Compliance Alone Won't Protect Your Organisation: Edna Conway on the Real Future of Cyber Risk
A cybersecurity veteran with four decades in the field says ticking regulatory boxes is not the same as being secure. Here is what she means, and why it matters to everyone.

Key points
- Edna Conway, a cybersecurity and supply-chain resilience expert with over 40 years of experience, argues that meeting compliance rules does not equal genuine security.
- Organisations that treat cyber risk as a box-ticking exercise remain exposed even after passing audits.
- Supply chains (the networks of outside suppliers and software that businesses depend on) represent a growing weak point that compliance frameworks often fail to address.
- The conversation, originally featured by SecurityWeek, carries practical implications for any organisation that stores customer or patient data.
What is the core argument here?
Compliance means following the rules: filling out the right forms, passing the right audits, earning the right certificates. Conway's point is blunt: following the rules and actually being secure are two different things, and too many organisations confuse them.
After 40 years in the field, including senior roles shaping how large companies think about cyber risk, Conway has watched organisations pass every regulatory test and still suffer serious breaches. A breach, in plain terms, is when criminals get into a system they should not be able to reach and take, alter, or lock what they find there.
Why does supply chain risk matter to ordinary people?
It matters because most organisations do not operate alone. A hospital buys software from one company, which buys components from another. A retailer connects its payment system to a dozen outside services. Each of those connections is a potential door.
Conway's career has focused on what happens when criminals walk through one of those side doors rather than trying to force the front one. Some of the biggest breaches in recent years reached their eventual victims not through a direct attack, but through a trusted supplier whose security was weaker.
Compliance frameworks (the official rulebooks that governments and industries produce) rarely keep pace with how these supplier networks actually work. A company can be fully compliant on paper and still have an unexamined supplier quietly passing malicious code, meaning software designed to cause harm, into the chain.
| Factor | Compliance Approach | Risk-Based Approach |
|---|---|---|
| Goal | Meet defined rules | Reduce real-world harm |
| Supplier oversight | Often checkbox-based | Continuous, evidence-driven |
| Pace of change | Slow (rules lag threats) | Adaptive |
| Audit outcome | Pass or fail | Ongoing risk score |
What should ordinary people actually do?
If you are a customer, patient, or employee of any organisation, you cannot audit their suppliers yourself. What you can do: treat any unexpected email asking for personal details or a password reset with suspicion, even if it appears to come from a company you trust. Criminals who breach a supplier often use stolen information to send convincing fake messages to that supplier's customers.
For anyone running or working inside an organisation, Conway's argument points in one clear direction. Passing the compliance audit is the floor, not the ceiling. Real security requires asking harder questions about every system and supplier the organisation depends on, not just the ones the rulebook requires you to examine.
The conversation is a useful reminder that a certificate of compliance is evidence that rules were followed on a given day. It is not a guarantee that nobody is already inside.



