Integrating Security and Compliance Teams to Curb Modern Risks
July 12, 2022

Colin Fallwell
Sumo Logic

Share this

As the world's technology rapidly evolved and threats skyrocketed in the cloud, the need for security and compliance teams to come together to protect organizations and their customers has never been more important. Unfortunately, this hasn't happened yet.


In partnership with Enterprise Management Associates (EMA), we polled 204 technology and business leaders in North America from more than ten industry verticals to investigate this theme. The research found that most organizations recognize the importance of managing both compliance and security functions in-house. Nearly 83% of respondents said that a corporate employee was responsible for information security and 88% said that IT audit and compliance functions are also handled internally.

Yet, while most organizations run internal compliance and security teams, their status is not weighted equally. Compliance imperatives typically drive security priorities. However, organizations' combined security and compliance postures will be better served when both teams work together, and budgets and investments should reflect that equal importance.

Key takeaways from the research include:

Security and compliance ownership and budgets are splintered

Security and compliance ownership and budgets are splintered. They often operate with different teams, budgets and investment levels, but they need to work together to better protect the organization's posture instead.

■ 47% said that IT owns the security budget, while 11% noted that compliance is the security budget owner.

■ In the future, 86% of those surveyed plan to make a significant investment in compliance solutions and data privacy, while just over half (52%) will make a significant investment in a security management suite.

Compliance challenges amplified by rapidly growing IT environments

Compliance challenges are amplified by rapidly growing and global IT environments with different regulatory climates.

■ 39% of respondents said having multiple IT environments with different requirements is their primary compliance challenge.

■ 40% of organizations have postponed security projects to address regulatory compliance concerns.

■ 68% believe their regulatory compliance programs are a competitive differentiator.

■ 75% said that they are using existing tools or evaluating new tools to address data privacy.

compliance needs driving cybersecurity priorities

Organizations' compliance needs are driving cybersecurity priorities, causing teams to alter security strategies to align with requirements.

■ 67% said that data privacy regulations like GDPR, CCPA or changing data controls were their biggest compliance challenges.

■ 38% said that data security and privacy was the greatest security challenge in their organization

■ 25% stated that information security projects are dependent on compliance projects

■ 76% said that compliance has completely or significantly shifted their security strategy

Compliance and security teams must work together

Compliance and security teams must work together to best manage a mature and robust program, while maintaining numerous attestations and controls globally.

■ 89% indicated that the priorities of the security and compliance teams were aligned.

■ 85% stated that the security tools used adequately address compliance considerations.

■ 59% indicated that data privacy regulations have impacted their approach to security.

Integrated Security and Compliance Solutions

This survey also signaled the growing demand for integrated security and compliance solutions that increase visibility while mitigating emerging threats and privacy regulations. When organizations prioritize DevSecOps, they can better maintain compliance, especially as they are expected to comply with multiple standards, including PCI, HIPAA, PII, SOC and GDPR, in highly regulated industries.

It is undeniable that all organizations will benefit from incorporating a security-centric culture and fostering better collaboration between security and compliance teams. Organizations must adopt solutions that provide real-time monitoring for continuous compliance and help maintain system security.

Colin Fallwell is Field CTO of Sumo Logic
Share this

The Latest

August 12, 2022

The development of the Thousand Brains Theory of Intelligence framework will now serve as a foundation for further research and new developments in Artificial Intelligence (AI) and Machine Learning (ML) ...

August 11, 2022

IT teams feel overwhelmed by too many tools that do not provide a unified view of the entire IT infrastructure, according to The Shift to Unified Observability: Reasons, Requirements, and Returns, a new independent survey conducted by IDC in collaboration with Riverbed ...

August 10, 2022

Legacy systems require a great deal of a prior knowledge, and then significant configuration, for anomaly detection to work effectively. ML and AI are beginning to change that, but it's important to really validate the claims of any NPM solution ...

August 09, 2022

Successful insight into the performance of a company's networks starts with effective network performance management (NPM) tools. However, with the plethora of options it can be overwhelming for IT teams to choose the right one. Here are 10 essential questions to ask before selecting an NPM tool ...

August 08, 2022

Hybrid and remote work environments have been growing significantly in the past few years. As individuals move away from traditional office settings in today's new remote and hybrid environments, many operational issues such as poor visibility into asset status and refreshes, unaccounted assets, and overspending on software are becoming a bigger challenge for IT departments ...

August 05, 2022

MLOps or Machine Learning Operations are a combination of best processes and practices that businesses use to run AI successfully ... While it is a relatively new field, MLOps is a collective effort that captured the interest of data scientists, DevOps engineers, AI enthusiasts, and IT ...

August 04, 2022

The data is in: enterprises are not happy with their managed service providers (MSPs) and cloud service providers (CSPs). According to the latest CloudBolt Industry Insights report, Filling the Gap: Service Providers' Increasingly Important Role in Multi-Cloud Success, 80% are so unsatisfied with their existing MSP and/or CSP, they are actively looking to replace them within 12 months ...

August 03, 2022

The last two years have accelerated massive changes in how we work, do business, and engage with customers. According to Pega research, nearly three out of four employees (71%) feel their job complexity continues to rise as customer demands increase, and employees at all levels feel overloaded with information, systems, and processes that make it difficult to adapt to these new challenges and meet their customers' growing needs ...

August 02, 2022

Investing in employees will always be smart business. And right now, investing in employees means giving people the resources — and ability — to optimize performance ... For pretty much every company, that means delivering the digital tools necessary to facilitate seamless, secure, user-friendly access and connectivity ...

August 01, 2022

Digital transformation can be the difference between becoming the next Netflix and becoming the next Blockbuster Video. With corporate survival on the line, "digital transformation" is no longer merely an impressive buzzword to throw around in boardrooms. It's the ticket for entry into the digital era, a fundamental business strategy for every modern company ...