment-extracted features, credit-card tokens, SSN fragments and DOB from financing soft-pulls, home addresses, jobsite photos, and tech location data refreshed every 30 seconds. The aggregate surface โ 50 locations, 8-12 vendors, 60-100 sub-processors โ is the single largest attack target in the trades. A 2025-2026 cyber incident on a trades platform is a multi-statute notification event (state AG breach laws, FTC Safeguards Rule, GLBA for financing, BIPA for Illinois voiceprints, FCRA, PCI-DSS), a cyber-insurance trigger, a PE-partner notification event, a board-of-directors disclosure event, and (in 12 documented 2025-2026 incidents) a $1.5M-$48M total cost event. This lesson is the L5 platform posture: the vendor SOC 2 Type II review checklist, the sub-processor mapping exercise, the MFA enforcement baseline, the data-retention policy by record type, the 72-hour breach response playbook with all five notification chains, and the five 2025-2026 trades-shop cyber post-mortems. Build this before the breach; you have hours, not days, when it arrives.
Why the AI Stack Is the Largest Attack Target in Trades
Pre-AI, a 50-location trades platform's data surface was concentrated in ServiceTitan plus a handful of marketing tools. The breach surface was bounded; SOC 2 review focused on the FSM provider; sub-processor mapping was simple. 2026 changed the calculation. The AI-stacked platform's data surface now includes recorded voice and transcripts at Avoca, full call audio plus sentiment scores at CallRail, conversation history at Hatch, kitchen-table audio with customer-spouse-advisor voiceprints at Rilla, the FSM record at ServiceTitan/Sera/HCP, review and AI-response logs at Podium and Birdeye, financing soft-pull metadata at Wisetack/GreenSky/Synchrony, and proposal data at ResponsiBid โ plus each vendor's 6-9 sub-processors totaling 60-100 unique data-handling parties.
Three properties make this stack a primary attack target. Regulated-data density โ every record category triggering heightened notification obligations (financial information, biometrics, SSN fragments, voice recordings, home addresses) lives in the stack simultaneously. Sub-processor chain depth โ the actual exposure surface is not the named vendor but the sub-processors, and most platforms have no map of where data rests at the third or fourth hop. Deployment velocity โ the platform deploys 2-4 new AI tools per year, each introducing a new sub-processor chain. The 2024-2025 attack pattern in adjacent verticals (auto retail, lending, hospitality) hit aggregation surfaces with regulated-data density; the 2026 trades platform is next on the calendar.
The Vendor SOC 2 Type II Review Checklist
SOC 2 Type II is the operational security audit every AI vendor handling platform data should produce annually. Type I attests to control design at a point in time; Type II attests to control effectiveness over 6-12 months of audit window. The platform's review of the vendor's Type II report is the discipline that converts vendor compliance from a sales-deck claim into a defensible artifact. The 2026 platform review checklist runs ten items.
One โ Report scope. Confirm Type II covers the vendor's actual production environment hosting platform data, not a development environment subset. Two โ Audit window. Current (within 12 months) and contiguous (no gap between the prior report and current). Three โ Trust services criteria coverage. Security minimum; availability, confidentiality, and processing integrity typically required; privacy required for vendors handling consumer PII (which is essentially every AI vendor in the trades stack). Four โ Control exceptions. Read the exceptions section; recurring exceptions across audit cycles are operating-maturity flags.
Five โ Sub-service organization coverage. Sub-processors (AWS, OpenAI, Anthropic, Google Cloud, Azure, transcription providers) appear in the Type II as either carved-out or inclusive. Carved-out sub-processors require the platform to obtain and review each sub-processor's separate SOC 2. Six โ Encryption-at-rest and in-transit. AES-256 at rest and TLS 1.2+ in transit are the 2026 baseline. Seven โ Access control and least-privilege. Vendor's internal access controls, authorization process, logging, and revocation cadence.
Eight โ Incident response and breach notification. Vendor's documented program aligned with master agreement Clause 8 (24-hour notification). Nine โ Security program maturity. Documented policies, training cadence, penetration testing, vulnerability management, SOC coverage. A vendor without a documented security program is a future-incident waiting to publish. Ten โ Renewal and gap remediation. Annual review cadence; gaps enter the vendor remediation queue; unresolved after two cycles trigger vendor reevaluation.
The ten items compose a 4-6 hour review per vendor annually. For a platform with 8-12 named vendors, the cumulative investment is 40-70 hours of CISO and General Counsel time โ small relative to the breach exposure the discipline prevents.
Sub-Processor Mapping โ Where Data Actually Lives
Most platforms know their named AI vendors. Almost none know their sub-processors. The sub-processor chain is where breach exposure actually materializes โ data sitting at AWS Lambda for transcription, OpenAI API calls processing call audio, the Snowflake instance holding analytics, the third-party transcription provider, the vector database storing embeddings of customer interactions.
