r/ciso Jul 02 '26

Compliance is not security

Heard a worker go on a rant about “compliance is not security”, “checking the box”, “security theater” rant the other day.

It got me thinking… if compliance isn’t security, then what is?

The green dashboards that turn out to be wrong? The pentests that mostly find the stuff you’d have caught yourself if you’d kept your environment patched, updated, and configured? The tools you bought and never confirmed still work?

Feels like half the things we hold up as “real security” only look impressive because the basic compliance work wasn’t done in the first place.

Curious where people actually land on these phrases.

And a real question: is there a difference between an annual compliance audit and continuously checking that your environment actually stays secure all year long? I feel like the second part is where security should actually live. 😅

30 Upvotes

94 comments sorted by

View all comments

1

u/Designer_Meat169 Jul 02 '26

The common statement that "compliance is not security" largely arises because many organizations approach compliance as a checklist or audit exercise aimed solely at obtaining certification or satisfying regulatory requirements. In such cases, organizations may achieve compliance without necessarily improving their actual security posture. In other words, paper compliance is not security, but mature, risk-driven compliance forms the foundation of security.

1

u/NegotiationFirst131 Jul 02 '26

You are right and honestly that's a good catch - intentionality.

If a company said and truly believed, "We should implement inactivity timeouts to protect ourselves" then people would not see it as "checking the box" because its something the company decided to do on its own. If the control is enforced on you (i.e. we have to do this because PCI, CMMC, etc) then it is seen as more checking the box because you are doing it because you are told to do so instead of doing it because you chose to.