TL;DR: A passed audit proves controls existed at a point in time, but SecurityScorecard argues that it does not prove they were still effective when attackers moved, especially as third-party risk and configuration drift continue between review cycles. The practical lesson is that compliance is a baseline, while continuous control validation is what closes the gap between paperwork and real security.
NHIMG editorial — based on content published by SecurityScorecard: Compliance vs security explained
By the numbers:
- 35.5% of breaches now involve a third party, according to SecurityScorecard's 2025 Global Third-Party Breach Report.
- 41.4% of ransomware attacks have a third-party nexus, according to SecurityScorecard's 2025 Global Third-Party Breach Report.
Questions worth separating out
Q: Why can an organisation pass an audit and still be insecure?
A: Because an audit only proves that a control existed when the evidence was collected.
Q: How should teams close the gap between compliance and security?
A: They should connect each compliance requirement to a live operational control, an owner, and a monitoring signal.
Q: What are the signs that compliance is being treated as the finish line?
A: Warning signs include annual evidence scrambles, control testing that happens only before audits, weak post-audit follow-up, and little visibility into vendor or identity drift between reviews.
Practitioner guidance
- Link every audit control to a live owner Assign each compliance requirement to a control owner who also receives operational telemetry, so evidence production and control health are checked together rather than in separate workflows.
- Continuously validate third-party access paths Review vendor accounts, integrations, and delegated permissions on an ongoing basis, with special attention to standing access, expired exceptions, and unused privileged connections.
- Map identity controls to production signals Tie service account rotation, privileged session controls, and access reviews to detection signals that show whether the control is still active in live systems.
What's in the full article
SecurityScorecard's full article covers the operational detail this post intentionally leaves for the source:
- How the vendor distinguishes audit evidence from live security validation in practice
- The control gaps that commonly appear between certification cycles and real-world exposure
- How continuous monitoring changes third-party risk workflows and evidence collection
- Why compliance reporting alone does not capture drift in identity and access controls
👉 Read SecurityScorecard's analysis of why compliance does not equal security →
Compliance vs security: is your audit evidence matching live risk?
Explore further
Compliance drift is the real security gap, not the audit itself. A clean audit proves a control existed on a date, but it says nothing about whether that control survived operational change. In identity-heavy environments, access paths, credentials, and vendor entitlements drift faster than annual attestations can capture. The discipline problem is treating evidence collection as protection. Practitioners should map every control to live enforcement, not just to audit readiness.
A question worth separating out:
Q: Should organisations prioritise continuous monitoring over periodic certification?
A: They should treat certification as necessary but insufficient, then prioritise continuous monitoring for controls that can fail quickly, especially access, identity, and third-party dependencies. Periodic certification still matters for governance, but only live validation shows whether the control is effective when the environment changes after the audit window closes.
👉 Read our full editorial: Compliance vs security: why passing audits can still leave risk