Compliance Alone Won't Protect Your Organisation: Edna Conway on the Real Future of Cyber Risk
A cybersecurity veteran with four decades in the field says ticking regulatory boxes is not the same as being secure. Here is what she means and why it matters.

Key points
- Edna Conway, a cybersecurity leader with over 40 years of experience, argues that meeting compliance rules does not equal genuine security.
- Organisations that treat cyber risk as a box-ticking exercise remain exposed even after passing audits.
- Supply chains, the networks of outside suppliers and software that businesses depend on, represent a growing weak point that compliance frameworks often fail to address.
- The conversation, originally featured by SecurityWeek, carries practical implications for any organisation that stores customer or patient data.
What is the core argument here?
Compliance means following the rules: filling out the right forms, passing the right audits, earning the right certificates. Conway's point is blunt. Following the rules and actually being secure are two different things, and too many organisations confuse them.
After 40 years in the field, including senior roles shaping how large companies think about cyber risk, Conway has watched organisations pass every regulatory test and still suffer serious breaches. A breach is when criminals get into a system they should not reach and either take or lock what they find there.
We covered the same gap on 6 July in "Seven Cyber Risk Assessment Mistakes That Give Security Leaders False Confidence", where experts found that confusing a passed audit with actual security is one of the most common failure modes in the field.
Why does supply chain risk matter to ordinary people?
Most organisations don't operate alone. A hospital buys software from one company, which buys components from another. A retailer connects its payment system to dozens of outside services. Each connection is a potential door.
Some of the biggest breaches in recent years reached their eventual victims not through a direct attack, but through a trusted supplier whose defences were weaker. Compliance frameworks, the official rulebooks that governments and industries produce, rarely keep pace with how these supplier networks actually work. A company can be fully compliant on paper and still have an unexamined supplier quietly passing malicious code, meaning software designed to cause harm, into the chain. Our July piece "Your Vendors Are a Risk You Cannot Ignore" found that most companies can't say what financial damage a vendor failure would actually cost them.
| Factor | Compliance Approach | Risk-Based Approach |
|---|---|---|
| Goal | Meet defined rules | Reduce real-world harm |
| Supplier oversight | Often checkbox-based | Continuous, evidence-driven |
| Pace of change | Slow (rules lag threats) | Adaptive |
| Audit outcome | Pass or fail | Ongoing risk score |
Should you worry about this?
If you're a customer or employee of any organisation, you can't audit their suppliers yourself. What you can do: treat any unexpected message asking for personal details or a password reset with suspicion, even if it appears to come from a company you trust. Criminals who breach a supplier often use stolen data to send convincing fake messages to that supplier's customers.
For anyone running an organisation, Conway's argument points in one direction. Passing the compliance audit is the floor, not the ceiling. Real security means asking hard questions about every system and supplier the organisation depends on, not just the ones the rulebook names.
A certificate of compliance is evidence that rules were followed on a given day. It's not a guarantee that nobody is already inside.



