Close Menu
NCIJ Network NCIJ Network
    What's Hot

    US House panel votes to hold Leon Black in contempt over Epstein subpoena

    September 15, 2026

    The AI data center boom is colliding with cities scarred by big industry 

    September 15, 2026

    Inside NVIDIA’s cuDNN Graph API: Fusion, Autotuning, and Plan Reuse with cuDNN Frontend

    September 15, 2026
    Facebook X (Twitter) Instagram
    Trending
    • US House panel votes to hold Leon Black in contempt over Epstein subpoena
    • The AI data center boom is colliding with cities scarred by big industry 
    • Inside NVIDIA’s cuDNN Graph API: Fusion, Autotuning, and Plan Reuse with cuDNN Frontend
    • “We Think the Security Control Is Working” Is No Longer Good Enough
    • CoinEx quits after 9 years as crypto trading concentrates at biggest exchanges
    • Marine heatwave likely caused sharp decline in Hawaiian humpback whales, study finds
    • Did Trump, Vance skip 9/11 observance in Pennsylvania that was rescheduled so they could attend?
    • Western intelligence warns of Iranian cyber threats targeting dissidents | Cybersecurity News
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, September 15
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    “We Think the Security Control Is Working” Is No Longer Good Enough

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 15, 2026 Cybersecurity No Comments6 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Security, risk, and control assessments are typically done for the sake of compliance: tools deployed, audits passed, workflows completed, boxes checked. That’s no longer enough for boards, customers, and regulators, who all want an answer to a harder question: ‘can you prove your controls are working right now?’

    I often ask CISOs a version of that question, and the honest answer is usually some form of “we think so.” It’s not because they’re careless. Most control checks still happen the way a dentist visit does. When your dentist asks whether you brush and floss every day, you could fib and say yes, but one look at your x-ray tells the real story.

    Security works the same way. An annual audit captures what you told the auditor, or what looked true on the day someone checked. But it may not be the ground truth.

    There’s a gap between what we believe about our controls and what we can actually verify. That’s where the trouble lives, and it is wider than most teams admit. In a 2025 Dell study, 69 percent of IT professionals said their own leadership overestimates the organization’s readiness for a cyber event. Even the people closest to the controls think the people reporting on them upstairs are too confident. Without live control evidence, no one can check the belief.

    Why point-in-time proof keeps failing

    A control is not a monument. It is a living thing that drifts. A firewall port opened for a two-week integration may still be open eight months later. A vendor that passed review last year changes a configuration this year. A new system goes live between audit windows. Something can drift out of place the day after an audit closes and stay that way for months, and the only honest thing a CISO can say about it is that the last review looked fine.

    You can’t rely on sampling-based assessments

    Advertisement. Scroll to continue reading.

    Enterprises are constantly changing with digital transformation. New AI risks are stacking on top of existing IT risks, and the enterprise landscape itself grows by double digits every year.

    A sampling-based approach, one that inspects only a small slice of that landscape, gives a CISO almost no real confidence, even as they’re under pressure to sign their name to the company’s security and compliance posture in customer attestations, regulatory filings, and contractual commitments. When your signature is the assurance, testing a fraction of the environment cannot stand behind it. High confidence comes from testing everything, continuously.

    Continuous control monitoring is how you ‘prove it’

    Continuous control monitoring is the way forward. Instead of reconstructing evidence on a calendar, your controls are tested against live data on an ongoing basis, so your risk picture stays current between audits. You lead with the question ‘did anything change in our environment today?’ instead of looking in the rearview mirror.

    Practically, that means watching the things that actually drift and hurt if they fail: identity and access, cloud configurations that change by the hour, the remediation clock on critical vulnerabilities, and the posture of the vendors who sit closest to your data.

    This does not always mean ripping out the GRC systems a team already runs. Enterprises have spent a significant amount of money and effort in creating their GRC systems of record. The upgrade that they need to implement should be focused on replacing the input into the system of record from manual, point-in-time, sampling-based data with automated continuous comprehensive facts.

    The biggest change in strategy is expecting your systems to reflect what is true today, not just store what was true at audit time. More than a purchase, it is a decision that “we think so” is no longer an acceptable answer.

    But won’t that just create more noise?

    This is the fair objection I hear from CISOs, and the likely reason a lot of teams have stayed put. Their team is already drowning in alerts, so “monitor continuously” sounds like a nightmare.

    That gets the goal backwards. Continuous monitoring done well produces less to chase, not more, because every signal is tied to the thing it puts at risk: a contract, a customer commitment, a regulatory obligation. A misconfiguration that touches nothing critical can wait. A control failure that puts mission-critical business at risk cannot.

    The value is knowing, at any moment, which things matter, what failure would cost the business, and where to remediate first. The standards bodies have already moved this way. When NIST updated its Cybersecurity Framework in 2024, it added a new Govern function built on a simple premise: cybersecurity is enterprise risk that senior leaders must weigh alongside finance and reputation, and it should be managed against continuous, measurable outcomes rather than a checklist.

    What changes when you can prove it

    When your security, risk, and compliance posture is always current and improving quarter over quarter, the obvious wins are real: audits stop being fire drills, customer security reviews stop stalling deals, and security leaders actually start looking forward to board meetings.

    But the deeper change is harder to see and matters more. A security leader who can only describe the past is, in the end, a historian, valuable, but always reporting on a decision that has already been made. This is the part that rarely shows up on a compliance report. With a live view of the business, of what changed today and what it puts at risk, the security leader becomes one of the few people in the company who can see a risk taking shape while there is still time to act.

    That is the version of the security leadership role worth building toward, and it is within reach for teams willing to stop reporting on a calendar. Security has long been measured by effort and by the absence of bad news. The real test is being able to show, on any given day and with proof in hand, that your controls are working right now. That is what produces real resilience, stronger regulatory and contractual standing, and higher customer trust.

    control good longer Security working
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

    British bosses to be forced to meet with employees who request flexible working | Employment law

    What Zero-Day Response Should Be in the Post-Mythos Era

    KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

    This doorbell camera lets a human security guard watch your front door

    Hackers target WordPress sites via third-party WooCommerce plugin

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    US House panel votes to hold Leon Black in contempt over Epstein subpoena

    September 15, 2026

    The AI data center boom is colliding with cities scarred by big industry 

    September 15, 2026

    Inside NVIDIA’s cuDNN Graph API: Fusion, Autotuning, and Plan Reuse with cuDNN Frontend

    September 15, 2026

    “We Think the Security Control Is Working” Is No Longer Good Enough

    September 15, 2026
    Latest Posts

    Two new compounds could reveal hidden drivers of Alzheimer’s disease

    August 4, 2026

    Marmot Researchers Turn to OnlyFans for Funding—And There Are Meme Coins Too

    August 4, 2026

    New Pass-ta-key attacks let malware hijack Google-synced passkeys

    August 4, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    US House panel votes to hold Leon Black in contempt over Epstein subpoena

    September 15, 2026

    The AI data center boom is colliding with cities scarred by big industry 

    September 15, 2026

    Inside NVIDIA’s cuDNN Graph API: Fusion, Autotuning, and Plan Reuse with cuDNN Frontend

    September 15, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.