# The Compliance Trap: Why Checkbox Security Is Making You Less Safe
Forty years ago, Edna Conway was learning to think about risk inside courtrooms and engineering firms. Today, she's watching organizations build elaborate compliance architectures that make them feel secure while leaving them wide open. The gap between those two realities is the story the industry keeps failing to tell honestly.
Conway, whose career spans law, engineering, and now senior cybersecurity leadership roles at firms like Microsoft and Cisco, appeared on the SecurityWeek podcast this week with a message that should be uncomfortable for anyone who's signed off on a SOC 2 report and called it a day: compliance is not security. It never was. And treating it as a proxy for resilience has become one of the most expensive mistakes the industry makes.
## Governance Is What Happens After Compliance Fails
The distinction Conway draws between governance and compliance is worth sitting with. Compliance answers "are we meeting the standard?" Governance answers "are we making the right decisions under uncertainty, including uncertainty about standards we haven't written yet?"
The difference is not semantic. Compliance frameworks are, by definition, backward-looking — they codify what went wrong before, or what regulators could agree on after months of debate. A CMMC certification or a PCI-DSS audit tells you whether your controls matched a snapshot taken two or three years ago. It says almost nothing about whether you'll withstand an attack engineered last month.
What Conway describes as governance is closer to genuine institutional judgment: the capacity to assess novel risk, allocate resources ahead of mandates, and make calls where the framework doesn't provide guidance. Most organizations have one without the other. They have compliance functions that produce documentation and governance committees that rubber-stamp it.
## Supply Chain Is Still the Blind Spot
The supply chain thread running through Conway's work is where her argument gets the most urgent. The SolarWinds breach in 2020 was supposed to be the wakeup call that fixed this. It wasn't. The XZ Utils backdoor in 2024 demonstrated that the same attack surface — trusted software, trusted process, trusted vendor — could be compromised through a years-long social engineering campaign against a single open-source maintainer. No compliance checklist saved anyone.
Conway connects supply chain vulnerability explicitly to geopolitical drift. That framing matters. When companies map their critical software and hardware dependencies, they're often not asking "is this vendor compliant?" — they're asking a question compliance frameworks weren't built to answer: "What happens to my infrastructure if the relationship between two countries changes overnight?"
The answer, for most organizations, is that they don't know. Vendor risk assessments that run off questionnaires and annual reviews are not designed to model that kind of dynamic. Conway's point — that geopolitical shifts require active supply chain resilience strategies, not static audits — is one the industry has been slow to operationalize despite talking about it constantly since 2021.
## AI Doesn't Automate Its Way Past This Problem
It would be easy to read Conway's discussion of AI, blockchain, and quantum computing as standard-issue tech optimism. It isn't. The more interesting thread is the cautionary one: new infrastructure doesn't inherit the problems of old infrastructure, it compounds them.
AI integration at the infrastructure level creates new compliance blind spots faster than frameworks can track them. The model supply chain — training data provenance, model weights, inference endpoints — introduces dependencies that most vendor risk programs weren't designed to assess. Quantum readiness is now a real timeline question for anyone holding long-lived cryptographic material. The organizations spending 2026 debating whether to prioritize post-quantum migration are already behind.
Her workforce argument is less glamorous but probably more actionable in the near term: you cannot upskill fast enough if you start from compliance requirements rather than capability gaps. Training people to pass certifications is not the same as training people to think under adversarial conditions.
## The Collaboration Gap No One Wants to Talk About
Conway is explicit about the need for coordination across government, academia, and private sector — a point so often made it can land as platitude. But there's a harder version of this argument buried in her framing. The organizations that actually share threat intelligence, that participate in ISACs with genuine reciprocity rather than minimum viable disclosure, consistently demonstrate better detection and response outcomes than those that treat threat data as proprietary.
The real barrier isn't technical. It's that sharing information about breaches and near-misses requires admitting vulnerability, which creates legal, regulatory, and reputational exposure in a compliance-first culture. The irony is complete: the compliance posture that was supposed to protect organizations also disincentivizes the collaboration that would actually make them safer.
---
## HackWire Analysis
Conway's thesis isn't new — Bruce Schneier has been making versions of this argument for two decades. What's worth paying attention to is *when* it's gaining traction and *who* is saying it. The fact that a veteran with four decades of credibility across legal, engineering, and security domains is making this case at Black Hat 2026, in the same week as multiple critical zero-days and a $2.4 billion acquisition in the fraud intelligence space, suggests the industry is arriving at a genuine inflection point.
The compliance-first era produced several measurable outcomes, and they're not impressive. The years between 2015 and 2025 saw the largest concentrations of regulatory security requirements in history — GDPR, CMMC, SEC incident disclosure rules, NIS2, state-level privacy laws — and also some of the most damaging supply chain compromises, ransomware incidents, and identity infrastructure failures on record. The correlation is not causal, but it should prompt a real question: what did all that compliance spend actually buy?
Conway's governance framing points toward the answer that security practitioners already know but rarely say in budget meetings: resilience is not a control you implement, it's a capability you develop over time through institutional decision-making, adversarial testing, and genuine accountability for outcomes — not accountability for documentation.
For defenders, the practical implication is to identify one place in the next quarter where you're reporting compliance status when you should be reporting resilience metrics. Patch coverage percentages, audit findings closed — these aren't the same as mean time to detect, blast radius containment, or third-party dependency mapping. Start the conversation with that distinction and see where it goes.
The organizations that weather the next wave of geopolitically-motivated supply chain attacks and AI-amplified intrusion campaigns won't be the ones with the best audit scores. They'll be the ones that knew the difference between governance and compliance before the incident, not after.
— HackWire Editorial
---
## Related Coverage