Certified but Breached: Why Compliance Alone Doesn’t Stop Attacks

Yes, certified companies get breached, and it happens more often than most compliance programs like to admit. ISO 27001 and SOC 2 certificates prove that controls existed and were documented at the time of the audit. They do not prove those controls are still working today, against the attack techniques being used right now.

That gap between compliance and security is not a flaw in the frameworks themselves. It is a predictable result of treating certification as the finish line instead of the starting point. At CyberSapiens, we sell compliance services, and we still tell clients this plainly: a certificate on the wall is not a defence against an attacker on the network.

Why certified companies still get breached

Compliance frameworks are built around evidence, not real-time defence. An auditor checks whether a policy exists, whether a control was tested, and whether a log was kept. None of that confirms whether a phishing email would still get through, whether an exposed port was found last month, or whether an employee with old access has since left the company.

Attackers do not check your audit calendar before they act. Certification cycles run annually or every three years. Threat actors probe continuously. The organisations getting breached with a valid certificate are usually not lying to their auditors. They are simply discovering that a point-in-time pass does not hold up against a continuous threat.

The short answer: compliance proves a moment in time. Security is what happens every day after the audit ends.

In the next section, we walk through three real patterns we see repeatedly in certified organisations that still get breached, followed by what closing that gap actually looks like in practice.

Three patterns we see in certified companies that still get breached

Across CyberSapiens engagements, breaches at certified organisations tend to trace back to one of three recurring patterns. None of them involve a failed audit. All three involve a gap the audit was never designed to catch.

Pattern 1: Paper controls

A policy exists in the document library and satisfies the auditor, but it was never operationalised on the actual network. Multi-factor authentication is documented as mandatory, yet a legacy admin account still logs in with a password alone. The control passed on paper because nobody tested it against a live login attempt.

Pattern 2: Point-in-time compliance

The environment was genuinely secure on audit day. Six months later, a new SaaS tool was connected, a firewall rule was loosened for a vendor, and a patch cycle slipped. Nothing in the certification process re-checks any of this until the next audit cycle, which can be a year or more away.

Pattern 3: Scope games

The certified scope covers one business unit, one product, or one data centre, while the actual attack surface is much wider. A breach through an unscoped subsidiary system or a shadow IT tool does not make the certification false. It just means the certificate never claimed to cover the part that got hit.

What connects all three is timing and scope, not dishonesty. This is consistent with how frameworks like the NIST Cybersecurity Framework describe security as a continuous function, not a one-time assessment. Closing the gap means treating certification as a baseline to monitor, not a result to file away.

Closing the gap practically

None of the three patterns above require throwing out your certification. They require adding a layer of continuous oversight on top of it. At CyberSapiens, the organisations that close this gap consistently do four things between audit cycles, not just before them.

Four step model showing continuous monitoring, regular VAPT, vCISO oversight, and full scope attack surface coverage to close the compliance versus security gap

First, controls get monitored continuously instead of being reviewed once a year. Second, penetration testing and vulnerability assessments run on a regular schedule, not just as a pre-audit exercise designed to pass a checklist.

Third, a virtual CISO reviews posture, risk, and scope on an ongoing cadence rather than once around audit time. This is the role CyberSapiens plays for many clients: someone accountable for security outcomes, not just for the next audit passing.

Fourth, visibility extends past the certified scope to cover subsidiaries, shadow IT, and third-party connections. A certificate that covers one business unit should not be mistaken for coverage of the whole organisation.

In practice, this means the vCISO model exists to be the layer between audits, not a replacement for the audit itself.

What good looks like beyond the certificate

An organisation that has genuinely closed the compliance-security gap looks different from one that has simply passed its latest audit. These are the markers CyberSapiens looks for when we assess whether a certified client is actually secure, not just certified.

Controls are tested against live conditions, not just reviewed on paper during the audit window.

Vulnerability and penetration testing happens on a recurring schedule, not once before each audit.

Someone owns security outcomes year round, whether that is an internal CISO or a virtual CISO on retainer.

Asset and access reviews happen when the environment changes, not only when the next audit cycle opens.

Foundational controls align with practical frameworks such as the Essential Eight, not only the framework named on the certificate.

Scope is reviewed regularly so the certificate keeps pace with the business, rather than describing an environment from two years ago.

Several of these markers line up directly with the Essential Eight maturity model from the Australian Cyber Security Centre, which treats security as a set of controls to keep maturing, not a checklist to pass once.

Frequently asked questions

Does ISO 27001 or SOC 2 certification guarantee we will not be breached?

No, certification does not guarantee a breach will not happen. It confirms that specific controls existed and were tested at the time of the audit, within a defined scope. Between audit cycles, environments change, new tools get connected, and attacker techniques evolve, so certification needs continuous monitoring to stay meaningful.

What is the difference between compliance and cybersecurity?

Compliance is evidence that agreed controls were in place at a point in time, assessed against a specific framework and scope. Cybersecurity is the ongoing practice of preventing, detecting, and responding to real attacks. A business can be fully compliant and still have security gaps outside what the framework measured.

How often should we test our security controls between audits?

Most organisations benefit from vulnerability scanning on a continuous or monthly basis, with full penetration testing at least annually or after major system changes. High-risk environments such as financial services or healthcare often test more frequently. The right cadence depends on how often the environment itself changes.

What is a vCISO and do we need one if we are already certified?

A virtual CISO is an outsourced security leader who owns risk, posture, and strategy on an ongoing basis, without the cost of a full-time executive hire. Certification proves a point-in-time state, while a vCISO provides the year-round oversight that keeps that state accurate as the business changes.

Robin Dsouza, Founder CyberSapiens

Content reviewed by Robin Dsouza

Founder and Lead Cyber Security Expert

Cyber Forensic Advisor, Karnataka State Police

CISA CPISI v3.2 ISO 27001 Lead Implementer 10+ Years Experience

Robin is the founder of CyberSapiens and one of Australia’s leading cybersecurity experts. With over 10 years of experience, he has trained more than 200,000 individuals, consulted over 200 organisations, and conducted 500+ seminars. Previously at Infosys, KPMG Global Services, and iPRIMED Education Solutions.

GRC and SOC 2 ISO 27001 HIPAA IT Risk Management Security Auditing Network Security Data Privacy

Certified is not the same as secure. Find out where the gap is.

Book a beyond-compliance review with CyberSapiens and get a clear picture of where your certified controls end and your real attack surface begins.

Book Your Beyond-Compliance Review
1300 507 668
Lvl 1, 206 Lorimer St, Port Melbourne, Australia