July 19, 2026
Every Breached Company Had the Certificate
A security founder’s honest defence of compliance — and its limits
By Akshay Dubey
5 min read
A security founder's honest defence of compliance — and its limits
I run a security company, so people assume I will say compliance is useless checkbox theatre. That is the fashionable opinion in our industry. Every conference has one speaker making jokes about auditors.
I actually believe the opposite. I think compliance is one of the most useful things a company can do for its security. But I believe it for a completely different reason than most people think, and if you hold this belief the wrong way, it will get you breached. So let me explain both sides properly, with real numbers, because I have seen too many engineering leaders learn this the expensive way.
First, the uncomfortable facts
In September 2013, Target's systems were certified compliant with PCI DSS — around 300 requirements, assessed by an independent third party. Their own CFO told the US Senate this, under oath. Roughly two months later, attackers were inside the network. They came in using credentials stolen from a refrigeration vendor — not through some genius zero-day, but through a vendor's login for a billing portal. Forty million payment cards. Personal data of up to seventy million more people. Target's own SEC filings put the cumulative expense at $292 million.
Heartland Payment Systems passed its PCI assessment in April 2008. Nine months later it disclosed what was then the largest card breach ever known — the federal indictment for that scheme charged theft of more than 130 million card numbers. The CEO, Robert Carr, later said something that made the whole industry angry: "The audits done by our QSAs were of no value whatsoever." Harsh words. But here is the detail people forget — Visa's risk officer replied with something even more interesting. She said no breached company has ever been found to be actually compliant at the moment of the breach. Think about that. The certificate said compliant. The reality was not. The certificate was a photograph; the network was a movie.
Anthem, one of the biggest health insurers in America, was regulated under HIPAA when attackers took data of 78.8 million people in 2015. They later paid a then-record $16 million to the US health regulator, plus $115 million in a class action. Equifax held an ISO 27001 certification — audited annually by an Ernst & Young affiliate, in place since at least 2011 — when the 2017 breach exposed data of roughly 147 million people. After the breach, their own annual report quietly mentioned that the certifications were suspended.
So if your belief is "we are compliant, therefore we are secure" — history is not on your side. Not even once.
Then why do I still defend compliance?
Because of what I have seen in companies that have nothing.
No asset inventory. Nobody knows how many cloud accounts exist, or who has admin on what. Logs going nowhere. An incident response plan that is basically "call Ramesh, he knows the system." Access given during some urgent release in 2022 and never removed. This is the normal state of most companies, honestly. Not because people are careless — because everyone is busy shipping.
Now watch what happens when that same company starts working towards ISO 27001 or SOC 2 seriously. Suddenly someone has to make the asset list. Someone has to answer "who can access production and why." Someone has to set up log retention, review access quarterly, write down what happens when things go wrong. Is that security? Not fully. But it is the skeleton of security. It forces the boring, unglamorous discipline that no engineering team does voluntarily, because there is always a feature deadline.
That is my honest position: compliance is the floor, not the ceiling. The companies in the stories above did not get breached because they were compliant. They got breached because they stopped at compliant. They treated the floor as the ceiling, framed the certificate, and relaxed. Meanwhile most companies that get breached never even had the floor.
So when someone asks me "should we do SOC 2 or should we do security" — the question itself is wrong. Do the compliance work sincerely and you will build 60–70% of a real security programme as a side effect. Just never confuse the certificate with the outcome.
One more thing people mix up: a law is not a certificate
This part genuinely confuses people, so let me separate three things that get called "compliance" in the same breath.
Laws and acts — GDPR, India's DPDP Act, the EU AI Act. Nobody certifies you against these. There is no auditor who stamps you "GDPR certified" (be careful of vendors selling exactly that). You are simply subject to the law, and a regulator can fine you — up to 4% of global revenue under GDPR, up to 7% under the EU AI Act. Saying "we adhere to the act" is a legal claim about your ongoing behaviour, not a badge.
Certifications and attestations — ISO 27001, SOC 2. Here a real auditor examines you and issues a report or certificate. Very valuable for trust and sales. But note what it actually is: an opinion about a scoped system, at a point in time or over a period. It expires. It samples. It cannot see what changed the day after the auditor left.
Frameworks — NIST CSF, OWASP's lists, CIS benchmarks. Pure guidance. Not certifiable, not enforceable, and frankly some of the most useful documents in security. Use them like a map, not like a shield.
So "compliant" is not one thing. You obey laws, you certify against standards, you adopt frameworks. A company can hold every certificate and still break the law, and a company can obey the law with zero certificates. Knowing which one you are talking about is half the maturity.
What actually keeps you secure
The certificate is a photograph taken on audit day. Attackers do not attack the photograph — they attack the live system, on a random Tuesday, three months after the auditor left, one hour after someone made an S3 bucket public "just for testing."
So the real work is making the compliant state continuous: knowing your inventory today, not last quarter. Knowing which identity can reach which system today. Catching the risky change in minutes, not at the next audit. Watching your attack surface the way an attacker does — from outside. Compliance tells you what good looks like. Continuous verification tells you whether you actually look like that right now. You need both, in that order.
If I compress this whole article into three lines, it is this:
- If you have no security programme, start with a serious compliance effort — it is the best forcing function you will ever get.
- The day you get the certificate, the real work begins, because the certificate is already ageing.
- And know what you are claiming — obeying a law, holding a certificate, and following a framework are three different sentences.
The companies that get hurt are not the ones that fail audits. They are the ones that pass, frame the certificate, and go back to sleep.
Full disclosure: I am the co-founder of EchelonGraph, a cloud and AI security company — so yes, I have a horse in this race. That's exactly why I've cited primary sources for every claim: Senate testimony and SEC filings for Target, the Federal Reserve Bank of Philadelphia's case study for Heartland, HHS for Anthem, and the Office of the Privacy Commissioner of Canada for Equifax. Please verify me — that habit is the whole point of the article.
Sources
- Senate Commerce Committee staff report, "A 'Kill Chain' Analysis of the 2013 Target Data Breach" (March 2014)
- John Mulligan (Target EVP/CFO), written testimony, US Senate (Feb/Mar 2014)
- Target Corp. Form 10-K FY2016 ($292M cumulative expenses; $202M net of insurance)
- Krebs on Security, "Target Hackers Broke in Via HVAC Company" (Feb 2014)
- Federal Reserve Bank of Philadelphia, Heartland Payment Systems case study (Jan 2010)
- CSO Online interview with Robert Carr (Aug 2009)
- US DOJ press release, Albert Gonzalez indictment (Aug 2009–130M+ card numbers)
- HHS Office for Civil Rights, Anthem resolution agreement ($16M, Oct 2018)
- In re Anthem Data Breach Litigation, $115M settlement (final approval Aug 2018)
- Office of the Privacy Commissioner of Canada, PIPEDA Findings #2019–001 (Equifax ISO 27001)
- Equifax Form 10-K FY2017 (certifications suspended; ~147M consumers)