When Does Compliance Stop Reflecting Reality?
There is a particular kind of confidence that settles in once a security programme has been signed off. Policies are approved, training delivered, dashboards show completion rates, and the organisation can demonstrate alignment with recognised cyber security frameworks. From a distance, the picture feels settled even mature.
The doubt usually arises later, often after an incident, when leaders start to question whether those controls were shaping decisions or simply documenting good intentions. Glenn Wilkinson, ethical hacker and co-founder of Agger Labs, has seen this repeatedly. “A lot of organisations overestimate their position,” he explains. “They think they are safer than they really are because they’ve gone through the process and the papers. The reality often looks very different from the data they see.”
From that vantage point, the difference between controls that reassure and those that protect is rarely found in policy language or slides. It shows up in how people respond when something feels urgent, confusing or slightly out of place (exactly the moments attackers exploit).
How Often Are Breached Organisations Technically Compliant?
Many organisations Glenn tests are technically compliant at the time of compromise. Controls exist, frameworks are mapped, and awareness training has been completed. None of that surprises him.
“Tick-box security is great for the audit, but it doesn’t stop a skilled attacker from exploiting predictable human behaviour,” Glenn notes. “Compliance gives a sense of safety but it rarely changes the needle from an attacker’s point of view.” He compares it to seat belts, wearing one saves lives but it can also make people take greater risks because they feel protected. Compliance can have a similar psychological effect, softening caution while attackers watch and wait.
Does Compliance Meaningfully Change Risk from an Attacker’s Perspective?
The short answer is not usually. Attackers focus on human behaviour, which often remains vulnerable regardless of audit outcomes. Glenn elaborates: “Compliance can unlock budgets and enable better tooling but on its own it doesn’t change the way attackers interact with your environment.”
What does make a difference is understanding the human component. Small interventions (contextual guidance, nudges and tools like Redflags) help people pause and reassess risky decisions in the moment. “It’s like having someone watching over your shoulder,” Glenn explains, “just a little prompt that says stop, think, don’t click that, because this could hurt you and the business.”
How Human Behaviour Drives Risk in Cyber Security
Social engineering, phishing, and shadow IT persist because human behaviour is predictable under pressure. Attackers leverage authority, urgency, and incentives knowing that most people respond instinctively. “They’ll frame themselves as a boss, compress timelines, or offer a reward. We fall for it because it mirrors how we work every day,” Glenn says.
People break rules not out of malice but to get work done. Shadow IT (forwarding documents to personal email, using consumer cloud tools, or bypassing approved systems) is often a response to friction rather than negligence. “When users upload to Dropbox or copy to a USB, it’s rarely malicious,” he notes. “They’re just trying to get work done. Security should enable them not punish them. Give people the tools to succeed safely and they won’t feel cornered.”
Cyber Security Awareness: Bridging Theory and Reality
Annual security awareness training continues because it’s measurable and familiar, but its limitations are clear. “Training is fine in isolation but people don’t operate in isolation,” Glenn explains. “An email arrives while you’re juggling meetings, deadlines, and kids at home. Your brain is in a very different state than during training.”
The most effective interventions combine ongoing, context-specific guidance with supportive tools. Redflags, for example, delivers nudges at the point of risk, helping staff make safer choices without undermining trust. Glenn likens it to self-defence training: techniques learned in class rarely transfer perfectly under adrenaline, but consistent situational practice improves real-world response.
Using Compliance as a Launchpad for Real Security
Compliance remains valuable, it aligns stakeholders, unlocks budgets, and provides a foundation for risk management. The mistake is treating it as a finish line.
“Use compliance as a foundation not the destination,” Glenn says. “Push the needle a little every day. That’s how organisations become genuinely resilient.” Combining sensible processes, human-centred tools, and contextual awareness ensures organisations reduce risk while respecting human limitations.
Key Takeaways
- Compliance and cyber security are related but not interchangeable; human behaviour remains the most exploitable factor for attackers
- Rule-breaking often signals friction or unmet needs rather than negligence
- Behavioural interventions and supportive tools, like Redflags, help guide safer decisions in moments of risk
- Annual awareness training alone rarely translates to behaviour change under real-world pressure
- Small, context-specific nudges and environmental adjustments can have a disproportionately positive impact on security
Continue the Conversation
For practitioners exploring how compliance expectations intersect with human-centred cyber security, our Compliance Hub brings together webinars, articles, and research.
You may also find our latest guide useful:
Evidence of Understanding – Rethinking Human Risk in Cyber Security Compliance for 2026
This guide includes perspectives from Amy Lemberger, founder of The CISO Hub, alongside Tim Ward, CEO of Redflags, and Lucy Finlay, Delivery Director for Secure Behaviour and Analytics at Redflags. It explores how organisations are evidencing behavioural change and engaging constructively with auditors while strengthening real-world security outcomes.
Access our Compliance Hub Here!
About the Author
Glenn Wilkinson is an ethical hacker, keynote speaker, and co-founder of Agger Labs. He has tested cyber security resilience across government, finance, law enforcement, and global enterprises, with a focus on human risk and attacker psychology. Known for live hacking demonstrations and practical, human-centred insights, Glenn helps organisations understand attacker behaviour and how tools like Redflags can support safer decisions under real-world pressure.