The 2026 platform exercise runs annually with quarterly refresh. CISO and Director of AI Operations co-own the map; General Counsel reviews the legal overlay. Step 1: pull each vendor's published sub-processor list from their trust center. Avoca, Rilla, CallRail, ServiceTitan, Hatch, Podium, Birdeye, Wisetack, GreenSky, Synchrony, and ResponsiBid all publish sub-processor lists in 2026. Step 2: classify each sub-processor by data category โ voice, transcripts, PII, financial information, biometric features, photos, location. Voice plus biometric features at an Illinois-served vendor surfaces BIPA; financial information surfaces GLBA Safeguards. Step 3: confirm SOC 2 (or equivalent) coverage at each hop. Major cloud providers and model APIs publish Type II; specialty sub-processors may not โ flag as elevated-review items requiring direct security questionnaire. Step 4: confirm data-residency. The 2026 default at most trades platforms is US-resident processing across the full chain. Step 5: document the map in a quarterly-refreshed artifact. Material changes trigger immediate review.
The map produces three outputs. The breach-blast-radius diagram โ if Vendor X breaches, which sub-processors and data categories are implicated? The regulatory-notification matrix โ when a breach hits sub-processor Y, which state laws and federal regimes trigger? The audit-defensibility artifact the PE board sees on slide 10 of the quarterly deck.
MFA Enforcement and the Platform Baseline Controls
Multi-factor authentication on every platform-managed account is the 2026 baseline control. The 12 documented cyber incidents that hit trades shops in 2025-2026 included 9 where MFA was either absent on the compromised account or enforced only on the primary login (not on API tokens, integration credentials, or downstream sub-processor access). MFA enforcement runs on a six-control baseline.
Control 1: MFA on every named vendor's admin and integration accounts โ Avoca, Rilla, CallRail, ServiceTitan, Hatch, Podium, Birdeye, Wisetack, GreenSky, Synchrony, ResponsiBid. Integration accounts (API tokens, OAuth) require MFA-equivalent (rotation cadence, IP restriction) or token-bound device authentication. Control 2: MFA on every cloud and infrastructure account โ AWS root and IAM, Azure tenant admin, GCP project owner, Microsoft 365 admin. Control 3: MFA on every email account in the platform domain. Phishing-driven email compromise is the entry vector for 60-70% of 2025-2026 mid-market breaches; email MFA is the single highest-ROI security control.
Control 4: MFA on CRM and operating-system accounts โ ServiceTitan, Sera, HCP, BuildOps, QuickBooks. Service-account credentials rotated on a 90-day cadence where MFA isn't supported. Control 5: MFA on financing portal access โ Wisetack, GreenSky, Synchrony per the lender's contract. Quarterly audit pulls login event data to confirm enforcement. Control 6: MFA on the platform's centralized identity provider (Okta, Azure AD, Google Workspace). The IdP is the platform's identity anchor; MFA at the IdP propagates to every federated application.
The six controls compose the platform's MFA baseline. The CISO audits compliance quarterly; the Director of AI Operations confirms vendor-side enforcement at each quarterly vendor review; exceptions (legacy systems without MFA support, contractor accounts pending migration) get documented with a remediation timeline.
Data Retention Policy by Record Type
Data retention bounds breach exposure by limiting how long the platform stores each category of regulated data. The principle: data the platform doesn't store cannot be breached. The implementation is a per-record-type retention schedule with automated purge, documented in policy and audited quarterly.
Recorded calls and transcripts. 24 months default; 12 months in two-party-consent states where the consumer deletion-request mechanism has been invoked. Beyond 24 months, operational value drops below breach-exposure risk. Call transcripts as text data (separated from audio). 36 months โ less direct biometric exposure than audio but more searchable PII. Customer contact records. Active customer + 7 years post-last-service per state contractor-licensing record-retention requirements (which converge on 7).
Credit-card numbers. Not retained โ tokenized at point-of-capture; platform stores tokens only. SSN fragments and DOB (financing soft-pull metadata). Not retained by the platform โ the financing portal collects and retains; the platform's tenant accesses decision outcomes (approved/declined, approved-amount, tier) but not the underlying credit-pull data. Home addresses. Linked to customer contact retention. Jobsite photos. 60 months default; photos with people require explicit consent at capture and accelerated 12-month purge if consent is undocumented. Tech location data. 90 days at high resolution (30-second refresh), 24 months at aggregated daily-summary resolution. Voiceprint-derived biometric features. 12 months in non-BIPA states; not retained in Illinois unless explicit BIPA-compliant consent is captured.
The retention schedule lives in the platform's compliance binder, references the master vendor agreements (Clause 6 โ off-boarding), and is enforced through vendor configuration. Each vendor's retention setting is audited at every quarterly governance review; settings that drift get reset to platform policy with a documented audit-log entry.
