惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

大猫的无限游戏
大猫的无限游戏
S
SegmentFault 最新的问题
量子位
A
Arctic Wolf
L
Lohrmann on Cybersecurity
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
WordPress大学
WordPress大学
V
Vulnerabilities – Threatpost
博客园 - Franky
C
Cyber Attacks, Cyber Crime and Cyber Security
The Cloudflare Blog
Last Week in AI
Last Week in AI
The Hacker News
The Hacker News
I
Intezer
J
Java Code Geeks
P
Privacy International News Feed
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
S
Secure Thoughts
Cisco Talos Blog
Cisco Talos Blog
阮一峰的网络日志
阮一峰的网络日志
S
Securelist
Security Latest
Security Latest
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
小众软件
小众软件
Jina AI
Jina AI
有赞技术团队
有赞技术团队
人人都是产品经理
人人都是产品经理
博客园_首页
酷 壳 – CoolShell
酷 壳 – CoolShell
T
The Exploit Database - CXSecurity.com
雷峰网
雷峰网
T
Tenable Blog
www.infosecurity-magazine.com
www.infosecurity-magazine.com
P
Privacy & Cybersecurity Law Blog
Simon Willison's Weblog
Simon Willison's Weblog
博客园 - 【当耐特】
T
Threat Research - Cisco Blogs
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
MongoDB | Blog
MongoDB | Blog
D
DataBreaches.Net
N
News | PayPal Newsroom
Google Online Security Blog
Google Online Security Blog
K
Kaspersky official blog
H
Help Net Security
宝玉的分享
宝玉的分享
罗磊的独立博客
Webroot Blog
Webroot Blog
月光博客
月光博客
B
Blog RSS Feed
Recorded Future
Recorded Future

