October 2, 2026
Bad Cybersecurity Is Now a Compliance Failure
Jeff Darrington, Technical Marketing Director, Graylog

By Graylog
4 min read
Compliance and cybersecurity have long lived in separate parts of most org charts, with separate budgets, reporting lines, and assumptions about whose job it is when something goes wrong. That separation is collapsing, and a federal regulator just said so out loud, in front of exactly the audience least expecting to hear it.
Josh Goldfoot, a deputy assistant attorney general in the DOJ's Criminal Division, put a question to a room of compliance officers in Orlando, Florida this week: "If your organization is bad at cybersecurity, then ultimately, is it really complying with any of the policies you sought to enforce?"
FBI Special Agent Jason Cromartie, opening the same session, laid out why: the FBI's Internet Crime Complaint Center logged more than a million complaints in 2025 for the first time, up from roughly 860,000 the year before, with losses approaching $21 billion. Generative AI has erased the warning signs compliance training spent years teaching people to spot. Voice cloning has already cost one Fortune 500 company a million dollars through a single cloned executive voicemail.
Regulators in Brussels, New Delhi, and Singapore are asking a similar question this year through DORA, NIS2, and statutory logging mandates for critical infrastructure. Cybersecurity and compliance have merged into the same conversation everywhere. And once an organization has to prove what it did, a second question follows immediately: where is that proof actually allowed to live?
Retention was never the finish line
Every framework in this convergence rewards the same thing, and it isn't storage volume. DORA codifies it plainly: operational resilience is demonstrated by a documented capacity to detect, respond to, and report on incidents within defined timeframes, not by the existence of monitoring infrastructure. Treating "we retain logs for the required period" as a compliance posture stopped working. The actual question, and you'll hear it at the worst possible moment, is what you did with the data and whether you can prove it in a form someone can actually examine.
The fix for alert noise is also the fix for audit evidence
The structural fix for security effectiveness and the fix for compliance evidence turn out to be the same fix. Stop treating every log line as its own decision. Correlate related activity into a small number of confirmed incidents before anyone has to look at them one by one.
An asset and identity model that already recognizes which logs belong to which user or system, tracking accumulated risk across all of it, gives any analyst, or any AI applied on top, a narrow, already-relevant set of facts to reason over instead of an entire unstructured data lake. That's the difference between an agent asking "why did this specific user's risk just spike" and an agent trying to make sense of everything at once. It also happens to be a far more auditable question for a regulator to review later.
The paperwork has to write itself
Most organizations still fall short here. Regulators keep describing the same gap: an inability to show what actually happened during a response. That gap closes the moment documentation starts generating itself as a byproduct of the investigation, instead of getting reconstructed afterward in whatever format an auditor happens to want.
A summary built directly from the evidence already gathered during an investigation, what happened, the impact, what was done about it, turns hours of write-up into minutes. That reasoning has to be checkable, or it isn't really evidence. The underlying work matters as much as the conclusion: the prompt that was used, every tool call and what it returned, the path that led to a determination. An auditor examining an AI-assisted conclusion shouldn't have to take the AI's word for it any more than they'd take an analyst's word without a case file behind it.
Sovereignty has to follow the evidence, not just the logs
This is the part most compliance architectures still treat as an afterthought. Data residency, as most organizations implement it today, covers where raw logs land. It increasingly needs to cover a second category entirely: the audit trail and the AI-generated case summary built from those logs, because that document is the exact thing a regulator asks to see.
Plenty of organizations can honestly say their logs never leave the EU, while their incident summaries get generated or stored through infrastructure well outside that same boundary. Technically fine on the raw data question. Quietly not fine on the evidence question, since the document a DORA examiner requests was never fully confined to where its source data lived. Extending native, in-region storage through the full investigation and reporting lifecycle, not just the ingestion layer, closes both halves of that requirement at once, for the EU or anywhere else a regulator draws the same line.
The math backs it up
Goldfoot's own numbers make the business case regardless of which regulator you answer to. Organizations that paid a ransom got attacked 83% of the time again, with 93% having data stolen either way. Reporting to law enforcement fell from 52% of affected organizations in 2024 to 40% in 2025, moving the wrong direction as the threat accelerates.
Regulators on multiple continents are asking the same two-part question this year, independently: can you prove what you did, and can you prove that proof stayed exactly where you were required to keep it. Most platforms answer half of that, one region at a time. The organizations closing the whole gap aren't running three separate compliance programs. They're running one workflow where the evidence, not just the logs, was built to stay wherever it needs to from the start.
Graylog closes both halves of that gap in one workflow: verified incidents built from a correlated entity model, AI-generated case summaries with the full reasoning exposed rather than a black-box verdict, and native storage that keeps the resulting evidence within whichever jurisdiction requires it.
Follow Graylog on LinkedIn for practical guidance built for the teams running compliance and security together.