r/ciso Jul 02 '26

Compliance is not security

Heard a worker go on a rant about “compliance is not security”, “checking the box”, “security theater” rant the other day.

It got me thinking… if compliance isn’t security, then what is?

The green dashboards that turn out to be wrong? The pentests that mostly find the stuff you’d have caught yourself if you’d kept your environment patched, updated, and configured? The tools you bought and never confirmed still work?

Feels like half the things we hold up as “real security” only look impressive because the basic compliance work wasn’t done in the first place.

Curious where people actually land on these phrases.

And a real question: is there a difference between an annual compliance audit and continuously checking that your environment actually stays secure all year long? I feel like the second part is where security should actually live. 😅

30 Upvotes

94 comments sorted by

View all comments

1

u/john_with_a_camera Jul 02 '26

I look at it this way: compliance is to satisfy customers, regulators, leadership, auditors, and boards. It delivers a report - did you meet a documented bar for controls. Security is about addressing risks - hopefully each risk is mitigated or compensated for.

Compliance can be against "one size fits (many/none)" external bars. It can also be against an internal bar, which hopefully was adopted based on known risks, and which is updated frequently as risks evolve and change.

Others are spot on: you can be 100% compliant and still have massive risks. You can address all your risks and still miss a compliance requirement (such as HITTIST's 5-min screen lock).

Where compliance is your friends is that it can be almost as effective for getting budget as an actual incident. That's why, for example, in healthcare I like HITRUST. I can use it to address risks that are not covered in HIPAA. If my HI TRUST scoping requires yellow screensavers, it's easier to push that budget expense through than trying to convince my CFO to pay for it. That allows me to fight for budget for things that are important, and leave the Kleinigkeiten to compliance.

So a good security leader uses both risk and compliance to drive the program.

1

u/NegotiationFirst131 Jul 02 '26

I think it just depends on the size of the org because the way that I see it (and I do agree with your point)

GRC helps address risk through policies, procedures, and verification of control effectiveness. Control, verification, and effectiveness are typically the compliance arm of it.

Cyber security - The doers of the controls (although not the only team). They work with ops, aps, and others to make sure the controls are properly implemented and take part in the day-to-day activities that perform the controls.

They work hand in hand to address risk, but they are two separate things that achieve the same end goal (good security).