Forbes - Innovation

Why Do Humans Have Fingerprints? Hint: It’s Not What You Think Booking.com Confirms Data Breach, Reservation PIN Codes Changed Why Major News Sites Are Blocking The Internet Archive’s Wayback Machine iPhone Fold Release Date: New Report Details Frustrating Apple News Comet Tracker: How To See Pan-STARRS And Three Planets On Wednesday NYT Mini Crossword Today: Tuesday, April 14 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Tuesday, April 14 (It’s A Little Unclear) Today’s Wordle #1760 Hints And Answer For Tuesday, April 14 Most Of The Microplastics In Urban Air Come From Tires Today’s Wordle #1759 Hints And Answer For Monday, April 13 NYT Mini Crossword Today: Monday, April 13 Hints And Answers NYT Pips Today: Hints, Answers And Walkthrough For Monday, April 13 The YC Chief Who Codes 10,000 Lines A Day Has A Simple Secret Samsung Expands One UI 8.5 Beta To More Galaxy Owners Why You Should Stop Using Your iPhone If It’s On This List Chamath Says Firms That Treat AI As A Strategy Hand Rivals Their Edge 3 Unexpected Habits Of Secure Couples, By A Psychologist The First Lamp That Folds Your Clothes Samsung’s Disappointing Price Update For Galaxy Phone Buyers 3 Subtle Signs Someone Is Falling In Love With You, By A Psychologist Do Mantis Shrimp See More Colors Than Humans? A Biologist Explains NYT Connections Answers Explained For Monday, April 13 (#1,037) NYT Connections Hints Today: Monday, April 13 Clues And Answers (#1,037) LEGO Luigi & Mach 8 (72050) Review: 2026’s Best Set Yet? Marc Andreessen Says AI Productivity Will Trigger A Hiring Boom 3D Printing Is The Ultimate Hack To Reduce Household Spending Apple iPhone Fold: Striking Design Revealed In Leaked Photos Apple Smart Glasses: New Leak Reveals A Major Design Twist To Beat Meta Tested: The AI Coming To The Rivian R2 Quordle Hints Today: Monday, April 13 Clues And Answers Companies And H-1B Employees Endure Immigration Waits At Consulates 3 Easy Ways To Turn Anxiety Into Sustained Focus, By A Psychologist Here’s The Most Affordable Humanoid Robot You Can Buy Now UFC 327 Results: 5 Biggest Takeaways From A Wild Night In Miami UFC 327 Results, Bonus Winners, Highlights And Reactions Dana White Announces Huge New Fight For UFC White House Today’s NYT Strands Hints, Spangram, Answers: Sunday, April 12 (Get Ready) Tesla ‘Model 2’ Rises From The Ashes Today’s Wordle #1758 Hints And Answer For Sunday, April 12 NYT Pips Today: Hints, Answers And Walkthrough For Sunday, April 12 Tyson Fury Vs. Arslanbek Mahkmudov Results: Highlights and Reaction NYT Mini Crossword Today: Sunday, April 12 Hints And Answers How Shadow AI Culture Is Destroying Your Business Venture Capital Funds That Market Like Startups Win More Deals Conor Benn Vs. Regis Prograis Results: Highlights and Reaction Samsung’s Disappointing Price Update For Galaxy Phone Buyers Artemis Reached The Moon. The Grid Can Reach The 21st Century A Biologist Explains How Archerfish Shoot Down Prey. Hint: Their Aim Rivals Human Throwing Is It Time For Apple To Forget About The MacBook Air NYT Connections Hints Today: Sunday, April 12 Clues And Answers (#1036) Trump’s 2027 Budget To Reshape U.S. Environmental And Energy Policy CDC Delays Reporting Of COVID-19 Vaccine Benefits—Here’s What To Know Oura Has Designed A Solution To A Big Smart Ring Problem Netflix’s Best New Show Has A Near-Perfect 95% Rotten Tomatoes Score Coachella 2026 Is Being Taken Over By Creator Streams Quordle Hints Today: Sunday, April 12 Clues And Answers This Startup Wants To Use AI To Help Digitize History How To Get The Best Shield In ‘Crimson Desert’ Microsoft Venom Attack Targets C-Suite Executives ‘Maul: Shadow Lord’ Sets Even More Star Wars Rotten Tomatoes Records 3 Ways Happy Couples Argue Differently, By A Psychologist Success For Leapmotor Might Have Negatives For Stellantis New Names Surface As Potential Rogue And Wonder Woman In The MCU And DCU 4 Reasons Artemis Mission Matters Even If You Think It Is Wasteful Fast ‘Crimson Desert’ Patch Adds New Moves, Shield Hiding And One Great Feature Why Do Humans Blush? An Evolutionary Biologist Explains The Signal We Can’t Control Apple iPhone Fold: Striking Design Revealed In Leaked Photos Adobe Attacks Underway—Windows And Mac Users Given 72 Hours To Update iOS 26.4.1 Release: Crucial iPhone Feature Update Arrives, But No Security Fix Fury vs. Makhmudov Full Card, Ring Walk Times and How to Watch Can’t Stand Liquid Glass? This New Hidden iPhone Setting Is A Game-Changer Test-Driving The 2026 Changan Deepal S05: Italian Style Made In China NSA Warning—Reboot Your Internet Router Now Ways That Human-AI Collaboration Slides People Into ‘AI Brain Fry’ And Cognitive Downturns Stop Using These Networks—Google, NSA And TSA Warn NASA Changes Moon Plan: Landing Now Depends On SpaceX Or Blue Origin Samsung Expands One UI 8.5 Beta To More Galaxy Owners The Evolution Of Programmable Hardware At Xilinx NYT Mini Today: Saturday, April 11 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Saturday, April 11 (You’re Putting Me On) Splashdown! NASA’s Artemis II Returns To Earth After Moon Mission Attention Is All You Need. The Human Kind Is Still The One That Counts Today’s Wordle #1757 Hints And Answer For Saturday, April 11 NYT Pips Today: Hints, Answers And Walkthrough For Saturday, April 11 Android Circuit: Galaxy S27 Pro Emerges, Honor 600 Pre-Order Offers, Pixel 11 Display Leaks Apple Loop: iPhone 18 Pro Leak, Urgent iOS Update, MacBook Neo Issues Morgan Stanley Has Mostly Positive Outlook On Tesla Robotaxi, FSD V15 Running Out Of AI Tokens Faster Than Ever? Here’s Why CoreWeave Shares Pop 13% After Anthropic Deal ‘Euphoria’ Season 3’s Rotten Tomatoes Score Crashes, Has Lost Key Player People Don’t Agree On What AI Can Do, But They Don’t Even Use The Same Product ‘Overwhelming’—Google Issues Gemini Update For Gmail Users NYT Connections Hints Today: Saturday, April 11 Clues And Answers (#1035) Quordle Hints Today: Saturday, April 11 Clues And Answers The Costly Dream Of Space-Based AI Infrastructure Can You See The Watcher In This ‘Daredevil: Born Again’ Shot? Adobe Attacks Underway—Windows And Mac Users Given 72 Hours To Update You Just Watched The Backdoor Pilot For ‘The Pitt: Night Shift’ Are Nicotine Pouches Like Zyn And VELO Safe To Use? A Doctor Answers Human Resources (HR) Is The Key To AI Success Per WalkMe ( SAP)
The Real Compliance Crisis Is Not Technology
Emil Sayegh · 2026-05-07 · via Forbes - Innovation
Compliance rule law and regulation graphic interface for business quality policy

