Global spending on regulatory compliance reached 213 billion dollars in 2025 (Gartner). That same year, data breaches notified to European authorities rose 22 percent over 2024 (ENISA). The correlation is not a coincidence. Organisations that invest heavily in compliance are not necessarily better protected. Sometimes they are better exposed.
The pattern has a name: the compliance-first approach. It treats regulatory compliance as the goal of the security function rather than as an indicator of an actual security state. This article sets out how that approach manufactures risk, what the organisations that escaped it do differently, and how to assess where you stand.
What compliance-first actually produces
Regulatory compliance runs on a logic of state: on the date of the audit, do your controls meet the framework's requirements? That logic is fundamentally incompatible with the nature of cyber risk, which is dynamic, continuous, and indifferent to audit calendars.
NIS2 requires a documented, maintained risk management policy. DORA imposes operational resilience testing on a defined schedule. ISO 27001 certifies an information security management system at a periodic audit. In all three cases, compliance demonstrates a state, not a capability. An ISO 27001 certificate issued in January says nothing about your security posture in September.
The first organisation to suffer a mass breach while holding current PCI-DSS compliance was not an outlier. It illustrated a structural property. Compliance looks backward. Risk looks forward. Aligning the two takes deliberate effort that compliance-first does not encourage.
Three mechanisms by which compliance worsens exposure
First: optimising the control rather than the resilience. When compliance is the goal, teams naturally optimise for the auditor's questions. They pick controls that document well, policies that write up cleanly, training that leaves a trail, not because those measures cut risk most effectively, but because they audit most easily.
Take privileged access management. Article 21 of NIS2 requires "policies on access control and asset management". A compliance-first programme will produce a documented access control policy, an annual rights review, and twelve months of retained logs. What does not appear in the audit report: that 23 percent of active administrator accounts belong to people who left more than six months ago (Presidio internal data, client scope 2025).
Second: resources drift toward reporting. In a compliance-first organisation, the share of the security budget spent on reporting, documentation and audit preparation grows structurally. A 2025 Forrester study of 240 European CISOs found that security teams in compliance-first organisations spend an average of 31 percent of their year on administrative compliance work, against 12 percent in organisations that adopted a risk-first approach.
Those nineteen points, for a team of ten, are two full-time equivalents on reporting rather than on detection, incident response, or improving technical controls. The residual risk of that drift is rarely modelled in the risk registers of the same organisations.
Third: the illusion of coverage. Meeting the ten requirements of NIS2 Article 21 does not mean you are protected against the attack paths most used by the APT groups active in your sector. Compliance frameworks are built by regulatory consensus, on revision cycles measured in years. Attackers adapt in weeks.
The most common error is validating compliance on a narrow scope, the systems declared in the NIS2 perimeter, while leaving out assets that, once compromised, open the way into it. Compliance-first encourages that restrictive scoping. It simplifies the audit, shrinks the documented perimeter, and produces a compliant result. It does not reduce the real risk.
What risk-first organisations do differently
Organisations that inverted the logic treat compliance as a by-product of their risk management programme, not as its objective. The distinction is operational as much as semantic.
In practice, they build their risk register from real threat scenarios (MITRE ATT&CK, ENISA sector reports, threat intelligence) and only then identify the frameworks that address those risks. They do not start from regulatory requirements and map them onto assets. That inversion changes how controls are prioritised, how scope is defined, and where the budget goes.
In this model, preparing a NIS2 audit is not a special mobilisation. It is the output of documentation that already exists because it serves day-to-day risk management. Teams that prepare an audit through a six-week compliance sprint are signalling, without meaning to, that their security programme was not operational outside audit season.
How to assess where you stand
Four questions diagnose whether your organisation is compliance-first or risk-first.
Is your risk register updated between audits, or mostly while preparing for one? Are your controls prioritised by their effect on residual risk, or by their presence in a regulatory requirement? Does your security perimeter cover the assets carrying the highest risk, or the assets declared in your compliance scope? Does your CISO report on security posture, or on compliance rate?
If three of the four point toward compliance, your programme is structurally compliance-first, whatever language you use to describe it.
Presidio includes a GRC maturity assessment that maps your programme along these dimensions and shows where compliance is over-funded and risk under-funded. See the assessment module →
Conclusion
Three things to keep. Compliance measures a past state: it does not predict your ability to withstand a future attack. Optimising for reporting diverts resources from actual risk reduction, at a cost that is rarely modelled. And the illusion of coverage, compliant without being secure, is the most underrated operational risk in GRC programmes in 2026.
Organisations that leave compliance-first behind do not cut their compliance spending. They redirect it toward what actually reduces exposure. The difference rarely shows in audit reports. It shows in incidents.
In your own context, how much of your security programme would survive an audit of relevance rather than an audit of compliance?
Read next: GRC automation: calculated ROI against what the data says.
