Trending Topics

Lessons from the boardroom: How CISOs should approach compliance
This article is part of our Opinions section, where we invite industry professionals to share their views on the most pressing technology questions of our time.
There’s a persistent misconception that compliance is the end goal. I’ve heard it often with customers and among executive teams, but this is faulty logic. Compliance is a signal, not a goal; it’s a way to communicate risk posture at scale to customers, stakeholders, and regulators. Compliance is an evolving journey intended to support the Board of Directors.
After years of sitting on both sides of the table – buying, selling, defending, and scrutinising security programs – it’s become increasingly clear that the way CISOs approach compliance needs to evolve. Not just to satisfy auditors, but to meet the expectations of customers, executives, and boards.
Start where it actually matters
When reviewing an audit report, don’t start with the controls. Instead, start with scope and findings. Why? Because everything else is secondary.
Scope tells a CISO whether the report is even relevant. If you’ve scoped your audit in a way that excludes critical parts of the service customers are leveraging—identity systems, sensitive data flows, anything touching PII or regulated data—that’s not a minor detail, that’s the whole story.
Findings, on the other hand, paint a picture of how transparent and mature your program is. A mature organisation will have findings, technical debt, and legacy systems. What auditors are looking for is whether you can acknowledge the issue, understand the risk and have a credible plan to address it – not that these things don’t exist. If your response is “we didn’t think it was important,” that’s not a finding problem; that’s a leadership problem. And in many cases, it’s a deal-breaker.
Compliance is a risk conversation, and your response is the proof
Too many organisations still treat compliance like a pass/fail exercise. That’s not how experienced CISOs or informed boards approach it. Audit reports are not endpoints; they’re starting points for a deeper conversation about risk.
When something appears out of scope, the right response isn’t to immediately walk away or flag it as a failure. It’s to lean in and ask better questions. What exactly is the gap? Why does it exist? And most importantly, what risk does that gap introduce to the business or to the customer? The ability to stay in that nuance, to seek understanding instead of reacting to surface-level signals, is what separates a compliance mindset from a true risk mindset. At the board level, especially, the expectation isn’t perfection, it’s clarity. Leaders want to know that you understand where your risks are, why they exist, and how they’re being managed.
That’s why one of the most telling parts of any audit report isn’t the finding itself, it’s the management response that follows it.
Findings, in and of themselves, are not disqualifying. In fact, in many cases, they’re expected. Any organisation that’s been operating at scale for a meaningful period of time may carry some level of technical debt or operational complexity. What matters is how that reality is acknowledged and addressed. The management response is where an organisation demonstrates whether its program is grounded and operational or simply performative.
A strong response doesn’t hide behind overly polished language or legal framing. It is clear about the issue, direct about ownership, and realistic about what will be done to address it. It shows that the organisation understands the problem and has a credible, actionable path forward.
Let’s take insufficient log retention for sensitive data as an example. One way to respond to questions around this is: “We didn’t retain logs beyond 30 days during the audit period. Here’s the gap, here’s why it existed, and here’s the specific control we’ve put in place to address it going forward.” A less optimal response sounds a bit more like: “log retention isn’t something we’ve prioritised at this stage.”
The first response closes the conversation in the best possible way, with trust established, stakeholders satisfied, and the deal moves forward. The second doesn’t just raise a technical concern; it signals a cultural one. It tells the reviewer that the organisation either doesn’t understand the risk or doesn’t care about it.
When a strong response is present, stakeholders can move forward with confidence that an organisation truly understands its environment.
Navigate to “Yes”, but know when to say “No”
There’s an art to compliance conversations, especially with customers or board members. It’s all too easy to become a “yes” in these high-pressure rooms, and while my philosophy is that you should always try to navigate to a “yes,” there are going to be instances where you have to draw a hard line.
If a request violates your data classification policy or introduces real risk, it’s ok to say “no” but offer an alternative. A good CISO will be flexible where it makes sense, offering alternatives like screen shares instead of sharing sensitive artefacts, and explaining their rationale in a way that brings the stakeholders along.
When “no” is the reasonable answer, and you’re consistent, it often builds credibility. Over time, these stakeholders learn that when you say “no,” there’s a good reason behind it.
Understand the purpose of compliance artefacts
Take SOC 2 Type II as an example. The entire point of that report is to reduce the need for bespoke, granular questionnaires. So when customers ask for raw evidence, internal plans, or sensitive documentation on top of a SOC 2, it often signals a misunderstanding of what the report is designed to do.
Your job as a CISO isn’t to blindly comply with every request. It’s to educate stakeholders, protect sensitive information and provide assurance in a controlled, appropriate way. Sometimes that means compromise in the shape of walkthroughs or controlled demonstrations, but it should never mean overexposure.
Shift the conversation: from compliance to resiliency
Boards today are increasingly less interested in which certifications you have or how many controls you’ve implemented. Instead, they are interested in your ability to answer one (not so simple) question: Is your organisation resilient?
Resiliency is outcome-focused, and truly resilient organisations can do things like recover from an incident while continuing operations and protect their customer experience even under stress. It’s no longer enough to say your data is backed up – boards and customers alike expect more.
Think about what that actually means in practice. If you suffer a ransomware event, can you restore encrypted data from clean backups? Can you rebuild the environment from scratch — dependencies, configurations, integrations — while the business keeps running? Can you protect the customer experience while your team is in full incident response mode? Those aren’t hypothetical questions. Boards are starting to ask them directly, and “we have backups” is no longer a sufficient answer.
Executives need to be able to demonstrate a consistent ability to restore that data, build the environment, reconnect dependencies, and actually run the business.
The board doesn’t care how much you spent on tools. They care whether your program protects the confidentiality, integrity, and availability of what matters. Compliance is table stakes. What differentiates strong CISOs, especially in front of boards, is the ability to translate compliance into risk, resilience, and business impact. If your program can do that, the reports take care of themselves. If it can’t, no amount of certifications will save you.