Compliance Is No Longer Just A Technology Problem: it Is A Data Governance And Operational Discipline Challenge.

getty

Across the technology industry, compliance initiatives are still too often approached primarily as infrastructure projects. Organizations buy tools, migrate workloads into compliant cloud environments, implement monitoring platforms, deploy identity controls and assume the problem is largely solved. That mindset misses the hardest part entirely.

The most difficult aspect of modern compliance is no longer technology itself. It is governance over data, processes, people and operational discipline. The challenge is not simply securing systems. The challenge is understanding what sensitive information exists, where it resides, how it flows across the organization, who has access to it and how it should be governed throughout its lifecycle.

What changed is that compliance failures are no longer simply audit findings or contractual inconveniences. They are increasingly becoming operational, legal and national security risks tied directly to contract eligibility, False Claims Act exposure, cyber resilience and supply chain trust.

Cybersecurity Maturity Model Certification within the Defense Industrial Base is one of the clearest examples of this shift, but the lesson extends far beyond defense contracting. Financial services, healthcare, critical infrastructure, cloud providers and multinational enterprises are all confronting the same underlying problem: how to govern sensitive and regulated information inside increasingly interconnected, cloud-based and globally distributed operating environments.

The organizations struggling most with compliance are often not the ones lacking cybersecurity tools. They are the ones lacking clarity around scope, data lineage, workflow governance and operational accountability.

Technology Is Usually The Easier Problem

Most mature organizations today can deploy strong cybersecurity tooling. Multi-factor authentication, encryption, endpoint detection and response, security information and event management platforms, privileged access management and cloud security controls are no longer exotic capabilities reserved for the largest enterprises.

The market has matured significantly over the past decade. Major cloud providers have invested heavily in compliant infrastructure offerings, while managed security providers and compliance platforms have simplified deployment and operations. Government cloud environments, secure enclaves and managed compliance architectures now allow organizations to stand up highly secure environments far faster than was possible only a few years ago. The harder challenge begins after the technology is implemented.

Organizations must determine which information actually falls under regulatory scope and where that information resides across the enterprise. Sensitive data may exist in engineering systems, collaboration platforms, email, shared drives, cloud repositories, backup systems, supplier environments or employee endpoints. In many cases, organizations discover that the real issue is not lack of tooling, but lack of visibility and governance.

The operational questions quickly become far more difficult than the technical ones:

  • What data is actually regulated?
  • Where does that data move across the organization?
  • Which employees, contractors and suppliers require access?
  • How should regulated and non-regulated environments interact?
  • Which workflows introduce compliance risk?
  • How should sensitive information be shared externally?

That operational complexity is where compliance programs either mature or fail.

Compliance Has Become A Data Governance Problem

One of the biggest misconceptions in regulatory compliance is the assumption that entire companies, applications or product lines automatically become regulated environments. In reality, most compliance obligations are tied to specific data sets, workflows and business processes.

Within the defense industry, many companies operate highly blended environments where commercial products, international collaboration and government programs coexist simultaneously. A manufacturer may develop commercial aviation systems sold globally while also supporting Department of Defense or Federal Aviation Administration programs that require protection of Controlled Unclassified Information. Engineering teams may collaborate internationally while only specific technical deliverables, drawings or program documentation fall under regulatory controls.

A company may customize a commercial product for a government customer, only to later sell portions of that functionality globally. Another may receive Defense Federal Acquisition Regulation Supplement clauses even though the actual exchange of CUI is minimal or poorly defined. Engineering teams may need to collaborate across suppliers, international subsidiaries and commercial business units while attempting to maintain compliant segmentation around only a subset of regulated information. This is where compliance becomes significantly more complicated than simply deploying cybersecurity tools.

