Compliance Unfiltered is TCT’s tell-it-like-it is podcast, dedicated to making compliance suck less. It’s a fresh, raw, uncut alternative for anyone who needs honest, reliable, compliance expertise with a sprinkling of personality.
Show Notes: Compliance Theater: Are You Actually Secure or Just Checking Boxes?
Quick Take
Most organizations are just performing compliance – ticking boxes, not building real security. What happens when the curtain is pulled back on these check-the-box programs? You might be under the illusion of safety, but in reality, you’re exposing your organization to serious risks.
In this eye-opening episode, Todd Coshow and cybersecurity expert Adam Goslin reveal how many companies operate in “compliance theater,” creating an illusion of security to meet audit deadlines without safeguarding their environment. They unpack the stark difference between being audit-ready and genuinely secure, exposing how superficial policies, outdated evidence, and a mindset focused on passing assessments put your company at risk.
Read The Transcript
So let’s face it, managing compliance sucks. It’s complicated, it’s hard to keep organized, and it requires a ton of expertise in order to survive the entire process.
Welcome to Compliance Unfiltered, a podcast dedicated to making compliance suck less. Now, here’s your host, Todd Coshow, with Adam Goslin.
Todd Coshow:
Welcome in to another edition of Compliance Unfiltered. I’m Todd Coshow, alongside the fresh glass of lemonade to your compliance Sunday picnic, Mr. Adam Goslin. How the heck are you, sir?
Adam Goslin:
I’m doing good today, Todd. How about you?
Todd Coshow:
I can’t complain. It is a beautiful summer day here in San Diego, California. Before we jump in today, as always, Adam, we wanted to thank the folks. You want to do the thank-yous today?
Adam Goslin:
Sure. To the listeners, appreciate you joining us.
Just a couple of favors. One, tell your friends. Two, think about stuff going on in your world. What would be an interesting topic that you ran across? Heck, especially if it’s a war story or something that went horrifyingly awry that maybe other folks can learn from.
Do me a favor: protect the innocent. We won’t relay it, but we’d love to hear from you. So shoot us a note at [email protected].
Todd Coshow:
Indeed. Today, Adam, we’re going to visit the theater. That’s right, the compliance theater.
The topic for today really boils down to whether or not folks out there are actually secure or if they’re just checking boxes. So let’s start with the tough one.
Are organizations actually secure or just really good at checking the bare minimum boxes before the auditor shows up?
Adam Goslin:
If we’re being honest about it, most of them are performing.
There are too many organizations out there to count that their view of navigating their security and compliance waters is doing the least preparation that’s humanly possible in advance of their audit or their assessment. They’re just trying to get through the process.
In a lot of cases, it’s like a mantra: “We have to check. We’re being forced to do this, and we’re doing as little as we can just so that we can achieve the little piece of paper that says we’re secure.”
They know what they need to show to the assessor, when to show it, and how to package it. But there’s a stark difference between organizations that are actually operationally secure, really taking this stuff seriously, etc.
It also doesn’t provide any proof that everything’s going to be cooking with gas come some random Tuesday in March. Security isn’t a moment-in-time thing, where unfortunately most of the assessments and audits are.
Todd Coshow:
When we say compliance theater, what does that actually mean in practice? Where do you see organizations just going through the motions instead of building real security?
Adam Goslin:
Compliance theater is when your program’s built to prove something instead of actually demonstrating or doing something. That’s where you see compliance theater coming into play.
Maybe it rears its head with screenshots that are cobbled together the day before the assessment. Maybe it’s policies that get refreshed once a year and, other than that, collect dust somewhere. It’s controls that exist but aren’t truly implemented or operationalized.
Probably one of the biggest signs for an organization is when there’s this crescendo of compliance effort that happens with their annual assessment, and then all of a sudden, the second the auditor leaves, everybody’s wiping the sweat off their brow: “Thank God we made it through that one.”
