International Cyber Expo International Cyber Expo
  • About Us
Sunday, 4 October, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Why compliance does not guarantee cyber resilience

Why passing an audit is not proof an organisation can withstand a real incident

by Lara Joseph
August 19, 2026
in Featured
Why compliance does not guarantee cyber resilience
Share on FacebookShare on Twitter

Cyber security has become one of the most audited and regulated areas of enterprise technology. Yet an organisation can satisfy every requirement on paper and still discover, during a real incident, that its systems, people or processes are not ready for the pressure that follows. Compliance can demonstrate that controls have been put in place; it cannot, on its own, demonstrate that those controls will continue to work when a critical service is disrupted. Here, Nathan Charles, head of customer experience at cyber resilience specialist OryxAlign, explains why organisations need to look beyond compliance and test whether their resilience claims stand up in practice.

Organisations invest significant time and resource into achieving certifications such as ISO 27001 and Cyber Essentials, while regulated firms face additional obligations under frameworks such as the Financial Conduct Authority (FCA) and Prudential Regulation Authority (PRA) operational resilience rules. These frameworks provide valuable structure and demonstrate a credible baseline of security maturity.

Compliance frameworks like these set a recognised baseline, create accountability and give boards and customers a way to benchmark security maturity. The risk lies in what happens post-certification.

For many organisations, passing an audit becomes the objective in itself, rather than a step towards genuine resilience. Certification and self-assessment exercises capture a snapshot of security controls at a single point in time, under conditions that are largely predictable. They rarely test what happens when those controls are placed under real pressure, such as a ransomware attack that spreads faster than the incident response plan anticipated, a misconfigured update that takes core systems offline, or a supplier outage with knock-on effects nobody had mapped. 

When the paperwork doesn’t match reality

The gap between documented compliance and operational reality is well evidenced. The UK Government’s Cyber Security Breaches Survey 2025/2026 found that 43 per cent of UK businesses reported experiencing a cyber security breach or attack in the past twelve months. This is despite most organisations already having basic technical measures, such as malware protection, firewalls and access controls, in place.

The financial services sector, where operational resilience obligations are most mature, illustrates the same gap. In March 2026, the FCA published its first detailed review of how firms had performed since the transition period for its operational resilience rules ended in March 2025. The review examined whether firms had genuinely embedded resilience into daily operations, or whether their self-assessments amounted to little more than a paperwork exercise.

This distinction matters because resilience is ultimately about outcomes rather than the existence of controls. An organisation may have an incident response plan, supplier assessments and documented recovery procedures, but that does not necessarily mean the right people know what to do when a critical service fails. It may also be unclear how one disruption affects another system, supplier or business process. These dependencies can be difficult to identify through conventional compliance exercises because they only become visible when the organisation is placed under stress.

In other words, an organisation can produce all the required documentation and still be unable to demonstrate that its most critical services would survive a severe but plausible disruption. The challenge is moving from asking whether a control exists to asking whether it delivers the intended outcomes when it matters most. 

Regulators are recognising the gap too

Encouragingly, this is not a case of compliance frameworks being wrong; it reflects how regulators and standard-setters are actively evolving what they expect organisations to demonstrate. The National Cyber Security Centre (NCSC) has developed its Principles Based Assurance approach specifically to move away from assessment against fixed, compliance-driven control sets, in favour of a risk-based approach.

The FCA has followed a similar trajectory, shifting its supervisory focus from asking firms whether they have identified their important business services, to asking whether they can prove they remain within agreed impact tolerances today, through tested evidence rather than policy documents.

Similar principles underpin the EU’s Digital Operational Resilience Act, which requires financial entities to test their resilience through scenario-based exercises rather than rely on point-in-time compliance reviews. Across sectors and geographies, there is a consistent direction of travel where demonstrated resilience, not paperwork, is the real measure of readiness.

This shift is important because it changes the question organisations need to ask themselves. Rather than viewing resilience as something demonstrated during an audit, it should be treated as an ongoing capability that needs to be evidenced throughout the year. A successful assessment should therefore be viewed as a starting point for further testing, rather than confirmation that the organisation is resilient. 

From checklist to stress test

For organisations that want to close this gap, the starting point is treating resilience as something that is tested and proven, not assumed because a framework has been satisfied. That means running scenario-based exercises that simulate severe but plausible disruption, such as the loss of a critical supplier, a ransomware incident or a major cloud outage, and observing how systems, teams and decision-making actually hold up under pressure.

The value of these exercises is not just about identifying whether an organisation can recover. They can expose assumptions that have gone unchallenged, reveal dependencies between critical services and show where responsibilities become unclear during an incident. They can also provide evidence for whether recovery objectives are realistic and whether teams have the information they need to make effective decisions when normal processes are no longer available.

Crucially, testing should not be treated as another compliance exercise. If an exercise only seeks to demonstrate that an existing plan works, there is a risk that organisations will overlook the weaknesses the exercise is intended to uncover. Instead, scenarios should be designed to challenge assumptions and provide an honest assessment of how systems, people and processes perform under pressure.

Compliance frameworks and regulatory obligations remain an essential part of managing cyber risk, and organisations should not disregard them. But they represent a floor, not a ceiling. Genuine operational resilience is proven under pressure, not certified on paper.

Organisations that build a culture of continuous testing, honest assumption-challenging and cross-functional ownership will be far better placed to keep critical services running when, not if, disruption occurs. The objective should not be to abandon compliance, but to use it as the foundation for a broader approach in which resilience is continually tested, evidenced and improved. 

To learn how OryxAlign helps organisations map digital dependencies and strengthen operational resilience, visit www.oryxalign.com.

ShareTweet
Previous Post

Hacker Claims Millions of Records Stolen From Azure Tenants

Next Post

Premier League Introduces Mandatory Cybersecurity Standards, Backed by Fines of Up to £100,000

Recent News

Ship fast, verify independently: keeping application security in step with AI-written code

Ship fast, verify independently: keeping application security in step with AI-written code

October 2, 2026
Shadow AI and the permissions problem: what to check before handing AI the keys

Shadow AI and the permissions problem: what to check before handing AI the keys

October 2, 2026
Cybersecurity Awareness Month: AI agents are users too, and they need governing like it

Cybersecurity Awareness Month: AI agents are users too, and they need governing like it

October 2, 2026
Malicious Email Could Hijack AI Agent and Access Connected Accounts

Malicious Email Could Hijack AI Agent and Access Connected Accounts

October 2, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol