“We Think the Security Control Is Working” Is No Longer Good Enough
Opinion piece argues CISOs must replace point-in-time, sampling-based audits with continuous control monitoring to prove controls work in real time.
The article contends that annual, sampling-based compliance assessments no longer satisfy boards, customers, and regulators who demand live proof that security controls are working. It cites a 2025 Dell study where 69 percent of IT professionals said leadership overestimates cyber readiness, and notes NIST's 2024 CSF update added a Govern function emphasizing continuous, measurable outcomes. The author advocates continuous control monitoring of identity, cloud configuration drift, vulnerability remediation clocks, and vendor posture, feeding automated evidence into existing GRC systems.
- 69% of IT pros say leadership overestimates cyber readiness (2025 Dell study)
- Point-in-time audits miss configuration drift between audit windows
- Continuous monitoring should tie signals to business risk, reducing noise
- NIST CSF 2024 update added Govern function emphasizing measurable outcomes
Full article1,010 words · extracted from securityweek.com · click to collapse
Security, risk, and control assessments are typically done for the sake of compliance: tools deployed, audits passed, workflows completed, boxes checked. That’s no longer enough for boards, customers, and regulators, who all want an answer to a harder question: ‘can you prove your controls are working right now?’
I often ask CISOs a version of that question, and the honest answer is usually some form of “we think so.” It’s not because they’re careless. Most control checks still happen the way a dentist visit does. When your dentist asks whether you brush and floss every day, you could fib and say yes, but one look at your x-ray tells the real story.
Security works the same way. An annual audit captures what you told the auditor, or what looked true on the day someone checked. But it may not be the ground truth.
There’s a gap between what we believe about our controls and what we can actually verify. That’s where the trouble lives, and it is wider than most teams admit. In a 2025 Dell study, 69 percent of IT professionals said their own leadership overestimates the organization’s readiness for a cyber event. Even the people closest to the controls think the people reporting on them upstairs are too confident. Without live control evidence, no one can check the belief.
Why point-in-time proof keeps failing
A control is not a monument. It is a living thing that drifts. A firewall port opened for a two-week integration may still be open eight months later. A vendor that passed review last year changes a configuration this year. A new system goes live between audit windows. Something can drift out of place the day after an audit closes and stay that way for months, and the only honest thing a CISO can say about it is that the last review looked fine.
You can’t rely on sampling-based assessments
Advertisement. Scroll to continue reading.
Enterprises are constantly changing with digital transformation. New AI risks are stacking on top of existing IT risks, and the enterprise landscape itself grows by double digits every year.
A sampling-based approach, one that inspects only a small slice of that landscape, gives a CISO almost no real confidence, even as they’re under pressure to sign their name to the company’s security and compliance posture in customer attestations, regulatory filings, and contractual commitments. When your signature is the assurance, testing a fraction of the environment cannot stand behind it. High confidence comes from testing everything, continuously.
Continuous control monitoring is how you ‘prove it’
Continuous control monitoring is the way forward. Instead of reconstructing evidence on a calendar, your controls are tested against live data on an ongoing basis, so your risk picture stays current between audits. You lead with the question ‘did anything change in our environment today?’ instead of looking in the rearview mirror.
Practically, that means watching the things that actually drift and hurt if they fail: identity and access, cloud configurations that change by the hour, the remediation clock on critical vulnerabilities, and the posture of the vendors who sit closest to your data.
This does not always mean ripping out the GRC systems a team already runs. Enterprises have spent a significant amount of money and effort in creating their GRC systems of record. The upgrade that they need to implement should be focused on replacing the input into the system of record from manual, point-in-time, sampling-based data with automated continuous comprehensive facts.
The biggest change in strategy is expecting your systems to reflect what is true today, not just store what was true at audit time. More than a purchase, it is a decision that “we think so” is no longer an acceptable answer.
But won’t that just create more noise?
This is the fair objection I hear from CISOs, and the likely reason a lot of teams have stayed put. Their team is already drowning in alerts, so “monitor continuously” sounds like a nightmare.
That gets the goal backwards. Continuous monitoring done well produces less to chase, not more, because every signal is tied to the thing it puts at risk: a contract, a customer commitment, a regulatory obligation. A misconfiguration that touches nothing critical can wait. A control failure that puts mission-critical business at risk cannot.
The value is knowing, at any moment, which things matter, what failure would cost the business, and where to remediate first. The standards bodies have already moved this way. When NIST updated its Cybersecurity Framework in 2024, it added a new Govern function built on a simple premise: cybersecurity is enterprise risk that senior leaders must weigh alongside finance and reputation, and it should be managed against continuous, measurable outcomes rather than a checklist.
What changes when you can prove it
When your security, risk, and compliance posture is always current and improving quarter over quarter, the obvious wins are real: audits stop being fire drills, customer security reviews stop stalling deals, and security leaders actually start looking forward to board meetings.
But the deeper change is harder to see and matters more. A security leader who can only describe the past is, in the end, a historian, valuable, but always reporting on a decision that has already been made. This is the part that rarely shows up on a compliance report. With a live view of the business, of what changed today and what it puts at risk, the security leader becomes one of the few people in the company who can see a risk taking shape while there is still time to act.
That is the version of the security leadership role worth building toward, and it is within reach for teams willing to stop reporting on a calendar. Security has long been measured by effort and by the absence of bad news. The real test is being able to show, on any given day and with proof in hand, that your controls are working right now. That is what produces real resilience, stronger regulatory and contractual standing, and higher customer trust.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.securityweek.com/we-think-the-security-control-is-working-is-no-longer-good-enough/