Most organizations are just performing compliance – ticking boxes, not building real security. What happens when the curtain is pulled back on these check-the-box programs? You might be under the illusion of safety, but in reality, you're exposing your organization to serious risks.In this eye-opening episode, Todd Coshow and cybersecurity expert Adam Goslin reveal how many companies operate in “compliance theater,” creating an illusion of security to meet audit deadlines without safeguarding their environment. They unpack the stark difference between being audit-ready and genuinely secure, exposing how superficial policies, outdated evidence, and a mindset focused on passing assessments put your company at risk.


Episode Transcript:

The topic for today really boils down to whether or not folks out there are actually secure or if they’re just checking boxes. So let’s start with the tough one.

Are organizations actually secure or just really good at checking the bare minimum boxes before the auditor shows up?

Adam Goslin:
If we’re being honest about it, most of them are performing.

There are too many organizations out there to count that their view of navigating their security and compliance waters is doing the least preparation that’s humanly possible in advance of their audit or their assessment. They’re just trying to get through the process.

In a lot of cases, it’s like a mantra: “We have to check. We’re being forced to do this, and we’re doing as little as we can just so that we can achieve the little piece of paper that says we’re secure.”

They know what they need to show to the assessor, when to show it, and how to package it. But there’s a stark difference between organizations that are actually operationally secure, really taking this stuff seriously, etc.

It also doesn’t provide any proof that everything’s going to be cooking with gas come some random Tuesday in March. Security isn’t a moment-in-time thing, where unfortunately most of the assessments and audits are.

Todd Coshow:
When we say compliance theater, what does that actually mean in practice? Where do you see organizations just going through the motions instead of building real security?

Adam Goslin:
Compliance theater is when your program’s built to prove something instead of actually demonstrating or doing something. That’s where you see compliance theater coming into play.

Maybe it rears its head with screenshots that are cobbled together the day before the assessment. Maybe it’s policies that get refreshed once a year and, other than that, collect dust somewhere. It’s controls that exist but aren’t truly implemented or operationalized.

Probably one of the biggest signs for an organization is when there’s this crescendo of compliance effort that happens with their annual assessment, and then all of a sudden, the second the auditor leaves, everybody’s wiping the sweat off their brow: “Thank God we made it through that one.”

Everybody goes back to their day jobs and waits another nine or ten months before they have to prep for their next cycle. That’s the epitome of the compliance theater arena.

Todd Coshow:
Talking about the audit-versus-reality gap, how big is the gap between passing the audit, like PCI, SOC 2, ISO, and what’s actually happening on a day-to-day basis inside of an environment?

Adam Goslin:
There’s a bigger gap than folks want to admit.

If you’re passing an audit or an assessment, that means that you’ve met the minimum bar at a specific point in time. But it doesn’t necessarily mean that the controls are being consistently applied across the environment throughout the compliance cycle.

It doesn’t mean that you’re keeping your evidence fresh. It doesn’t mean that the team may even understand what they have or what they do. All I know is that for this particular requirement, I had to go into this interface, click these buttons, grab this information, this screenshot, and poof.


Podden och tillhörande omslagsbild på den här sidan tillhör Total Compliance Tracking. Innehållet i podden är skapat av Total Compliance Tracking och inte av, eller tillsammans med, Poddtoppen.