Does Malicious Compliance Define Your Organization's Security Program?

Even with the best intentions, no law or regulation can address every possible security threat. Every organization has unique challenges, and new threats arise daily. Organizations who base security programs around only compliance are missing many security best practices and are at risk of a breach. We call this malicious compliance, and it is a constantly growing threat.

What exactly is malicious compliance? Malicious compliance comes as a result of an organization building a security program, or adhering to a set of security practices, solely around being compliant to a specific law or regulation as opposed to security best practices.

Is malicious compliance happening in my organization? Simply put, your organization may concede to this mindset if there is a belief that compliance equals security, which any good security professional knows is not the case.

How does my organization avoid the problem? While the answer is simple, the solution is complex; begin building an enterprise security program with effective management, operational and technical controls. The absence of any one of these components results in an ineffective security program. The absence of an effective security program most likely will result in a lack of compliance with industry regulations or, at the very least, a security program built around malicious compliance.

A  simple example follows, regarding a much more complex problem as to how these controls can come together to help maintain an effective compliance program.

Let’s start with management controls. When we discuss management controls, we have to begin with organizational structure. A good security program uses a top-down approach. That means an effective security program is supported by upper management and filters down through mid-level managers all the way down to hourly associates.

This is, in a sense, the only way to properly execute an effective security program. This approach is not industry specific, as Fortune 100 banks to mom-and-pop dry cleaning chains all should use the same approach.

At the end of the day, if upper management isn’t concerned with security, then why would an hourly associate care? In an organization where this approach is not executed, the only ones who care about security is the person who will lose their job in the event of a breach. Most times these people aren’t the ones with decision making power. In this type of organization, an individual or department unfairly holds most of the risk for the organization.

There is no right way to properly structure an organization, as all organizations are different. Typically in a banking environment, there will be dedicated security, risk management, and internal audit departments. In an organization such as this, all of these departments have to work together effectively and act as a check and balance system. In a smaller organization it probably isn’t necessary to split departments in this manner. The only things that remain consistent are that security should be supported from the top down, and that there is an effective way to identify and manage risk.

Second is operations. These employees perform the day to day activities including anything from monitoring to access control maintenance. The ways in which these actions are performed are dictated by operational policies and procedures.

Both policies and procedures set the tone for how the organization is to operate. They comprise the law of the land, if you will. Without these, there is no good way to communicate marching orders from upper management.

Policies and procedures cannot just be stagnant documents sitting on the company intranet of which no one knows the location. These important documents need to be constantly updated to reflect technological changes, as well as communicated to associates. Any unapproved action by the end user to circumvent these policies and procedures needs to be met by management with disciplinary action against the end user. All approved exceptions to standard policies and procedures need to go through formal change management and be documented as such.

One last note: policies and procedures shouldn’t be based solely on compliance requirements, but should also include industry best practices. Typically compliance requirements are a step behind industry best practices, and most times compliance requirements are updated to reflect industry best practices. This approach ensures that your organization remains ahead of the curve from a compliance standpoint.

Finally, there are technical controls. These are implemented to enforce information security best practices as well as corporate policies and procedures. These controls encompass everything from a corporate firewall to ensuring that USB ports are disabled on end user systems.

The level of technical controls implemented on systems in an organization typically depends on the risk associated with that specific system. For many regulations such as GLBA, HIPAA, and FISMA, a formal risk assessment must be performed before technical control requirements are implemented. The results of this assessment determine the level of controls needed to protect the specific system/network infrastructure. Although one of the most effective ways to enforce policy, typically, this area is where most organizations want to do the minimum amount required by compliance regulations. Not only do technical controls have a high association with increased cost, but many also impact the way business is done and therefore are not typically supported by upper management or line of business owners.

Let’s consider an example of how all of these components come together and how doing so can help to maintain an effective compliance program. Once again, let’s start with people. Whether or not security is supported from the top down or not, senior executives do have a vested interest in ensuring that their organization is compliant with whatever regulation to which the organization may have to adhere.