Everybody goes back to their day jobs and waits another nine or ten months before they have to prep for their next cycle. That’s the epitome of the compliance theater arena.
Todd Coshow:
Talking about the audit-versus-reality gap, how big is the gap between passing the audit, like PCI, SOC 2, ISO, and what’s actually happening on a day-to-day basis inside of an environment?
Adam Goslin:
There’s a bigger gap than folks want to admit.
If you’re passing an audit or an assessment, that means that you’ve met the minimum bar at a specific point in time. But it doesn’t necessarily mean that the controls are being consistently applied across the environment throughout the compliance cycle.
It doesn’t mean that you’re keeping your evidence fresh. It doesn’t mean that the team may even understand what they have or what they do. All I know is that for this particular requirement, I had to go into this interface, click these buttons, grab this information, this screenshot, and poof.
There could be, and a lot of times is, a gap between what do I have to do versus what does it actually mean.
There are a lot of organizations that are, finger air quotes, “compliant” for some small portion of the year. It’s a bigger problem than a lot of organizations want to account for.
Todd Coshow:
That’s fair. Why do compliance programs tend to fall into that checklist mentality? Is it a tooling issue? Is it a process issue? Or is it just how the frameworks are actually designed?
Adam Goslin:
At the end of the day, it’s all three.
But a lot of it comes down to mindset. These frameworks weren’t intended to run like a to-do list, but that’s effectively what they’ve become. People walking into their annual audit or assessment are asking the question, “What do I need to pass? What do I have to hand you to pass?” instead of looking at it from the perspective of, “What do I need to do to be able to operate my organization in a secure manner?”
Then, from a tooling perspective, you’ve got tools, spreadsheets, and shared drives. Those make it all worse because they’re not really designed for supporting that operational mode of compliance where you’re doing continuous activities. They support the notion of more of a one-time collection.
The entire system is pushing organizations in a direction of checking boxes instead of managing their environment correctly, the way that they optimally should.
One of the biggest differences that I’ll see in an organization is really the approach that both the executive upper-level management and mid-level management take.
If their mantra is, “Just get the freaking assessment over with so that we can go back to our real jobs,” if that’s where their headspace is at, that’s not helping the cause.
If instead all of those layers of management have a security and compliance mindset and they’re pushing it top-down, guess what? The whole organization starts to step in line.
But if the upper levels of management aren’t going to care, why the hell would the frontliners give a crap? “If they don’t care, why should I care?” is going to be the mentality.
You’ve got to be a good representative of the organization. If you’re in that upper or mid-level management position, it’s part of your responsibility to help protect the company.
Todd Coshow:
That leads me to my next question around real-world risk.
What is the real risk of running a check-the-box compliance program? Are organizations exposing themselves without realizing it?
Adam Goslin:
Absolutely. The biggest risk is false confidence.
Everybody goes under this guiding assumption that because we’ve gone through and passed the audit, we’ve got the piece of paper that says we’re compliant. The reality is that as soon as the assessment’s done, everybody’s, finger air quotes, gone back to their day job.
The controls are already sliding. They’re already drifting. If it’s not supported by management, nobody else cares. Access reviews are starting to get outdated and maybe not being done. Being eyeball-deep in the logs and logging is happening. Evidence is getting more and more stale.
What I see a lot in organizations is this notion that they get the piece of paper and look at the piece of paper as having successfully completed the task.
What you did is complete the task to pass your assessment. But completing that task doesn’t translate to all of the time in between.
They run under this notion that they’re still protected when it’s four, five, or six months after the assessment. They just go into the guiding principle that all’s good.
Attackers aren’t going to give two craps if you passed your PCI last quarter. All they have to prove out is that your controls are weak right now.
This notion of compliance theater is a real dangerous illusion for the folks within the organization that everything’s fine when it really isn’t.
Todd Coshow:
How do you actually break out of compliance theater? What does a program look like that’s not just audit-ready, but continuously secure?
