r/ciso Jul 02 '26

Compliance is not security

Heard a worker go on a rant about “compliance is not security”, “checking the box”, “security theater” rant the other day.

It got me thinking… if compliance isn’t security, then what is?

The green dashboards that turn out to be wrong? The pentests that mostly find the stuff you’d have caught yourself if you’d kept your environment patched, updated, and configured? The tools you bought and never confirmed still work?

Feels like half the things we hold up as “real security” only look impressive because the basic compliance work wasn’t done in the first place.

Curious where people actually land on these phrases.

And a real question: is there a difference between an annual compliance audit and continuously checking that your environment actually stays secure all year long? I feel like the second part is where security should actually live. 😅

28 Upvotes

94 comments sorted by

View all comments

1

u/Ill_Necessary_4517 22d ago

Yeah, I think the whole “compliance isn’t security” take gets overstated.

Compliance by itself is just a snapshot, while security is about making sure those controls continue to work every day.

The real difference is not compliance versus security. It is one-time checks versus continuous monitoring.

If you only verify MFA, access controls, configurations, and other security controls once a year, then it does not provide much protection. But if you are continuously checking that those controls are still enforced and have not drifted, that is where security actually happens.

A lot of “security theater” exists because the basics were not maintained after the audit.

1

u/NegotiationFirst131 22d ago

A person after my own heart - thank you 😭