Cybersecurity Compliance Presents a Paradox
Compliance frameworks and regulatory regimes largely ask two questions: Are you watching? And are you doing something ridiculous? To comply with these frameworks means to manage your risk based on whatever best practices existed when the framework was written. For example, the National Institute of Standards and Technology 800-53 control SI-4 says, in effect, that you need to have an intrusion detection or prevention system (IDS/IPS). If you’re following ISO 27001, controls A.8.15 and A.8.16 say much the same thing.
The danger for IT managers is treating all of that work on compliance and risk management as the finish line. It’s not; it’s the baseline aimed at passing an audit.
There’s nothing in the compliance frameworks that says that attackers are going to trigger your IPS, for example. Or that your audit-approved security tool mix will find a true attack in the millions of events that show up each day — if you can even get your cloud provider to deliver those events. Or, if it sees the event, there’s no guarantee that it’ll properly prioritize it. And there’s even less of a guarantee that an alert-fatigued human analyst will have a chance to prioritize and investigate the event before it’s too late. You can be 100% compliant with every security information and event management solution with every AI assistant watching and still not see what has already happened in your network and all of its cloud extensions.
And while you should have an IDS/IPS system in place, that particular control is principally aimed at neutralizing an attack technique that’s somewhat out of fashion. Yes, there’s still malware and SQL injection attacks, but bad actors today are focusing elsewhere, exploiting human error not just in the enterprise but along the entire software supply chain. Successful attackers exploit operational weaknesses rather than the absence of risk controls. And they’re supercharging their attacks with AI.
Focus On the Blind Spots in Your Network
Compliance is based on the idea of knowledge: visibility and control of what’s happening and where the assets are. For networks of all sizes, this basic requirement is often a fantasy. IT managers know less about their networks than they believe. Cloud, Software as a Service, remote workers and mobile devices have all increased complexity to the point where every organization is challenged to understand possible failure points and how to apply compliance controls.
Add to this the obvious blind spots: shadow IT (and now shadow AI), unmanaged and legacy systems, cloud prototypes that never got shut down, and Internet of Things devices. Compound these challenges with configuration issues, deviations from documented policy, misconfigurations that never did what they should have, and cloud and DevOps environments morphing faster than security teams can evaluate and audit them. To all of this, mix in potential tool failure, such as siloed security consoles, or just general alert overload and analyst fatigue.
RELATED: Get started with a rapid maturity assessment.
Even if IT managers are aware of their blind spots, the reality is that attackers have the advantage of time asymmetry. A weakness can be exploited in days, even hours, because the attacker only needs one small path that lets them set up shop inside. IT teams, even diligent ones, work at human speed when exploring, documenting, cleaning up and applying controls to their blind spots: a quarter, a month, a year for the next audit, and when that’s done, a whole new set of issues are there to be discovered. The larger the organization, the more quickly it will fall behind.
Click the banner below to learn why cyber resilience is essential to enterprise success.
