


creditcontrol.co.uk
Credibility suffers when compliance is too quick
More than 85% of UK cybersecurity managers believe the race to secure certifications quickly is undermining their credibility and creating gaps in organizations’ security posture, according to new research from business resilience specialists IO).
The research also reveals that 21% of respondents believe third-party certifications can quickly become outdated, raising further questions about how much confidence businesses should place in certification achieved through accelerated implementation approaches alone.
“Certification can open doors to new contracts and demonstrate commitment to recognized standards but treating certification as the end goal rather than the outcome of establishing and embedding effective compliance is more often than not at the expense of long-term resilience. Businesses must treat compliance not as a tick-box exercise but an evolving, iterative, and business critical project,” explains Chris Newton-Smith, CEO, IO.
“While certification provides valuable independent assurance that an organization has implemented controls, where implementation has been heavily compressed, there may be limited opportunity to demonstrate that those controls have been embedded, monitored and improved over time. Genuine resilience requires that controls are embedded, understood, and actively maintained, not just documented for inspection.”
“The research gives us a clear picture of what practitioners believe genuine compliance resilience looks like, with controls that are monitored continuously, governance with named accountability and human expertise kept in the loop. These are the foundations that allow an organization to keep operating through disruption, demonstrate its security posture on demand and absorb regulatory change without starting from scratch. Compliance done rigorously delivers all this. It is not just a certification, but the capability to audit faster, absorb new requirements without disruption, face fewer costly surprises, keep the business running and keep earning trust,” says Newton-Smith.
While automation can speed up evidence gathering and routine checks, 45% of respondents believe that human expertise is still essential when evaluating whether the suggested automated compliance processes and actions are relevant or accurate, with 33% saying human expertise is needed to interpret complex regulations. A further 32% say human expertise is key to challenging the credibility or completeness of automated compliance evidence.
“The question to ask of any compliance programme isn’t how long it took. It’s: do the people in this organization understand what they’re doing and why? Are the controls genuinely embedded? Would this hold if something went wrong tomorrow? If the answer to those questions is yes, the certification means something. If the process was too fast for those questions to have been properly answered, the certificate is a risk, not a reassurance,” warns Newton-Smith.
“Procurement teams and partners are increasingly assessing not just whether an organization holds certification, but how it manages compliance on an ongoing basis,” adds Newton-Smith. “Certification remains an important signal of trust, but organizations are increasingly expected to demonstrate that compliance is embedded into day-to-day operations through governance, monitoring and continual improvement. The ability to demonstrate live, integrated governance is becoming a commercial differentiator for businesses.”
ISO standards, including ISO 27001, are built on continuous improvement. Organizations that treat compliance as an ongoing discipline – not a race to certification – gain stronger resilience and a lasting competitive edge.