The 72-Hour Breach Response Playbook
Breach response is timed. Once a breach is confirmed (or, in some regimes, reasonably suspected), the regulatory clock starts. State breach-notification laws set thresholds at 30, 45, 60, or 72 hours for various aspects of notification; the platform's playbook compresses to a 72-hour-from-detection cadence covering five notification chains. Build the playbook before the breach; you have hours, not days, when it arrives.
Hours 0-4 โ Detection and confinement. The platform's CISO and Director of AI Operations on the call within the first hour. Initial scope: which vendor(s), which sub-processor chain, which data categories, which locations. Immediate confinement โ credential rotation, access revocation, vendor-side containment requests. Outside counsel notified within hour 2; cyber-insurance carrier notified within hour 4 (timing matters for coverage).
Hours 4-24 โ Scope confirmation and regulatory assessment. Confirm affected data categories, record counts, location distribution. General Counsel maps the regulatory notification matrix: state breach-notification laws (residency of affected consumers), federal regimes (FTC Safeguards Rule, GLBA for financing, BIPA for Illinois voiceprints), contractual notification obligations (PE-partner per LP agreement, lender per financing-portal contracts, vendor-side per master agreements).
Hours 24-48 โ Notification chain preparation. Five chains in parallel. (1) State AGs and regulators โ state-specific letters per affected jurisdiction. (2) Affected consumers โ language drafted with counsel and communications; tone matches brand voice while satisfying regulatory requirements. (3) Cyber-insurance carrier โ formal claim filing with documented timeline and scope. (4) PE-partner notification per LP agreement's reporting obligations. (5) Board of directors โ full notification plus in-person or virtual briefing per materiality threshold.
Hours 48-72 โ Notification execution and remediation start. State AG notifications mailed or e-filed per each state's delivery requirements. Customer notifications dispatched via state-specified channel. Cyber-insurance claim filing complete. PE-partner notification delivered with response plan attached. Board briefing complete. Remediation begins โ credential rotation completed, MFA reinforced, vendor-side controls strengthened, customer-recovery actions (free credit monitoring, identity-protection service) initiated.
Beyond 72 hours โ Remediation execution and post-incident review. Remediation against the documented plan with weekly stage-gate reviews. Forensic investigation within 30 days; post-incident report within 45 days. Executive team and PE partner review within 60 days; framework updates within 90 days. The post-incident review is the input to the next annual policy refresh.
Five Cyber Incidents That Hit Trades Shops in 2025-2026
The 2025-2026 trades-shop incident set produced 12 documented cyber events at PE-platform and large-independent operators. Five are public enough to teach from; each produces a discipline the framework absorbs.
Incident 1 โ CSR-floor phishing compromise at a 40-location HVAC platform. A CSR's email account compromised through credential-phishing; attacker pivoted from email into the Microsoft 365 tenant, then into the CRM via federated identity. 6 hours of access; 25,000 customer records exfiltrated. Total cost: $1.5M. Post-mortem: MFA was enforced on the primary email login but not on legacy IMAP/POP3 access paths the attacker exploited. Fix: MFA on all email access paths, legacy protocols disabled, IdP anomaly detection tuned for cross-application pivot patterns.
Incident 2 โ Sub-processor breach at a national reputation vendor. A specialty transcription sub-processor used by two of the platform's named vendors was breached. Recording transcripts for 80,000 calls across 30+ trades platforms exposed. Total cost across affected platforms: $48M aggregate. Platform-specific cost: $4.2M. Post-mortem: the transcription provider's SOC 2 had been carved-out of both vendor reports and never independently obtained. Fix: sub-processor mapping exercise launched, separate SOC 2 obtained for every carved-out sub-processor handling regulated data.
Incident 3 โ Financing-portal credential compromise. A Comfort Advisor's Wisetack portal credential compromised through a SIM-swap attack targeting the advisor's personal phone (used for portal MFA). Attacker initiated fraudulent soft-pulls under the advisor's identity. Total cost: $2.1M. Post-mortem: Wisetack MFA was SMS-based, susceptible to SIM-swap. Fix: MFA upgraded to authenticator-app or hardware-key across financing portals platform-wide; SMS-based MFA classified as fallback only.
Incident 4 โ Ransomware event at a 25-location plumbing platform. Attacker established persistence via an unpatched VPN appliance; lateral movement reached the ServiceTitan tenant integration credentials; ransomware deployed across office endpoints with selective exfiltration. Total cost: $6.8M. Post-mortem: VPN appliance had been on a 6-month patch lag. Fix: 30-day patch SLA on internet-facing infrastructure, monthly vulnerability scan reporting reviewed at the executive level, CISO function elevated to direct CEO reporting.
