Using compliance as a tool for change
One of my guiding principles is that compliance does not equal security. Compliance isn’t a true representation of how well companies use security to protect themselves. It can be little more than checking all the boxes and telling the auditors what they want to hear. After all, many compromised banks were PCI-compliant, and several breached healthcare organizations were compliant with HIPAA.