Proportionate compliance: why ticking boxes does not protect you
Formal compliance and real risk are not the same thing. Evidence and measured exposure are where looking secure and being secure diverge.

There is a formally compliant company that gets breached anyway. The scene repeats often enough to stop being a paradox: certifications in order, every checklist ticked, audits passed — and an attacker walking in through the very gap no box had ever really closed.
The reason is simple and uncomfortable: formal compliance measures the presence of controls, not their effectiveness. These are two different things, and conflating them is the most elegant way to spend a lot and protect yourself little.
The ticked box and the right question
Take a classic control: “a patch-management policy exists”. The box is ticked with a document. But the question that matters is a different one: how long, on average, passes between a critical vulnerability being disclosed on exposed systems and it actually being fixed? The first answer is a file. The second is a measure of real risk. A company can have the perfect policy and patches that arrive weeks late exactly where it matters most.
This gap runs through almost every control. “An incident response plan exists” says nothing about how it would hold up in practice. “Multi-factor authentication is enabled” does not say whether it covers all privileged access or just email. The box describes intent; only evidence describes state.
Why formal compliance seduces
Checklist compliance is attractive because it is discrete, delegable and demonstrable. It is binary — done or not done — so it is easy to report to leadership; it can be handed to a vendor; and it produces a showable artefact in case of an inspection. Real risk is the opposite: continuous, shaded, and not certifiable once and for all. Between something easy to measure and something that matters, companies under pressure almost always choose what is easy to measure.
The better regulations know this, which is why they insist on proportionality and effectiveness. NIS2 asks for measures appropriate to the risk and an assessment of their effectiveness; DORA mandates real testing, not attestations; the CRA wants products actually free of known exploitable vulnerabilities, not declarations. The legislator, in other words, is trying to move the bar from presence to proof.
Proportionate means unequal
Proportionate compliance does not mean doing less: it means distributing effort in proportion to exposure. Not all systems deserve the same protection, and treating them as equal is itself a mistake — it scatters resources across marginal systems and starves the ones that, if they fall, stop the business or expose the data that matters. Proportioning means concentrating defences where a failure hurts most, and knowingly accepting more risk where the impact is contained. A checklist applied uniformly is, paradoxically, the opposite of proportionality.
Evidence as the foundation
The way out is not to abolish checklists — they remain useful as reminders — but to demand, for every control that matters, evidence that proves its effectiveness. Not “we have backups”, but “the last test restore happened on this date, took this long, recovered these systems”. Not “we run training”, but “the last phishing simulation produced this click rate, down from the previous one”. Evidence turns an assertion into a measure, and a measure can be tracked over time.
It is also what actually holds up in a dispute or an inspection. Demonstrating that you acted with due diligence is not done by producing policies, but by showing that controls were tested, measured and corrected. Evidence is at once what protects you from the attacker and what protects you from the challenge.
Measure exposure, not compliance
The step up in maturity is to stop asking “how many boxes have we ticked” and start asking “how exposed are we, and is that number falling?”. A few honest metrics on exposure — time to fix critical vulnerabilities, real coverage of key controls, tested detection and response times — say more about risk than a whole binder of attestations. And unlike boxes, they move: they tell you whether you are getting better or worse.
None of these measures needs to be rebuilt from scratch every quarter: their value lies in tracking them over time, with the same definition, so that a change actually means something. A metric that changes its method of calculation at every reading is not a measure, it is an anecdote.
The takeaway
Ticking boxes is necessary but not sufficient: it proves controls exist, not that they work. Security lives in the distance between the two, and that distance is closed only with evidence and an honest measure of exposure. Compliance is the floor, not the ceiling — and mistaking the floor for the house is the most expensive way to feel safe without being safe.