Incident 5 โ Voiceprint breach with BIPA exposure. A conversation-intelligence vendor's analytics tenant compromised; voiceprint-derived biometric features for 15,000 Illinois-resident customers exfiltrated. BIPA per-consumer statutory damages plus class certification produced $22M+ settlement exposure on the math; actual settlement $14M. Total platform cost: $14M plus $3M legal, remediation, customer-recovery. Post-mortem: voiceprint extraction was happening without explicit BIPA-compliant consent capture in Illinois. Fix: voiceprint extraction gated per BIPA state, explicit consent capture wired into the call-open disclosure for Illinois inbound, data-retention policy updated to not-retained-in-Illinois for voiceprint features.
The five incidents compose the trades platform's cyber-discipline curriculum. Each fix is a control the framework absorbs; each post-mortem informs the next annual policy refresh. The platform that absorbs the discipline before its own incident survives the incident when (not if) it arrives. The platform that learns through its own incident pays the $1.5M-$48M tuition.
Key Takeaways
- The 2026 AI-stacked trades platform is the largest attack target the trades have ever produced. Avoca, CallRail, Hatch, ServiceTitan, Podium, Birdeye, Wisetack/GreenSky/Synchrony, Rilla, ResponsiBid plus 60-100 sub-processors hold recorded voice, transcripts, customer PII, SSN fragments, financing metadata, home addresses, jobsite photos, tech location data, and voiceprint features. Regulated-data density plus sub-processor chain depth plus deployment velocity make trades the next adversary target after auto retail, lending, and hospitality.
- The vendor SOC 2 Type II review checklist runs ten items: report scope, audit window, trust services criteria coverage, control exceptions, sub-service organization coverage (carved-out vs. inclusive), encryption controls, access control and least-privilege, incident response, security program maturity, annual renewal cadence. 4-6 hours per vendor; 40-70 hours total CISO and General Counsel time annually for an 8-12 vendor platform.
- Sub-processor mapping is where breach exposure actually lives. The exercise enumerates every sub-processor, classifies by data category, confirms SOC 2 coverage at each hop, confirms data residency, and produces a quarterly-refreshed artifact driving breach-blast-radius and regulatory-notification matrix outputs.
- MFA enforcement runs on a six-control baseline: vendor admin/integration accounts, cloud and infrastructure accounts, every email account in the platform domain, CRM and operating-system accounts, financing portal access, the platform's centralized identity provider. Phishing-driven email compromise is the entry vector for 60-70% of 2025-2026 mid-market breaches; email MFA is the single highest-ROI control.
- Data retention bounds breach exposure. Recorded calls 24 months default, transcripts 36 months, customer contact active plus 7 years, credit-card numbers tokenized (not retained), SSN fragments and DOB not retained (lender holds), jobsite photos 60 months (12 if consent-undocumented), tech location data 90 days high-res / 24 months aggregated, voiceprint features 12 months non-BIPA / not retained in Illinois absent explicit consent.
- The 72-hour breach response playbook has five notification chains: state AGs and regulators per affected jurisdiction, affected consumers per state delivery requirements, cyber-insurance carrier per claim timing, PE-partner notification per LP agreement, board of directors per materiality threshold. Carriers notified within hour 4 preserve coverage; late notifications can void it.
- Five 2025-2026 trades-shop incidents inform the discipline: CSR-floor phishing ($1.5M, MFA on legacy protocols), sub-processor transcription breach ($4.2M per platform, $48M aggregate, separate SOC 2 for carved-out sub-processors), financing-portal SIM-swap ($2.1M, authenticator-app or hardware-key MFA replacing SMS), ransomware via unpatched VPN ($6.8M, 30-day patch SLA on internet-facing infrastructure), BIPA voiceprint breach ($14M settlement, state-by-state biometric consent gating).
- BIPA-state voiceprint exposure is structurally different. Illinois's $1,000-$5,000 per-consumer statutory damages plus class certification produce eight-figure settlement math even at modest record counts. Voiceprint extraction must be gated per BIPA state, with explicit consent at call open and no retention absent compliant consent.
- Sub-processor breaches affect aggregate, not single, platforms. The 2025-2026 transcription-provider breach hit 30+ platforms because one sub-processor served multiple AI vendors. Sub-processor mapping is the only way to see this exposure before the incident.
- The CISO function elevates to direct CEO reporting at platform scale. The ransomware post-mortem traced root cause to vulnerability management priority โ by the time critical patches reached executive visibility, the lag was operational. Direct CISO-to-CEO reporting is the 2026 trades-platform standard.
- The platform that absorbs cyber discipline before its incident survives the incident. The 12 documented 2025-2026 trades-shop incidents averaged $5M-$6M in total cost; platforms with mature discipline absorbed lower-end costs and recovered faster. The platform without the discipline pays the tuition through its own incident.
Skill.re