![]() |
Charlotte Stonestreet
Managing Editor |
| Home> | IIot & Smart Technology | >Cyber Security | >Why compliance does not guarantee cyber resilience |
Editor's Pick
Why compliance does not guarantee cyber resilience
02 September 2026
CYBER SECURITY has become one of the most audited and regulated areas of enterprise technology. However, simply passing an audit or achieving certification is not the same as proving that systems, people and processes can withstand a genuine outage or cyber incident.

Here, Nathan Charles, head of customer experience at cyber resilience specialist OryxAlign, explains why engineering businesses should look beyond compliance to build genuine operational resilience.
Engineering businesses invest significant time and resource into meeting the requirements of ISO 19650-5 and the National Protective Security Authority’s ‘Built it Secure’ approach. However, while these frameworks provide valuable structure and demonstrate a credible baseline of security maturity, it is very possible for certified firms to still lose control of sensitive data.
Compliance frameworks like these set a recognised baseline, create accountability and give boards and customers a way to benchmark security maturity. The risk lies in what happens post-certification.
For many organisations, passing an audit becomes the objective in itself, rather than a step towards genuine resilience. Certification and self-assessment exercises capture a snapshot of security controls at a single point in time, under conditions that are largely predictable. They rarely test what happens when those controls are placed under real pressure, such as a ransomware attack that spreads faster than the incident response plan anticipated, a misconfigured update that takes core systems offline, or a supplier outage with knock-on effects nobody had mapped.
When the paperwork doesn't match reality
The gap between documented compliance and operational reality is well evidenced. The UK Government's Cyber Security Breaches Survey 2025/2026 found that 43 per cent of UK businesses reported experiencing a cyber security breach or attack in the past twelve months. This is despite most organisations already having basic technical measures, such as malware protection, firewalls and access controls, in place.
According to Howden’s cyber exposure report, the UK was the most-attacked country in Europe in 2026 and the two most targeted industries were construction and engineering. Notable cyber-attacks in the last year or so include those on engineering contractor Morrisroe, the Construction Industry Council and Bouygues UK.
Regulators are recognising the gap too
Encouragingly, this is not a case of compliance frameworks being wrong; it reflects how regulators and standard-setters are actively evolving what they expect organisations to demonstrate. The National Cyber Security Centre (NCSC) has developed its Principles Based Assurance approach specifically to move away from assessment against fixed, compliance-driven control sets, in favour of a risk-based approach.
Notably, the EU's Digital Operational Resilience Act requires financial entities to test their resilience through scenario-based exercises rather than rely on point-in-time compliance reviews. Across sectors and geographies, there is a consistent direction of travel where demonstrated resilience, not paperwork, is the real measure of readiness.
From checklist to stress test
For organisations that want to close this gap, the starting point is treating resilience as something that is tested and proven, not assumed because a framework has been satisfied. That means running scenario-based exercises that simulate severe but plausible disruption, such as the loss of a critical supplier, a ransomware incident or a major cloud outage, and observing how systems, teams and decision-making actually hold up under pressure.
Compliance frameworks and regulatory obligations remain an essential part of managing cyber risk, and organisations should not disregard them. But they represent a floor, not a ceiling. Genuine operational resilience is proven under pressure, not certified on paper. Organisations that build a culture of continuous testing, honest assumption-challenging and cross-functional ownership will be far better placed to keep critical services running when, not if, disruption occurs.
To learn how OryxAlign helps organisations map digital dependencies and strengthen operational resilience, visit:
- Don't risk digitalisation paralysis
- Smarter working in utilities & water
- UK Digital Twin Centre opens in Belfast to drive nationwide industrial innovation
- Architectural vulnerabilities detected in Siemens SIMATIC S7-1500 Series
- All-new mobile browser with complete data encryption
- UK Space Agency to invest £374m per year in European Space Agency
- IoT botnet source code released
- UK initiative to shape global standards for AI
- A robotic approach to sortation
- First consumer testbed for 5G technology

















