Bonum Certa Men Certa

The ISO Delusion: How Sirius Picked Collaboration/Communication Tools That Harm Staff, Harm the Company, and Harm Its Clients

International Organization for Standardization (ISO) brag



Summary: Sirius 'Open Source' has long misused "ISO" to do all sorts of dubious things, including cover-up and frustration of staff; the time has come to explain what happened and maybe eventually report the matter to ISO itself

THOSE who have followed this series carefully enough know that pretty much all the communication tools of Sirius 'Open Source' had been outsourced to proprietary vendors (voice, text etc.) without bothering to ask staff, which complained only after the fact. Too late. It's a decree, not a proposal. Instead of self-hosting Asterisk and relying on Jabber (among other things) the company was sending its workflow to Google, Zoom, Slack (Salesforce) and even Skype (Microsoft) while publicly floating ISO logos.



Over the coming week or so we'll show this ugly façade of a company that still uses the term "Open Source" -- a thing that it is rejecting internally. It's not about doing what clients require; this is about what the company chooses for itself, as it's headed by managers who neither use nor support Open Source. It's a façade.

"It's not about doing what clients require; this is about what the company chooses for itself, as it's headed by managers who neither use nor support Open Source."The Office Manager will be a recurring theme here, as she was part of this façade. What is an Office Manager anyway when the company does not have an actual office? David Graeber's thesis would classify it as a 'bullshit job' [1, 2], probably the "box tickers" kind. To quote Wikipedia, we deal here with "box tickers, who create the appearance that something useful is being done when it is not, e.g., survey administrators, in-house magazine journalists, corporate compliance officers, quality service managers..."

As noted here right from the start (a day after resignation), the company was hardly compliant with anything sensible, including security and ethics. Last year I was asked to study logs for some anti-abortion group (without telling me where those logs had come from). What next? Would I be getting assigned jobs like checking logs for Oath Keepers or Proud Boys, seeing that anti-abortion groups were starting paying for "services" last year? (Off the record)

Anyway, yesterday this good article mentioned LastPass, another company that the stubborn new management decided to hand over to not only our own passwords but clients' too (even private keys!!!), insisting that according to LastPass the LastPass breach wasn't a big deal. Sirius did not even bother resetting passwords after I had repeatedly urged for this to be done (and, as a possible bonus, to dump LastPass altogether). In yesterday's article the author says: "I’d like to talk about some of my experiences with this topic, as well as recent events in the security community."

"Before I describe my experience," he says, "I need to set the stage. My LastPass fun took place around the same time as the infamous Bugcrowd incident with JSBN."

Watch how LastPass handled things: "My first step in esclating was security.txt. No dice. There was no clear security officer or contact information that I could discern from my social network either, so I chose the path of last resort: I contacted their support team."

"Hiring friends and relatives instead of qualified people leads to disaster."So it's more or less like Sirius. No wonder a client said the company was "incompetent". The client said this to a highly incompetent 'manager' who was never supposed to be there in the first place: No clue about technology or about management, just some associate from a former organisation in which a Sirius 'founder' had spent a few years. Hiring friends and relatives instead of qualified people leads to disaster.

Very basic security practices were often disregarded and staff was ignored in spite of technical background. It was like talking to the wall.

At first we had Asterisk internally; then someone decided it would be better to use some outside firm as a supplier and pay the fees. That was still a lot better than a move to a defective "service" and then purchase "phones" that are a security threat, in the hope (likely false hope) that it would 'fix' the issue. We'll come to that another day.

The management kept covering up for repeated failure/s, blaming the staff (victims) instead, never the decision-makers who introduced a faulty/defective alternative but are too vain to admit it, take the blame, and finally undo.

"The management kept covering up for repeated failure/s, blaming the staff (victims) instead, never the decision-makers who introduced a faulty/defective alternative but are too vain to admit it, take the blame, and finally undo."The company's obscene disregard for security would not end there. We've already covered cognition reports being stored on personal machines, then uploaded to AWS (not the client's servers). There was no longer any security protocol in place; no file server for them or for us (GDPR would be screaming!), set aside the fact that the company is no longer "open source" and is basically lying about it. It's more like bragging about ISO while gaslighting people who actually value security.