The difference between a top down approach and a “we just need to be compliant” approach is the “effectiveness” part. The latter of the two approaches pushes the organization into a program of malicious compliance. Other than the obvious issues around malicious compliance, it’s very hard to maintain compliance as such. For example, PCI requires only 7-character passwords. Let’s assume the organization simply wants to meet this minimum, but industry best practices suggest a minimum of 12.

If the standard were to change, then that organization would have to meet that requirement. Although this may seem like a relatively arbitrary task, I can ensure you that it isn’t that easy. In addition to the sometimes difficult logical changes that will need to be made, policies and procedures will need to be updated and communicated to end users as well.

However, if executive management would have actually been concerned about security and not just compliance to begin with (in a top down approach), policies and procedures would already have been created based on industry best practices to meet this new compliance requirement. In addition, the technical controls would already have been implemented to ensure that policies and procedures around this requirement were properly being enforced.

Compliance with various regulatory standards becomes much easier to manage if an organization is already aligning with industry best practices. In order to become compliant with industry best practices, all of the safeguards discussed need to be addressed.

This not only makes sense from a compliance perspective but just from an overall “doing good business” perspective. Organizations can use security frameworks such as NIST or ISO:27001-2 as good references for security best practices. Organizations can even become certified to such frameworks. Organizations that have certification and accreditation to such frameworks have no difficulty meeting the demands of either somewhat subjective compliance requirements such as GLBA and HIPAA or more black-and-white standards such as PCI.

In conclusion, much of the information provided above is fairly easy to understand -- Security 101 type stuff. The issue is not with understanding, but with articulating to organizations, that the long term reduction in the cost of compliance quickly will outweigh the short term investment needed to ensure their environment is implemented in accordance with security best practices. Unless security is made a top priority in your organization and is implemented using a top-down approach, the preceding advice will fall on deaf ears and malicious compliance will continue to plague your organization.



  • Cybersecurity Awareness Month: Top Five Action Items to Elevate Your Data Security Posture Management and Secure Your Data

    October is Cybersecurity Awareness Month, and every year most tips for security hygiene and staying safe have not changed. We’ve seen them all – use strong passwords, deploy multi-factor authentication (MFA), be vigilant to spot phishing attacks, regularly update software and patch your systems. These are great recommended ongoing tips and are as relevant today as they’ve ever been. But times have changed and these best practices can no longer be the bare minimum. Read Now

  • Boosting Safety and Efficiency

    Boosting Safety and Efficiency

    In alignment with the state of Mississippi’s mission of “Empowering Mississippi citizens to stay connected and engaged with their government,” Salient's CompleteView VMS is being installed throughout more than 150 state boards, commissions and agencies in order to ensure safety for thousands of constituents who access state services daily. Read Now

  • Live From GSX: Post-Show Review

    Live From GSX: Post-Show Review

    This year’s Live From GSX program was a rousing success! Again, we’d like to thank our partners, and IPVideo, for working with us and letting us broadcast their solutions to the industry. You can follow our Live From GSX 2023 page to keep up with post-show developments and announcements. And if you’re interested in working with us in 2024, please don’t hesitate to ask about our Live From programs for ISC West in March or next year’s GSX. Read Now

    • Industry Events
    • GSX
  • People Say the Funniest Things

    People Say the Funniest Things

    By all accounts, GSX version 2023 was completely successful. Apparently, there were plenty of mix-ups with the airlines and getting aircraft from the East Coast into Big D. I am all ears when I am in a gathering of people. You never know when a nugget of information might flip out. Read Now

    • Industry Events
    • GSX

Featured Cybersecurity


New Products

  • HD2055 Modular Barricade

    Delta Scientific’s electric HD2055 modular shallow foundation barricade is tested to ASTM M50/P1 with negative penetration from the vehicle upon impact. With a shallow foundation of only 24 inches, the HD2055 can be installed without worrying about buried power lines and other below grade obstructions. The modular make-up of the barrier also allows you to cover wider roadways by adding additional modules to the system. The HD2055 boasts an Emergency Fast Operation of 1.5 seconds giving the guard ample time to deploy under a high threat situation. 3

  • ResponderLink


    Shooter Detection Systems (SDS), an company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols. 3

  • Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

    Connect ONE®

    Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation. 3