A Checkbox Won’t Save You

“Security is a state of being. Compliance is just a snapshot in time”


Due to the lack of awareness (or sometimes just a lack of regard) for cybersecurity, companies and individuals don’t really stop to think about how secure they really are. That is, until someone comes knocking on your door and demanding updates on your security posture. It’s not thought about until it’s thought about, and usually by the time you’ve thought about it you realize you should have thought about it a lot sooner! (Try saying that ten times fast, I dare you.)

I’ve seen this more often within smaller companies, but larger businesses are not immune to it either: Law firms, clinics, libraries, startups and even larger industry players. If you’re not already taking into consideration things such as data privacy or AI regulations, chances are it will be a headache when it comes time to prove your business is in compliance. The reality of it is that the smaller businesses simply can’t afford to hire a full-time compliance officer. The larger businesses, though they may have more money, may wait too late to consider it. Yet everyone absolutely must pass security audits in order to retain clients. If you are not “certified”, chances are someone is going to go to your competitor that is.

This creates not only immense pressure, but a dangerous, industry-wide mindset: The pursuit of the “checkbox”.

You see, everyone thinks that for frameworks like SOC2 and GDPR, once you pass an audit you’ve essentially crossed the finish line. You fill out the paperwork, an (external) auditor gives you a passing grade, and return you get a shiny new badge at the bottom of your website that shows you are officially “compliant”

But here is the hard truth: there is a very dangerous difference between being compliant and actually being secure.

Compliance is a snapshot in time. It proves that on one specific Monday in January, your organization met the MINIMUM required standards. And I do mean minimum.

On the other hand, security is a continuous sequence over a much longer period of time. A threat actor does not care about your shiny badge that you earned in January. It is now July, and the only thing they care about is that employee that was offboarded last week whose access keys were never revoked. They care about that public internet facing server whose firewall was temporarily disabled for bug fixes and never got re-enabled.

When that happens tell me, where’s your shiny new badge now huh?

Now hear me out, I am not saying that there’s no worth in compliancy. However, Governance, Risk and Compliance (GRC) often is treated as just a lot of paperwork and insufferable policy tracking that no one cares to do. And look in a way I understand, but we need to realize that treating compliance as nothing more than a paperwork creates a vulnerability in and of itself!

In no world should there be a scenario where security is simply scrambling to gather documents and evidence a week before an auditory arrives. Ideally, it needs to be built into the architecture from day zero. In fact, compliance should come naturally. When you practice good security hygiene, that’s what produces compliance. Aiming only for compliance rarely produces good security.

There’s a quote that I find myself saying more and more each day, “If you have to do something more than twice, automate it”. Instead of relying on last minute, manual, error-prone checklists, I believe the future of small business security lies in automation.

  • Continuous Scanning: Using “Lite” GRC tools that routinely and automatically scan a company’s documents and infrastructure to generate audit-ready reports. Ideally, any day of the week, you’d be able to produce proof that you have a secure posture.
  • Security as Code: If the compliance rules are built into the code that generates things such as cloud infrastructure, out-of-bounds changes are blocked before they ever happen.
  • Constant Vigilance: We have to shift our mindset from simply passing the compliance exam, to actively monitoring your perimeter every single day.

Listen, I know it worked in high school. It probably worked in college too. But we have to grow up and stop treating security like a college exam that we can cram for last minute. The moment you take on that mindset, you are already vulnerable. Do the work. Stop chasing a checkbox. Start securing the system.

Leave a comment