This article is based on an episode from the Cyber & AI Perspectives podcast. Prefer listening instead? Listen to the audio version below.
Today I’ll speak about which one is more important: security or compliance, and if this is perhaps the wrong question to ask.
Compliance and security aren’t competitors. Compliance acts as a booster, a baseline, and a business case for security — driving budget, providing a starting framework, and speaking a language the board understands. It’s a means to security, not a rival to it.
Different people see security differently
You probably think: Of course, security is more important than compliance. Ultimately, everything comes down to reducing security incidents or protecting the confidentiality, integrity, and availability of the data — this is what’s most important.
But if you’re watching or listening to this podcast, then you’re probably a cybersecurity professional, which means that you’re naturally inclined towards security.
If I asked the same question of senior management, they probably wouldn’t put such an emphasis on security; they might say that security and compliance are kind of equally important.
And if I asked this question of legal counsel, or a compliance officer — this one is predictable — they would probably emphasize compliance.
Now, you might think that people who prefer compliance just don’t get it — we’re right and they are wrong. But it’s not that simple — you can’t simply neglect legal advisors, let alone your executives.
Compliance as a booster, a baseline, and a business case
So where does this leave us?
Even though many security professionals do not like compliance, let me give you some clues on how compliance can actually help you. It can serve as a booster, a baseline, and a business case. So, “3 Bs” to make it easier to remember.
What do I mean by booster? This is when you can’t get your cybersecurity budget approved for years, but when cyber becomes obligatory because of some new regulation, then suddenly everything gets approved. Or a potential client requires you to get a new security certificate, and then cybersecurity becomes much more important.
Security standards provide a very good baseline for security — there are numerous standards out there, ranging from management standards like ISO 27001, all the way to technical standards that specify the use of particular security technologies. In other words, these standards give you a useful starting point for almost anything related to security.
Finally, ROI on security is notoriously hard to measure, and that makes it hard to build a business case for the board. But when you show your executives that complying with a particular regulation allows you to avoid penalties, and that implementing standards allows you to reduce liability and even, as I mentioned, increase revenue, then you start finding a language that senior management understands.
Compliance is an enabler; security is a goal
So, to conclude, I do think that security is ultimately more important — but viewing security as something opposed to compliance is wrong. Instead, I think these two have different roles: Compliance should be viewed as an enabler, whereas security should be viewed as an ultimate goal.
So the question of whether security or compliance is more important is the wrong one. The right question is: Are you using compliance to support your security?
If this topic got you interested, there’s a free report worth reading called Compliance and Information Security: How Are They Related? It’s based on a survey of over 600 professionals and adds some real data to what I talked about.
Dejan Kosutic