Compliance is a floor, and teams keep mistaking it for a ceiling
Passing an audit tells you what you documented. It says remarkably little about whether you would survive a competent attacker.
There is a moment in many organisations, usually just after certification, where security stops being a subject of discussion. The audit passed. The controls are documented. The framework says the organisation is secure, and everyone would very much like to believe it.
The difficulty is that compliance frameworks and attackers are optimising against different objectives. A framework asks whether you have a documented, consistently applied control. An attacker asks where the weakest path to something valuable runs. Those questions overlap, but not nearly as much as the certificate implies.
What the gap looks like in practice
A compliant organisation can have quarterly access reviews and still grant standing administrative access to a dozen people who no longer need it, because the review confirms the process ran rather than whether the access was warranted. It can have documented change management and a deployment path that bypasses it for urgent fixes, which is where the interesting changes live. It can encrypt data at rest, as required, while the application queries it in full without constraint.
None of that is a failure of the framework. Frameworks are designed as a common baseline across wildly different organisations, and a baseline is exactly what they deliver.
Questions the audit will not ask
- If an attacker obtained one engineer’s credentials today, what could they reach, and how quickly would anyone notice?
- Which single account, if compromised, would be worst — and does anyone actually need that level of standing access?
- What have we deliberately accepted as risk, and is that decision still current, or was it made in 2021 by someone who has left?
- When did we last test detection rather than prevention? Most organisations discover during an incident that they had the log and no alert.
- How long would recovery take from backups, verified by an actual restore rather than a documented procedure?
Using compliance well
The productive posture is neither dismissal nor comfort. Frameworks provide a genuinely useful vocabulary, an annual forcing function, and executive attention that security teams otherwise struggle to obtain. That attention is worth a great deal.
The mistake is spending all of it on the certificate. The better use of an audit cycle is to satisfy the requirement efficiently and then apply the remaining time and credibility to the threats specific to your business — which no framework has ever seen and no auditor will ever ask about.
Let's build the system your business will run on next.
Tell us where it hurts. We'll bring the architects, engineers, and delivery model to fix it — and scale it.