Not only did the company ignore the warnings from me, it didn't even change passwords, alter providers, or self-host an actual "Open Source" alternative. It kept saying it would (or merely consider this), but those were lies. As we mentioned here before, this wasn't a matter of practicality of cost-savings either; Sirius was getting huge bills for "clown computing" (idle almost all the time but the bills kept growing and growing). Any suggestion of self-hosting, i.e. like before, was dismissed as "hobbyist" by the CEO. So what is to be sold as a service by Sirius? Outsourcing? Well, the company's latest incarnation in LinkedIn does say that.

Tomorrow we'll show some examples of misuse of the company's pretences (ISO, GDPR etc.) for cover-up, censorship etc.

In the meantime, however, consider this E-mail from July 2019 (when the company was setting up a shell in the US, covertly, when signing an NDA with the Gates Foundation):

xxxx wrote on 17/07/2019 17:20: > Hello Roy, > > As you are aware we’re currently going through the process of > implementing ISO 27001 (information security management system). It's > been brought to our attention that you using xxxxx Slack is > unacceptable due to the security of password sharing amongst yourselves. > > During your meeting at the training workshop - I had asked for you to > reconsider as this is a company requirement. > > Moving forward and with the advice from the ISO company this is now > something which needs to be completed by the end of your shift this > evening. Slack is an essential communication tool used by everyone > within the company. > > Would you please confirm the receipt of this email and a reply to this > request.

Hi,

Currently, all our sensitive communications end up on the server of a large corporation in another country, where this data can get sold. It included NHS stuff. This too is a problem as we need to be Open Source not only in name and I've been waiting for xxxxx to set up Matrix or similar for me to join. It has been months and I think it's essential for our company to demonstrate it takes security seriously. I can set up an Open Source alternative myself if that helps.

Regards,


Of course I only received more threats for this, rather than be listened to. Of course "information security" and Slack are incompatible concepts. As we shall revisit shortly, let's just say Slack suffered yet another data breach shortly thereafter, vindicating me. Did the management listen? Did it react? Of course not.

After some more threats I was compelled to give up, at least temporarily:

xxxx wrote: > Hello Roy, > > As I have expressed in my previous email and in all communication that > Slack is an essential communication tool used by everyone within the > company at the moment. We all should be there. > > This is a direct management requirement and instruction and it needs to > be implemented immediately.

I have just created the Slack account.

It would still be useful to know the timeline for moving to an Open Source alternatives. Slack has no business model other than spying at the moment, as media repeatedly points out.

Regards,


Regarding "I've been waiting for xxxxx to set up Matrix or similar for me to join," I was receiving false promises from the CEO, naming two people who would set up a Free software alternative like Riot/Mattermost. One of them left the company (as I had previously warned the manager) and another never implemented the change. Sirius management was just lying all along.

"Now, after so many years, Sirius is another disgrace or a black eye to ISO."We'll revisit Slack another day and we shall deal with each of these blunders in turn. ISO is a joke if it grants certification to companies which behave in this way, set aside how superficial the requirements are. 15 years ago Microsoft bribed a lot of firms and organisations to rig ISO; and ISO, in turn, was OK with it. Now, after so many years, Sirius is another disgrace or a black eye to ISO. No wonder clients suffered security breaches. They weren't even informed of how poorly Sirius had handled/managed security. ⬆

Recent Techrights' Posts

European Patent Office (EPO) Series: A Costa-Benefit Analysis: Has the Asset Become a Liability?
All other things being equal, one could expect the Portuguese political establishment to support Campinos in his reappointment bid. But what if all other things are no longer equal because the former "asset" has in the meantime become a "liability"?
Brigading Against Women - Part XIV - Mastery of Distraction
The finger-pointing actions themselves prove the saying that even an accusation is likely a confession
 
