Organizations have realized greater profits by doing business online for decades. Doing business online comes with the cost of operating in a landscape where threat actors exist. Those threat actors also keep improving their ability to profit, thrive, and achieve their objectives at your expense. The cost of a data breach has risen in the US to 10.22 million, and it’s been reported that Cybercrime (Yes, cyber- we lost this battle; general audiences identify it as cyber) has surged past a trillion dollars. Yet some companies still claim that they don’t have the resources or money to do security beyond compliance.
compliance is just compliance
There is nothing wrong with compliance. People bash it for not being “security,” but it was never meant to be security. It’s a set of policies and criteria required to meet a minimum bar to do business with certain customers. Its function directly correlates with the business’s ability to make more money. I can fully understand why companies emphasize this work over other types of security work. However, it is not a risk-reduction function.
Risk reduction is what you’re missing
What most companies miss is evaluating their organization through the lens of risk reduction and taking appropriate action to avoid breach-related loss. Losses vary and should be identified and addressed based on your circumstances (e.g., most companies don’t necessarily need a Red Team). Compliance alone does not reduce risk because compliance requirements are not meant to serve this purpose. However, most organizations do the bare minimum because it ties directly to making or not making more money.
“Always remember, compliance is important, but true security requires going beyond what’s mandated to effectively mitigate risk and stay ahead of the threat landscape – pg 10
Ross Young (2025)
Cybersecurity’s Dirty Secret: Why Most Budgets Go to Waste
You’re choosing to be a sitting duck
I want to be very clear: if you’re only doing compliance, you’re choosing to do almost nothing. This choice leaves you at the mercy of online threats, shows you don’t care about your customers’ data, and, to put it plainly, is negligent. This shift didn’t happen yesterday; in fact, choosing to do this for so long has led to a recent 2:1 advantage for adversaries yet again. Not to mention, many decades of breaches have shown us through experience that it’s a losing strategy. Your excuse about resources, money, or it being an *cough* APT is no longer acceptable. You’re responsible for making investments that reduce risk appropriately for your business…or you’re intentionally choosing to be a sitting duck 🦆.