← Back to Blog 05 Aug 2026

Compliance Can't Keep Up: Why Cyber Resilience Must Replace Checkbox Security

Compliance Can't Keep Up:  Why Cyber Resilience Must Replace Checkbox Security

For years, compliance has been treated as a proxy for good cybersecurity. Organisations invest heavily in meeting regulatory requirements, passing audits and demonstrating that the right controls are in place. Those frameworks matter. They create consistency, improve governance and establish a security baseline.

What they don't do is tell you whether you'll withstand the next attack.

AI has fundamentally changed the economics of cybercrime. Reconnaissance can be automated. Phishing campaigns can be generated and personalised at scale. Malware can evolve during an attack. Capabilities that once required experienced operators are becoming accessible to far less skilled criminals, allowing more attackers to launch increasingly sophisticated campaigns.

Compliance was never built for that pace.

Updating a compliance framework is deliberately thorough, and rightly so. New attack techniques need to be understood, evidence gathered and assessed, guidance drafted, stakeholders consulted and standards reviewed before any changes are adopted. Once revised guidance is published, organisations still need time to allocate budget, implement new controls, train their teams and demonstrate compliance during the next audit cycle.

From the emergence of a new threat to widespread adoption of a new control, two or even three years can easily pass. That isn't a flaw in the process. Compliance frameworks exist to provide consistency and governance, not to react to every new attack technique. The problem is that attackers don't work to the same timetable.

AI has compressed attack timelines from weeks to days and, increasingly, from hours to minutes. Threat actors constantly refine their methods, automate what works and abandon what doesn't. By the time a new requirement finds its way into a recognised framework, criminals are often exploiting techniques that weren't even being discussed when that guidance was first drafted.

That's why compliance and resilience should never be treated as the same thing. Compliance defines the minimum standard an organisation is expected to meet. Resilience determines whether it can detect, contain and recover when prevention fails.

I've seen organisations with mature governance, successful audits and well-documented controls still struggle to contain ransomware because operational resilience hadn't kept pace with the threat. Passing an audit doesn't stop an attacker. Containing them does.

The challenge is becoming more obvious as AI compresses the time defenders have to react. 

Most security operations still follow a familiar model. Events are collected across the environment, forwarded to central platforms, correlated with other activity and analysed before action is taken. That architecture has served organisations well for years, but it assumes defenders have time to process information before responding. Increasingly, they don't.

By the time an alert has been generated, prioritised and assigned to an analyst, an attacker may already have achieved their objective. Making Security Operations Centres more efficient certainly helps. SIEM platforms have become more capable, SOAR has reduced manual effort and AI is improving alert triage and investigations. But those improvements still sit on top of the same centralised operating model.

The next step is to push intelligence closer to where attacks begin. Endpoints, cloud workloads and other critical systems need to recognise malicious behaviour and respond immediately, rather than waiting for instructions from a central platform. That doesn't remove people from the process. It allows automated systems to contain threats at machine speed while analysts focus on validating decisions, investigating complex incidents and strengthening long-term defences.

AI is also changing who can become an attacker. The barrier to entry has fallen dramatically. Criminals no longer need years of technical experience to build convincing phishing campaigns, develop malware or automate reconnaissance. AI is giving less experienced threat actors access to capabilities that were once limited to highly skilled groups. That increases both the number of attackers and the volume of attacks organisations face.

Defenders don't have the same advantage. A cybercriminal can launch hundreds of attacks, learn from every failed attempt and keep adapting until one succeeds. Defenders only need to miss one.

Compliance frameworks do little to change that equation because they focus on governance rather than operational performance. They define what organisations should have in place, but they rarely measure whether those controls can detect, contain or recover from an attack quickly enough to make a practical difference.

Speed has become one of the most important measures of effective cyber defence.

How long does it take to isolate an infected endpoint? Can ransomware be contained before it spreads? How quickly can critical systems be recovered? Those questions provide a far better indication of resilience than whether every item on an audit checklist has been completed.

Compliance remains essential. Strong governance, accountability and recognised standards will always have an important role to play. They provide the foundation every security programme needs.

But they are only the foundation.

The organisations that will cope best with AI-driven attacks won't necessarily be those with the strongest audit reports. They'll be the ones that can detect threats earlier, contain them faster and recover before a cyber incident becomes a business crisis.