Gemini Links 02/10/2026: Hitchhiking, Dream, Journey of Thoughts, and ROOPHLOCH
Links for the day
IBM in Such a Bad Shape That Silent Layoffs Have Come to India
Make it hard for IBM to hide what's happening
The Mass Layoffs at Red Hat (Secret Layoffs) Not Limited to This Week or to October 1st
Red Hat can shed off 10% of its staff without anyone in the media uttering a word
The Latest "PARTNER CONTENT" at The Register MS is by Chief Marketing Officer at VergeIO
Maybe The Register MS can just run ads, not articles, and hope nobody will notice
Links 02/10/2026: Turkey's Censorship of Journalists Grows, "Hong Kong Journalist Arrested After Covering Gathering Linked to 2019 Protests"
Links for the day
IBM's Red Hat is a Slave of Microsoft, It Does Not Compete With Microsoft
As released and shown earlier today in "Red Hat Partner Connect"/redhat.com
Red Hat: Stop Saying Master, It's Racist. Today's Red Hat: "Master Your Skills" and Adopt Slop Plagiarism
IBM is shredding Red Hat to pieces while it keeps humiliating the collective intelligence of communities
Reform UK, Nigel Farage's party/company, admits missing winding-up petition
Reprinted with permission from Daniel Pocock
Links 02/10/2026: "McDonald's Caught Cheating Consumers for Profit" and "It's Not Illegal If You Buy New Laws"
Links for the day
EPO "Cocaine Communication Manager" - Part XVII - A Vote for Campinos This Month (Reappointment) Would be an Endorsement of Cocaine
The harder they try to silence critics, the worse it'll get
The Cyber Show on "Career Scientists" (Resellers of Establishment Brands Like GAFAM)
"The "career scientist" - with PhD and research office by their mid-twenties - follows well oiled tracks and institutional signposts, steering away from controversial or "difficult" subjects."
Reporting Court Matters While Preserving Dignity of Staff
There's a high and growing probability we'll take our appeal to the Court of Appeal next year
Broligarchs Speech-Policing, Faux 'Community' or 'Hub' in 'User-Driven' Clothing
Until a broligarch decides to "flag" inconvenient stories
Gemini Links 02/10/2026: Haiku, Microsoft EEE ('Linux' as a Container in Windows), and ROOPHLOCH 2026 Roundup
Links for the day
Microsoft Promised Them Bonuses, Instead They May Get Laid Off
Laid off or paid off?
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, October 01, 2026
IRC logs for Thursday, October 01, 2026
Lots of People Left Red Hat This Week, No Announcement Made of Layoffs
Companies just find ways and excuses not to announce their layoffs
Gemini Links 01/10/2026: Gemini-to-Web Proxies Considered Harmful, ROOPHLOCH 2026 at Griffith Park Observatory
Links for the day
"SPONSORED FEATURE" of HPE and NVIDIA at The Register MS Has Just Mentioned "AI" 68 Times in One Page!
Meanwhile, grown-ups ignore the hype and get work done without slop
Microsoft's XBox Layoffs Not Finished, Won't be Finished, It's Called "Forever Layoffs"
Microsoft will shut down (XBox) after shrinking it, there's no need to sell anything (a straw man)
IBM's Red Hat Lost Lots of People Today, Chief People Officer (CPO) Dethroned
Headcount falls shortly in secret.
Microsoft is "Pushing Up Daisies" Amid Mass Layoffs (Secret Ones)
"Longtime Microsoft research leader Peter Lee and former LinkedIn CEO Ryan Roslansky to depart"
Links 01/10/2026: "Lawyer Cites ChatGPT-Invented Fake Witnesses in Murder Appeal" and The 'Linux' Foundation Technical Advisory Board (TAB) Has Vacuum
Links for the day
Brigading Against Women - Part XIII - The Offer We Didn't Ask For (and Under Threats to a Lady at the Webhost, a Form of Extortion From America)
Two and a half months ago Garrett made an offer to my wife
Creditors beware: VMS Enterprises Ltd vs Brexit Party (Reform UK Party Ltd)
Reprinted with permission from Daniel Pocock
Techrights Turning 20 Next Month
Our image is under attack, our finances are constantly under attack and so on
Links 01/10/2026: "Meat Proxies" and "Japan’s Far Right Is Courting Young Voters"
Links for the day
Red Hat Being Phased Out of Existence (Like Many Other Companies That IBM Bought)
The "Red Hat" brand (and badge) is being dissolved some more today [...] IBM is imploding 'creatively'.
IBM Layoffs Cover-up
thelayoff.com is censoring threads
"Restricted Boot" Garrett's State is Now Implementing Kill Switches (Just What We've Warned About All Along)
The underlying concept is hardly new
