Trending Topics

Chris Newton-Smith, CEO of IO: “Regulations are rarely applied in exactly the same way across different organisations”
For many organisations, compliance has become a race to the finish line. Whether driven by procurement demands, customer expectations or regulatory pressures, businesses are under increasing pressure to achieve certifications such as ISO 27001 as quickly as possible. But as automation and AI promise to accelerate compliance programmes, an important question is emerging: does faster certification actually make organisations more secure?
New research from business resilience platform IO suggests many cybersecurity leaders have their doubts. According to the company’s findings, 87% of UK cybersecurity managers believe the speed at which compliance certifications are achieved affects their credibility, while many argue that continuous monitoring and human expertise remain essential to building genuine resilience rather than simply passing an audit.
Chris Newton-Smith, CEO of IO, believes organisations need to rethink their relationship with compliance. Rather than viewing certification as the destination, he argues businesses should treat it as the outcome of an ongoing governance programme that evolves alongside emerging threats, changing regulations and advances in AI.
In this interview with TechFinitive, Newton-Smith discusses why the pursuit of rapid certification can create a false sense of security, where automation adds genuine value to compliance, why human judgement remains indispensable, and how organisations can build governance models that keep pace with an increasingly complex regulatory landscape.
Your research found that 87% of cybersecurity managers believe the speed at which compliance certifications are achieved affects their credibility. How did the industry reach a point where compliance became something organisations expect to achieve as quickly as possible?
Over time, compliance has increasingly become linked to commercial requirements. Certifications are often needed to access new contracts, satisfy procurement requirements and demonstrate a baseline level of security assurance to customers and partners. As a result, many organisations have understandably focused on how quickly they can achieve certification rather than what the certification is intended to represent.
Technology has also played a role. The growth of automated compliance platforms and accelerated implementation services has created an expectation that certification can be achieved rapidly. The concern is not that speed is inherently the wrong approach. It is that compliance done fast, compressed, automated end-to-end, stripped of rigour, doesn’t deliver what compliance is actually for. It delivers a certificate. It doesn’t deliver a business that can handle what comes next.
Rapid certification can result in organisations implementing policies and controls quickly enough to satisfy an audit, but without enough time for those controls to become part of day-to-day operations. Staff may not fully understand them, ownership may be unclear and processes may not be consistently followed across the business. As a result, those organisations that focus on achieving certification as quickly as possible are at risk of leaving gaps in their security posture.
Many businesses still view compliance as a destination rather than an ongoing discipline. What are the biggest risks organisations face when they treat certification as a tick-box exercise?
The biggest risk is developing a false sense of security. A certificate demonstrates that controls existed and were assessed at a particular point in time, but threats, business operations and regulatory requirements continue to evolve.
Achieving certification quickly can limit opportunities to demonstrate that controls are operating effectively over time. Incident response plans, access management processes and risk management procedures may have been documented but not exercised, challenged or refined.
Our research suggests cybersecurity managers recognise this. Continuous monitoring of controls was identified as one of the strongest indicators of business resilience with nearly a third of those surveyed (31%) citing this. Organisations that focus only on passing an audit may miss opportunities to identify weaknesses, respond to emerging risks and strengthen governance as their risk position changes and the environment they operate in evolves. Ultimately, they risk being compliant on paper while remaining vulnerable operationally and this could therefore fail when relied upon during a real incident.
Automation and AI are increasingly being applied to compliance processes. Where do you see the line between automation that improves resilience and automation that simply accelerates paperwork?
Automation delivers real value when it helps organisations maintain visibility, accelerate evidence gathering and compliance workflows, and efficiently identify issues that require attention.
The line is crossed when automation is used solely to accelerate documentation and certification activity without improving understanding or oversight. If technology simply generates policies, collects evidence and moves organisations through an audit process faster, it may reduce administrative effort, but it does not necessarily improve security or resilience of a business. This is because automated outputs can only assess what they are configured to measure and may miss context-specific risks. The risk is that organisations gain confidence from compliance evidence that does not fully reflect operational reality.
Effective compliance requires organisations to understand their risks, own their controls and continuously improve them. Technology should support that objective rather than replace it.
The research highlights the continuing importance of human expertise in evaluating controls and interpreting regulations. As AI capabilities improve, which parts of compliance do you believe will always require human judgment?
Yes, 45% of respondents to our research believe that human expertise is still essential when evaluating whether the suggested automated compliance processes and actions are relevant or accurate, with 33% saying human expertise is needed to interpret complex regulations. A further 32% said human expertise is key to challenging the credibility or completeness of automated compliance evidence.
Human judgment remains critical wherever context, interpretation and accountability are involved. Regulations are rarely applied in exactly the same way across different organisations. Understanding how requirements relate to a specific business model, risk profile or operational environment requires experience and professional judgement.
Humans are also essential when assessing whether controls are genuinely effective in practice rather than simply documented. They are needed to challenge assumptions, identify gaps, evaluate the credibility of evidence and make decisions. AI will continue to improve efficiency and support analysis, but accountability for governance, risk acceptance, identifying where an organisation’s documented compliance posture may not fully reflect its day-to-day operational resilience, and regulatory interpretation will remain fundamentally human responsibilities.
Organisations today face a growing mix of requirements spanning cybersecurity, privacy, AI governance, regulations such as NIS2, DORA and other operational frameworks. How can businesses build a governance model that keeps pace with regulatory change without creating excessive complexity?
The key is to build governance around core business processes and risk management principles rather than treating every new regulation as a separate project. Many frameworks share common themes such as accountability, risk assessment, control monitoring, incident management and continual improvement.
Organisations that establish strong foundational governance can often map new requirements onto existing controls rather than starting from scratch each time a regulation emerges. Named accountability, continuous monitoring, regular review cycles and integrated management systems help businesses absorb regulatory change more efficiently. The goal should be to create a governance capability that evolves over time rather than a collection of disconnected compliance initiatives.
Similarly, creating a resilience loop that connects information security, data protection and AI compliance will help organisations to withstand disruption and continue operating while adapting to evolving threats, allowing them to recover effectively.
Looking ahead, do you think procurement teams, customers and regulators will become less interested in whether a company holds a certification and more interested in evidence that compliance is embedded into day-to-day operations?
Certification will remain important because it provides independent assurance and a recognised benchmark. However, we are already seeing growing interest in how organisations maintain compliance between audits and how effectively controls operate in practice.
Procurement teams, customers and regulators increasingly want confidence that compliance is embedded into day-to-day decision-making, governance and operational processes. They are looking beyond the certificate itself and asking questions about monitoring, accountability, continuous improvement and resilience. Organisations that can demonstrate live, integrated governance and provide evidence of ongoing control effectiveness are likely to be better positioned to build trust and differentiate themselves. In that sense, certification is becoming part of the story rather than the entire story.
