Skip to main content
Skip to content

article

Compliance can make systems less safe

When passing the audit becomes the objective, teams optimise evidence while operational risk moves elsewhere.

Emil Shirokikh · Published September 2, 2026 · Updated September 23, 2026 · 2 min read

Infrastructure, reliability and security engineering environment

Abstract

Controls written for general comparability may not match a specific threat model. Checkbox compliance can consume attention that should go to exposed paths and recovery.

Map controls to threats

Audit evidence can become the goal while unmodeled attack paths remain. A framework is a useful floor, not a complete threat model.

Control review

For each required control, name the threat and evidence. Record uncovered threats, compensating controls, control failures and operational tests outside the framework.

Acceptance evidence

Review whether evidence generation consumes attention without reducing exposure.

Challenge the conclusion

External standards create valuable discipline and common language. They remain a floor, not a complete security strategy.

Use this in a working session

Pick the most expensive control and ask which plausible attack it changes, how failure is detected and what residual risk remains.

BELTO editorial analysis. It does not describe a client engagement or claim a commercial result.

Author

Emil Shirokikh

Founder

Founder of Belto Inc. Writes on engineering, venture building and applied intelligence.