Breaking
SecurityDeveloping Story

Boards Want Proof Controls Work Now

A CISO argues that point-in-time audits no longer satisfy boards, regulators, and customers who want live proof that security controls are functioning.

··2 hours ago·4 min read
Four professionals in a business meeting around a table
Photo by Vitaly Gariev on Unsplash

Security assessments have traditionally been about compliance, not confidence. But the gap between what a security team believes about its controls and what it can actually demonstrate on any given day is where real risk hides.

In an opinion column written for SecurityWeek, Sravish Sridhar, founder and CEO of TrustCloud, lays out the case that annual audits and sampling-based checks are no longer sufficient for boards, customers, or regulators. He argues that continuous control monitoring is the way to close the gap between belief and verification.

Compliance Theater Meets Hard Questions

Sridhar opens with a dentist analogy: a patient can claim to brush and floss daily, but an x-ray reveals the truth. Security works the same way, he writes, noting that an annual audit captures what was told to the auditor or what looked true on the day someone checked, but it may not reflect ground truth.

He points to a 2025 Dell study in which 69 percent of IT professionals said their own leadership overestimates the organization's readiness for a cyber event. The finding suggests that even people closest to the controls believe those reporting upward are too confident.

The harder question from boards, customers, and regulators is simple: can you prove your controls are working right now? Sridhar says that when he asks CISOs that question, the honest answer is usually some form of "we think so."

Why Point-in-Time Proof Keeps Failing

The problem is that controls are not static. Sridhar describes a control as a living thing that drifts, not a monument. He offers examples: a firewall port opened for a two-week integration may still be open eight months later; a vendor that passed review last year changes a configuration this year; a new system goes live between audit windows.

Something can drift out of place the day after an audit closes and stay that way for months, leaving the CISO able to say only that the last review looked fine. Sampling-based assessments, which inspect only a small slice of the environment, cannot give real confidence.

Enterprises are constantly changing, Sridhar writes, and new AI risks are stacking on top of existing IT risks while the enterprise landscape itself grows by double digits every year. Yet security leaders are under pressure to sign their names to the company's security and compliance posture in customer attestations, regulatory filings, and contractual commitments.

Continuous Monitoring as the Answer

Sridhar says continuous control monitoring is the way forward. Instead of reconstructing evidence on a calendar, controls are tested against live data on an ongoing basis, keeping the risk picture current between audits. The leading question shifts from backward-looking to forward-looking, he writes: did anything change in our environment today?

Practically, that means watching the things that actually drift and hurt if they fail. In the source article, Sridhar lists these as identity and access, cloud configurations that change by the hour, the remediation clock on critical vulnerabilities, and the posture of the vendors who sit closest to your data.

He notes that this does not always mean ripping out existing GRC systems, which enterprises have spent significant money and effort creating. The upgrade should focus on replacing the input into the system of record from manual, point-in-time, sampling-based data with automated continuous comprehensive facts.

The Noise Objection, Addressed

Sridhar acknowledges the fair objection he hears from CISOs: teams are already drowning in alerts, so "monitor continuously" sounds like a nightmare. He argues that gets the goal backwards.

Continuous monitoring done well produces less to chase, not more, because every signal is tied to the thing it puts at risk: a contract, a customer commitment, a regulatory obligation. A misconfiguration that touches nothing critical can wait. A control failure that puts mission-critical business at risk cannot.

He points to standards bodies moving in this direction. When NIST updated its Cybersecurity Framework in 2024, it added a new Govern function. Sridhar describes its premise as cybersecurity being enterprise risk that senior leaders must weigh alongside finance and reputation, managed against continuous, measurable outcomes rather than a checklist.

What Changes When Proof Exists

The obvious wins, Sridhar writes, are real: audits stop being fire drills, customer security reviews stop stalling deals, and security leaders start looking forward to board meetings.

But he argues the deeper change matters more. A security leader who can only describe the past is a historian, valuable but always reporting on a decision that has already been made. With a live view of the business, of what changed today and what it puts at risk, the security leader becomes one of the few people in the company who can see a risk taking shape while there is still time to act.

The Push to Stop Reporting on a Calendar

Sridhar closes the column by stating that security has long been measured by effort and by the absence of bad news. The real test, he writes, is being able to show, on any given day and with proof in hand, that controls are working right now.

That, he says, is what produces real resilience, stronger regulatory and contractual standing, and higher customer trust.

Why This Matters Beyond the Column

For CISOs and security leaders, the argument suggests that the days of relying on annual audits and compliance checkboxes may be numbered. If boards and regulators begin demanding live evidence, organizations that can only produce point-in-time snapshots could face harder conversations, or worse, a false sense of readiness that leaves them exposed when a real incident occurs.

Customers, too, may start asking tougher questions during due diligence, expecting proof rather than assurances. Sridhar's piece is a reminder that the gap between belief and verification is not just an academic concern, but one that could shape how security budgets, board relationships, and even contractual terms are negotiated in the months and years ahead.

#compliance#ciso#continuous-monitoring#security-leadership#nist

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories