ITSecurityGuru

Why compliance does not guarantee cyber resilience


Cyber security has become one of the most audited and regulated areas of enterprise technology. Yet an organisation can satisfy every requirement on paper and still discover, during a real incident, that its systems, people or processes are not ready for the pressure that follows. Compliance can demonstrate that controls have been put in place; it cannot, on its own, demonstrate that those controls will continue to work when a critical service is disrupted. Here, Nathan Charles, head of customer experience at cyber resilience specialist OryxAlign, explains why organisations need to look beyond compliance and test whether their resilience claims stand up in practice.

Organisations invest significant time and resource into achieving certifications such as ISO 27001 and Cyber Essentials, while regulated firms face additional obligations under frameworks such as the Financial Conduct Authority (FCA) and Prudential Regulation Authority (PRA) operational resilience rules. These frameworks provide valuable structure and demonstrate a credible baseline of security maturity.

Compliance frameworks like these set a recognised baseline, create accountability and give boards and customers a way to benchmark security maturity. The risk lies in what happens post-certification.

For many organisations, passing an audit becomes the objective in itself, rather than a step towards genuine resilience. Certification and self-assessment exercises capture a snapshot of security controls at a single point in time, under conditions that are largely predictable. They rarely test what happens when those controls are placed under real pressure, such as a ransomware attack that spreads faster than the incident response plan anticipated, a misconfigured update that takes core systems offline, or a supplier outage with knock-on effects nobody had mapped. 

When the paperwork doesn’t match reality

The gap between documented compliance and operational reality is well evidenced. The UK Government’s Cyber Security Breaches Survey 2025/2026 found that 43 per cent of UK businesses reported experiencing a cyber security breach or attack in the past twelve months. This is despite most organisations already having basic technical measures, such as malware protection, firewalls and access controls, in place.

The financial services sector, where operational resilience obligations are most mature, illustrates the same gap. In March 2026, the FCA published its first detailed review of how firms had performed since the transition period for its operational resilience rules ended in March 2025. The review examined whether firms had genuinely embedded resilience into daily operations, or whether their self-assessments amounted to little more than a paperwork exercise.

This distinction matters because resilience is ultimately about outcomes rather than the existence of controls. An organisation may have an incident response plan, supplier assessments and documented recovery procedures, but that does not necessarily mean the right people know what to do when a critical service fails. It may also be unclear how one disruption affects another system, supplier or business process. These dependencies can be difficult to identify through conventional compliance exercises because they only become visible when the organisation is placed under stress.

In other words, an organisation can produce all the required documentation and still be unable to demonstrate that its most critical services would survive a severe but plausible disruption. The challenge is moving from asking whether a control exists to asking whether it delivers the intended outcomes when it matters most. 

Regulators are recognising the gap too

Encouragingly, this is not a case of compliance frameworks being wrong; it reflects how regulators and standard-setters are actively evolving what they expect organisations to demonstrate. The National Cyber Security Centre (NCSC) has developed its Principles Based Assurance approach specifically to move away from assessment against fixed, compliance-driven control sets, in favour of a risk-based approach.

The FCA has followed a similar trajectory, shifting its supervisory focus from asking firms whether they have identified their important business services, to asking whether they can prove they remain within agreed impact tolerances today, through tested evidence rather than policy documents.

Similar principles underpin the EU’s Digital Operational Resilience Act, which requires financial entities to test their resilience through scenario-based exercises rather than rely on point-in-time compliance reviews. Across sectors and geographies, there is a consistent direction of travel where demonstrated resilience, not paperwork, is the real measure of readiness.

This shift is important because it changes the question organisations need to ask themselves. Rather than viewing resilience as something demonstrated during an audit, it should be treated as an ongoing capability that needs to be evidenced throughout the year. A successful assessment should therefore be viewed as a starting point for further testing, rather than confirmation that the organisation is resilient. 

From checklist to stress test

For organisations that want to close this gap, the starting point is treating resilience as something that is tested and proven, not assumed because a framework has been satisfied. That means running scenario-based exercises that simulate severe but plausible disruption, such as the loss of a critical supplier, a ransomware incident or a major cloud outage, and observing how systems, teams and decision-making actually hold up under pressure.

The value of these exercises is not just about identifying whether an organisation can recover. They can expose assumptions that have gone unchallenged, reveal dependencies between critical services and show where responsibilities become unclear during an incident. They can also provide evidence for whether recovery objectives are realistic and whether teams have the information they need to make effective decisions when normal processes are no longer available.

Crucially, testing should not be treated as another compliance exercise. If an exercise only seeks to demonstrate that an existing plan works, there is a risk that organisations will overlook the weaknesses the exercise is intended to uncover. Instead, scenarios should be designed to challenge assumptions and provide an honest assessment of how systems, people and processes perform under pressure.

Compliance frameworks and regulatory obligations remain an essential part of managing cyber risk, and organisations should not disregard them. But they represent a floor, not a ceiling. Genuine operational resilience is proven under pressure, not certified on paper.

Organisations that build a culture of continuous testing, honest assumption-challenging and cross-functional ownership will be far better placed to keep critical services running when, not if, disruption occurs. The objective should not be to abandon compliance, but to use it as the foundation for a broader approach in which resilience is continually tested, evidenced and improved. 

To learn how OryxAlign helps organisations map digital dependencies and strengthen operational resilience, visit www.oryxalign.com.



Source link