Brett Wilson LLP Has Had No Annual Report in 16 Months
A cynic might hint that they try to hide something
Reform UK last minute accounts filing
Reprinted with permission from Daniel Pocock
Gemini Links 01/10/2026: "Babel With Better Hardware", Software Input That's Slop, and DWeb Cascadia 2026
Links for the day
Today is D-Day at Red Hat and People Leave in Droves
They said there would be "bluewashing", we're mostly seeing people announcing they're leaving
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, September 30, 2026
IRC logs for Wednesday, September 30, 2026
Gemini Links 30/09/2026: Fish Leather, Slop Formation, and ROOPHLOCH
Links for the day
In a Lot of Europe (or EU) Android (With Linux) is Bigger Than Windows
For example in Greece
Slop-Posting is a New Form of S---posting
We recently caught several more "linux" sites (with "linux" in their domain name) turning to slop
EPO Cocainegate: Lots of Money (Over a Million Euros) for Cocaine Addicts, Not for Children With Special Needs
Next month we'll bring out some more Campinos scandals
High Court victory: Nigel Farage is 'the Company's own candidate'
Reprinted with permission from Daniel Pocock
It Took GNOME's Code of Conduct Committee (CoCC) Over 8 Months to Realise CoC Reports Went Into /dev/null/
It would be ironic if the blunder's culprits were punished for it, would it not?
Links 30/09/2026: Microsoft "OpenAI Ignored Employees’ Warnings About Safely" and "Pentagon Personnel Agency Data Breach Impacts 3 Million People"
Links for the day
The Register MS "Events" As Paid Spam That Promotes and Keeps Afloat Hype About Slop
This dreary sort of media reads like a soup of words, i.e. like the thing it is advertising
Digital Independence in the UK and in Western Europe
We have the technical capacity and skilled personnel to achieve this
IBM's Anderon as a Mass Layoffs Ritual With a Bailout (From US Taxpayers to IBM) and Other Perks
Like those empty promises in the first term of the Cheeto dictator
Gemini Links 30/09/2026: David Bowie, Web Rendering Proxy, Ink and Letters, Gemlog Nostalgia
Links for the day
EPO Annual General Meeting (AGM) Will Speak of Financial State of the EPO's Union
Their work is needed because the EPO breaks the law
Rust Causes Upgrade Issues in Ubuntu
They could just keep GNU coreutils in place (nothing was broken about it) and avoid Microsoft's back doors and TPMs
Losses From Slop Are "Investment", Hundreds of Billions in Debt Are "Growth Opportunity", Layoffs Are "Great to See", and Loss of Business Means "We Need a Slowdown" (for "Safety")
Microsoft is removing staff, as investment is apparently the act of shrtinking
Brigading Against Women - Part XII - Toxic Masculinity, Hunting Women, Will Code for Sex
Who says things like these?
The Microsoft Lunduke Slop Problem
Microsoft Lunduke does not support Software Freedom; he serves to discredit many ideas championed by Free software or ideals articulated which are apolitical for the most part
Links 30/09/2026: "Understanding the LLM Bubble" and "Florida Senate Threatened Legal Action Against Newspapers"
Links for the day
It Looks Like Mass Layoffs at "Nordcloud, an IBM Company" Today (a Day Ahead of Red Hat)
Expect the same from Red Hat next
British Prime Minister Recognises Social Control Media as National Cohesion Problem
one has to wonder if addiction to social control media is not compatible with peace
The Future Isn't Social Control Media (Nothing Will be Left of It, Not Even Archives)
"Error code: 502 Bad Gateway"
GNU/Linux Usage in China is Increasing
China is leaving Microsoft and Windows behind
43 Years of GNU and GAFAM's (Especially Microsoft's) Attacks On It
GNU is very widely used (when people say "Linux commands" they typically mean "GNU programs"), hence it's being attacked a lot
CDMAG Covers Free Software, New Magazine From Decent People
If enough people accessed their site, they would not rely on social control media (third parties, censorship platforms)
Brigading Against Women - Part XI - An Abject Lack of Social Skills (and Not Knowing How to Handle Women)
GGG enjoy - if that's the right term - very bizarre or esoteric sex life
Gemini Links 30/09/2026: Accelerationism, "The Billionaire is Wrong", Rant About LLM-generated Support E-mails
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, September 29, 2026
IRC logs for Tuesday, September 29, 2026