SECURITY and compliance assessments based on annual audits and sampling may no longer give organisations a reliable picture of their current risk, according to Sravish Sridhar, founder and chief executive of TrustCloud. Citing a 2025 Dell study, Sridhar says 69% of IT professionals believe their leadership overestimates the organisation’s readiness for a cyber incident.
He argues that controls can drift soon after an audit: firewall ports opened temporarily may remain exposed, suppliers can alter configurations, and new systems may be introduced between review periods.
The article advocates continuous control monitoring, in which live data is used to test controls continuously rather than reconstructing evidence on an audit timetable. Areas highlighted for monitoring include identity and access, frequently changing cloud configurations, remediation deadlines for critical vulnerabilities and the security posture of suppliers handling sensitive data.
Sridhar says organisations need not replace their existing governance, risk and compliance systems; instead, they should replace manual, point-in-time and sample-based inputs with automated, comprehensive evidence. He acknowledges concerns that continuous monitoring could generate more alerts, but argues that effective programmes prioritise failures linked to important contracts, customer commitments and regulatory obligations.
The approach is presented as consistent with NIST’s Cybersecurity Framework 2.0, released in 2024, which added a Govern function and frames cybersecurity as an enterprise risk requiring continuous, measurable outcomes.