Adam Goslin:
It certainly means moving away from the annual—I’m going to go back to my “wabbit season” references—but moving away from treating compliance like wabbit season and actually looking at your program in a continuous fashion.
That means I’m not just going in and caring about this once a year. You’re not just documenting things and stuffing them on a shelf. You’re operationalizing your overall program, where the team has real visibility into what’s happening at any given moment.
If, as an organization, you can’t answer the question, “Are we compliant right now?” without scrambling, then you’re still in theater mode.
The utopia is to be able to go in, look at the state of your program, and know that yes, we’ve been doing these functions. They’re still effective. We’ve got periodic or regular pulse checks on these items.
We’re not just trying to survive an audit. You want to effectively make the notion of the audit irrelevant because you’re in a state of continuous readiness.
There are certain elements that only need to be touched or reviewed once a year. I’ll give you the notion of policies.
Certainly, if there are circumstances within the organization for their policies where there’s a business need—whether the standard changed, our scope has changed, our controls are changing, whatever—when those events occur during the year, those events ought to trigger the immediate updates to your policies and procedures so that you can get those up to speed in alignment with reality, redistribute them out to everybody, get them all to sign off on it, etc. That way, I’m in a state of continuous readiness.
If you haven’t had one of those events, then yes, once a year you’re going to need to review your policy documentation.
But again, with this notion of operational compliance, instead of leaving it to the very last second, let’s say that your on-site for your assessment is July 1. A lot of organizations wait until the week before the audit, and everybody’s diving through fire hoops to get the updated dates on their policies.
I look at compliance as an annual event with a compliance cycle. When I’m looking at a program, I’ll refer to it as compliance quarters.
As an example, if the target completion date for this particular organization’s assessment is in that July timeframe, then compliance Q4 is really calendar Q2.
As I’m referring to the compliance quarters, it’s just a relative quarter off of whatever the target goal date is.
Instead of leaving all your policies and procedures and everything until Q4 of your compliance cycle, do them in the latter part of Q2. That way, proactively, you’ve got them done. They’re ready to go. They’re certainly within the year, and you’re ready to rock.
That’s your best-case scenario.
Todd Coshow:
When the curtain gets pulled back on your compliance program, is it real security or just a really well-rehearsed performance? I guess that’s kind of an age-old question.
Adam Goslin:
Yeah, that’s for sure.
Todd Coshow:
Parting shots and thoughts for the folks this week. Got them?
Adam Goslin:
Going back to the earlier comment that I made about management, it’s really telling when management is doing the griping: “How long is the assessment taking? We got all these other priorities about what we need to do. Are you done yet?”
It seems like the kids in the backseat: “Are you done yet? We want to get back to real work.”
I’d say it two ways. One, for the folks that are involved in organizational compliance and are more in the control owner seat, those are things to watch out for from the levels of leadership.
But honestly, the gauntlet that I would throw is, if you’re in those levels of leadership, support your teams. Take this stuff seriously.
I’ve said it before, I’ll say it again. If somebody came to me and said, “Adam, would you rather pay for your cyber insurance or would you rather have a strong operational security and compliance program?” I’d light a match to the cyber insurance policy every single day of the week and twice on Sunday.
The bottom line is that taking this stuff seriously and doing it properly, operationalizing your engagement, making it part of the DNA of the company, those are all steps that will go a long way toward active protection for the company.
Sure, you want to keep your cyber liability insurance for the what-if, just in case, etc. I’m not suggesting people should just light those on fire.
But if I had to make a choice between the two, I would absolutely keep the strong program because it’s active protection for the company and really goes a long way toward mitigating risk to the organization.
Todd Coshow:
And that right there, that’s the good stuff.
That’s all the time we have for this episode of Compliance Unfiltered. I’m Todd Coshow.
Adam Goslin:
And I’m Adam Goslin.
Todd Coshow:
I hope we helped to get you fired up to make your compliance suck less.