The challenge is not “locking everything down.” That approach is operationally unsustainable and financially impractical for most organizations. In fact, in many organizations, the fastest way to fail compliance is to over-scope the environment.

Excessive restrictions create operational friction. Overclassification slows engineering and collaboration, increases costs, frustrates users and often pushes employees toward shadow IT workarounds that create even larger security gaps. Organizations that indiscriminately place entire enterprises into highly restricted environments often discover that productivity declines while compliance complexity increases.

The real challenge is understanding precisely:

  1. What information is actually regulated
  2. Where that information resides
  3. How that data moves internally and externally
  4. Which employees, contractors and suppliers require access
  5. Which systems and workflows fall inside compliance scope
  6. How regulated and non-regulated environments should interact

The organizations managing compliance most effectively are usually not the ones with the most restrictive environments. They are the ones with the clearest understanding of their data, workflows, supplier relationships and governance models.

CMMC Illustrates The Shift Perfectly

The evolution of CMMC highlights how compliance expectations are changing across industries. For years, many defense contractors operated under a self-attestation model. Companies could submit Supplier Performance Risk System scores while working toward eventual compliance with NIST Special Publication 800-171 requirements. In practice, this created an environment where compliance was often treated as a documentation exercise rather than an operational discipline. That model is now changing rapidly.

Organizations increasingly must demonstrate not only that controls exist, but that they are implemented consistently, monitored effectively and aligned to actual business operations and data flows. Third-party validation is becoming central to the process, while the Department of Justice has simultaneously increased scrutiny around cybersecurity-related False Claims Act exposure tied to inaccurate compliance assertions and weak cybersecurity practices.

The scale of this transition is enormous. The DOD estimates that more than 220,000 companies participate in the DIB supply chain in some capacity, while thousands of contractors are expected to require Level 2 certification over time as CMMC implementation accelerates. At the same time, assessor availability, operational readiness and supplier preparedness remain uneven across the market. This creates a dangerous gap between regulatory expectations and operational maturity.

At the same time, the compliance model pioneered through the DOD is beginning to influence the broader federal ecosystem. The General Services Administration has already increased cybersecurity and supply chain scrutiny across federal contractors, while agencies such as the Department of Homeland Security and Department of Energy are expected to continue expanding requirements around controlled information, operational resilience and supplier risk management.

What started as a DIB issue is increasingly becoming a broader federal contractor issue and eventually may become a broader enterprise governance model across regulated industries.

The discussion is no longer limited to whether an organization purchased the right tools or implemented baseline controls. The focus increasingly centers on whether leadership truly understands the environment they are attesting to, whether regulated information is properly identified and governed and whether compliance processes actually operate consistently across the enterprise.

In many cases, the real questions now become:

  • Does the organization understand what data is actually regulated?
  • Are regulated and non-regulated environments properly segmented?
  • Are supplier and third-party risks being governed appropriately?
  • Do documented policies reflect actual operational behavior?
  • Can the organization defend its compliance assertions during an audit, investigation or breach event?

Those are governance and operational maturity questions far more than pure technology questions such as which firewall to deploy, which endpoint platform to standardize on, which cloud environment to migrate into or which security information and event management system to purchase. In many cases, organizations already have strong cybersecurity tooling in place. The harder challenge is determining how regulated information moves across engineering teams, suppliers, cloud repositories, collaboration platforms and business workflows, while maintaining clear operational boundaries and defensible compliance governance.

Compliance Is Becoming An Operational Competency

The companies that will perform best in increasingly regulated industries are not necessarily the ones spending the most money on cybersecurity tooling. They will be the organizations that understand their data, maintain disciplined governance processes and operationalize compliance across business functions instead of isolating it within IT departments.

Modern compliance now intersects with engineering, procurement, legal, human resources, facilities, product development and executive leadership. It requires organizations to understand how sensitive information flows through the business and how operational decisions affect regulatory exposure. Technology remains essential, but technology alone is no longer sufficient.

Over the next decade, compliance programs will increasingly become operating systems for trust. Governments, customers, investors and supply chain partners will all expect organizations to demonstrate not only technical security, but disciplined governance over information, suppliers, operational risk and regulatory accountability.

The organizations that adapt early will treat compliance not as overhead or a one-time certification exercise, but as a long-term competitive advantage tied directly to resilience, customer trust, contract eligibility and enterprise credibility.