Every year we watch a business pour weeks into an audit. The questionnaire gets filled out, the policy binder gets updated, the evidence gets uploaded, and eventually a letter arrives saying everything is in order. Everyone exhales. Then, four months later, somebody in accounting wires money to a fake vendor, and the same business asks how it happened when they had just passed.

Both things are true. They did pass. They also got hit. Passing the audit and stopping the attack are two different jobs, done by different means, measured on different clocks. You need both, and the trouble starts the moment you assume one buys you the other. This is not an argument against compliance. Compliance is genuinely useful and sometimes legally required. It is an argument against mistaking the receipt for the meal.

What Compliance Actually Measures

Compliance answers a specific question: can you demonstrate, with evidence, that a defined set of controls existed at a defined moment? That is a real question worth answering. It just is not the same question as whether an attacker can get in.

Notice what that requires. Defined controls, so somebody else decided what counts. Evidence, so what matters is that the control is documented. A defined moment, so the assessment describes a point in time. Security answers a harder question nobody defined in advance: given everything about your business, is it actually hard to hurt you, today.

The standards bodies say so themselves. NIST published version 2.0 of its Cybersecurity Framework in 2024, and it is explicit that the framework’s outcomes “are not a checklist of actions to perform.” It also states that “The CSF does not embrace a one-size-fits-all approach,” because every organization has different risks and priorities. The Federal Trade Commission makes the same point in its guidance for small businesses, noting that the framework “is voluntary” and offers an outline of best practices to help you decide where to focus. Neither one describes a pass or fail line. That idea gets added later, usually by an insurer or a customer’s procurement team.

Where They Genuinely Overlap

We are not here to tell you compliance is theater. A large chunk of any credible framework maps directly onto things that stop real attacks, and if you are starting from nothing, an audit is an efficient way to find out what you are missing.

  • Inventory. Almost every framework makes you list your systems and data. You cannot protect what you have never written down, and most businesses discover something surprising the first time they try.
  • Access control. Frameworks force you to answer who can reach what. That question, honestly answered, usually removes more risk than any product purchase.
  • Patching. CISA’s Cyber Guidance for Small Businesses is direct about why attacks land: “Many attacks succeed because the victims were running vulnerable software.” Compliance nags you about updates, and the nagging works.
  • Backups. The same CISA guidance warns that many organizations hit by ransomware “had no backups or had incomplete/damaged backups.” A framework at least asks whether you have them.

That overlap is real and worth money. A business that takes a framework seriously is usually in better shape than one that never thought about any of this. Our point is narrower: the overlap is not complete, and the gap is where the losses happen.

Where Compliance Lags Reality

There are three structural reasons a compliant business can still be an easy target, and none of them are anybody’s fault. They are baked into how assessment works.

It takes an annual snapshot of a daily problem. An assessment describes the week it was performed. Attackers do not schedule around your audit cycle. NIST states the problem plainly in the 2024 framework: “Cybersecurity risks are expanding constantly, and managing those risks must be a continuous process.” The FTC’s guidance says to test your plan periodically and update policies to reflect lessons learned, which is the same message. A yearly checkpoint is a floor, not a heartbeat.

It grades the existence of a control, not its quality. “Do you require multifactor authentication?” is a yes or no question. It does not distinguish between a business that uses hardware keys everywhere and one that texts codes to phones and exempts three executives. Both answer yes. Only one is hard to break into.

It writes the requirements after the attacks. Standards move through drafts, comment periods, and revisions. That process produces careful, durable guidance, and it means the document reflects the threats of a few years ago. The attack that hits you next quarter was probably not on anyone’s checklist. Business email compromise and invoice fraud are good examples: they beat technical controls entirely by convincing a human being to do something ordinary, which is part of why phishing remains so hard to block.

Compliant and Breached at the Same Time

We are not going to trot out famous company names and claim to know what their auditors saw. Nobody outside those rooms does, and that kind of storytelling is how bad advice spreads. What we can tell you is the pattern we see in our own work, repeatedly.

The business was compliant. The finding, when it came, was never on the checklist. A vendor with too much access. An old account nobody closed. A shared login that made the audit easier to pass. A backup that was configured correctly and had never been restored. Every one of those can sit comfortably inside a clean report, because the control existed. It just did not work.

The worst version is when compliance actively hurts. Teams optimize for what gets graded, so budget goes toward documentation instead of detection, because documentation is what the auditor asks for. That is a rational response to the incentive, and it makes the business less safe. It is the same trap behind the “we will handle it when we are bigger” thinking we covered in why cybersecurity is no longer optional for mid-sized businesses.

Using a Framework as a Floor, Not a Ceiling

The fix is not to abandon frameworks. It is to use them the way their authors intended, then keep going. NIST builds this into the structure: document a Current Profile of what you achieve now, define a Target Profile of what you want, compare them, and work the gaps. It also describes four Tiers, from Partial through Risk Informed and Repeatable up to Adaptive, which exist precisely because passing is not a single line.

  1. Treat the certificate as the starting point. The day the letter arrives, ask what an attacker would still try. That question has a different answer than the audit did.
  2. Add a quarterly review between audits. Thirty minutes. New systems added, people who left, admin accounts, one backup restore actually performed. This is where the annual snapshot problem gets solved.
  3. Grade quality, not presence. For each yes on the checklist, write one sentence about how well it is implemented. The weak ones become obvious fast.
  4. Test the controls you claim. Restore a file. Try logging in without the second factor. Call your own accounting team pretending to be a vendor changing bank details.
  5. Budget separately. Give compliance work and security work their own lines. If they share a budget, compliance wins every time, because compliance has a deadline.

The Bottom Line

Compliance proves you met a standard on a given day. Security means an attack against you does not work. They share a lot of ground and they are not the same, and the businesses that get hurt are usually the ones that stopped at the letter and assumed the rest was covered.

Use the framework. Pass the audit. Then, the same week, ask the question no auditor asked you. Keep a floor and a ceiling in your head, and never confuse the two.

If you are working through an audit and want a candid read on where the real gaps are, we are happy to walk through it with you. Contact us today.


Sources:

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).