Security1 publisher2 min readPublished
The case for continuous control testing: CISOs can't prove controls work right now
A SecurityWeek column argues that boards, customers and regulators now want proof that controls hold today. Its one measurement is a 2025 Dell finding: 69 percent of IT professionals say their leadership overestimates cyber readiness.
The Watch · Security desk

What happened
- SecurityWeek published a column arguing that compliance-era control assessments no longer answer the question boards, customers and regulators now ask, which is whether controls can be proven to be working right now.
- The author writes that CISOs asked that question usually answer with some version of "we think so".
- Its single measurement is a 2025 Dell study in which 69 percent of IT professionals said their own leadership overestimates the organization's readiness for a cyber event.
- The drift it describes includes a firewall port opened for a two-week integration and still open eight months later, and a vendor that changes a configuration a year after passing review.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure The exposed party is the CISO whose name goes on customer attestations, regulatory filings and contractual commitments, and a sampled test is what has to defend that signature afterwards.
- constraint No enforcement action, contract term or filing is cited for the demand attributed to boards, customers and regulators. Take this to a budget meeting and there is no deadline to point at.
- decision Funding this is a decision about what feeds the GRC system of record a company already paid for. The line item sits with whoever owns those data inputs.
- capability Testing against live data makes "did anything change today" answerable for identity and access, hourly cloud configuration changes, critical vulnerability remediation clocks and vendor posture.
"A control is not a monument. It is a living thing that drifts," the author wrote [5]. The failure window opens the day after an audit closes. Something moves, stays moved for months, and the column says the only honest thing a CISO can then say is that the last review looked fine [7]. There is no incident behind any of this: the port and the vendor configuration are illustrations, and the piece names no actor and no vulnerability [18].
Sampling is where the argument gets specific. Inspecting a small slice of an enterprise gives a CISO almost no real confidence, the column says, and the environment being sampled grows by double digits every year while AI risks stack on top of the existing IT ones [10]. The author wrote: "When your signature is the assurance, testing a fraction of the environment cannot stand behind it. High confidence comes from testing everything, continuously." [8]
The Dell figure is the strongest evidence on offer. Sixty-nine percent of IT professionals reported a belief about their own leadership [3]. The other 31 percent did not report it [4]. Both figures count beliefs, and neither counts a control. A survey of perception cannot tell a board how many firewall rules, access grants or vendor configurations are out of place this morning.
The column says the standards bodies have already moved this way. Its supporting sentence, which begins to describe a NIST update, breaks off in the published text [15].
The objection the author reports hearing from CISOs is alert volume, since teams are already drowning. The answer given is that continuous monitoring done well produces less to chase, because every signal is tied to a contract, a customer commitment or a regulatory obligation, and a misconfiguration that touches nothing critical can wait [14]. That tying is the prerequisite. Do it badly and continuous testing adds rows to a queue that is already full. The column closes on the framing rather than the tooling: more than a purchase, the author writes, it is a decision that a we-think-so answer will no longer do [16].
What to watch
- The NIST update the column starts to cite: the published sentence stops mid-clause, and the actual language would show whether continuous evidence is required or only recommended.
- Whether Dell publishes the detail behind the 2025 study: sample size, sectors, and any measured control-failure rate under the perception gap.
- Any contract term or regulatory filing that requires continuous control evidence with a compliance date attached.