Integrating Security and Compliance Teams to Curb Modern Risks
July 12, 2022

Colin Fallwell
Sumo Logic

Share this

As the world's technology rapidly evolved and threats skyrocketed in the cloud, the need for security and compliance teams to come together to protect organizations and their customers has never been more important. Unfortunately, this hasn't happened yet.


In partnership with Enterprise Management Associates (EMA), we polled 204 technology and business leaders in North America from more than ten industry verticals to investigate this theme. The research found that most organizations recognize the importance of managing both compliance and security functions in-house. Nearly 83% of respondents said that a corporate employee was responsible for information security and 88% said that IT audit and compliance functions are also handled internally.

Yet, while most organizations run internal compliance and security teams, their status is not weighted equally. Compliance imperatives typically drive security priorities. However, organizations' combined security and compliance postures will be better served when both teams work together, and budgets and investments should reflect that equal importance.

Key takeaways from the research include:

Security and compliance ownership and budgets are splintered

Security and compliance ownership and budgets are splintered. They often operate with different teams, budgets and investment levels, but they need to work together to better protect the organization's posture instead.

■ 47% said that IT owns the security budget, while 11% noted that compliance is the security budget owner.

■ In the future, 86% of those surveyed plan to make a significant investment in compliance solutions and data privacy, while just over half (52%) will make a significant investment in a security management suite.

Compliance challenges amplified by rapidly growing IT environments

Compliance challenges are amplified by rapidly growing and global IT environments with different regulatory climates.

■ 39% of respondents said having multiple IT environments with different requirements is their primary compliance challenge.

■ 40% of organizations have postponed security projects to address regulatory compliance concerns.

■ 68% believe their regulatory compliance programs are a competitive differentiator.

■ 75% said that they are using existing tools or evaluating new tools to address data privacy.

compliance needs driving cybersecurity priorities

Organizations' compliance needs are driving cybersecurity priorities, causing teams to alter security strategies to align with requirements.

■ 67% said that data privacy regulations like GDPR, CCPA or changing data controls were their biggest compliance challenges.

■ 38% said that data security and privacy was the greatest security challenge in their organization

■ 25% stated that information security projects are dependent on compliance projects

■ 76% said that compliance has completely or significantly shifted their security strategy

Compliance and security teams must work together

Compliance and security teams must work together to best manage a mature and robust program, while maintaining numerous attestations and controls globally.

■ 89% indicated that the priorities of the security and compliance teams were aligned.

■ 85% stated that the security tools used adequately address compliance considerations.

■ 59% indicated that data privacy regulations have impacted their approach to security.

Integrated Security and Compliance Solutions

This survey also signaled the growing demand for integrated security and compliance solutions that increase visibility while mitigating emerging threats and privacy regulations. When organizations prioritize DevSecOps, they can better maintain compliance, especially as they are expected to comply with multiple standards, including PCI, HIPAA, PII, SOC and GDPR, in highly regulated industries.

It is undeniable that all organizations will benefit from incorporating a security-centric culture and fostering better collaboration between security and compliance teams. Organizations must adopt solutions that provide real-time monitoring for continuous compliance and help maintain system security.

Colin Fallwell is Field CTO of Sumo Logic
Share this

The Latest

December 08, 2022

Industry experts offer thoughtful, insightful, and often controversial predictions on how APM, AIOps, Observability, OpenTelemetry and related technologies will evolve and impact business in 2023. Part 4 covers monitoring, site reliability engineering and ITSM ...

December 07, 2022

Industry experts offer thoughtful, insightful, and often controversial predictions on how APM, AIOps, Observability, OpenTelemetry and related technologies will evolve and impact business in 2023. Part 3 covers OpenTelemetry ...

December 06, 2022

Industry experts offer thoughtful, insightful, and often controversial predictions on how APM, AIOps, Observability, OpenTelemetry and related technologies will evolve and impact business in 2023. Part 2 covers more on observability ...

December 05, 2022

The Holiday Season means it is time for APMdigest's annual list of Application Performance Management (APM) predictions, covering IT performance topics. Industry experts — from analysts and consultants to the top vendors — offer thoughtful, insightful, and often controversial predictions on how APM, observability, AIOps and related technologies will evolve and impact business in 2023. Part 1 covers APM and Observability ...

December 01, 2022

You could argue that, until the pandemic, and the resulting shift to hybrid working, delivering flawless customer experiences and improving employee productivity were mutually exclusive activities. Evidence from Catchpoint's recently published Site Reliability Engineering (SRE) industry report suggests this is changing ...

November 30, 2022

There are many issues that can contribute to developer dissatisfaction on the job — inadequate pay and work-life imbalance, for example. But increasingly there's also a troubling and growing sense of lacking ownership and feeling out of control ... One key way to increase job satisfaction is to ameliorate this sense of ownership and control whenever possible, and approaches to observability offer several ways to do this ...

November 29, 2022

The need for real-time, reliable data is increasing, and that data is a necessity to remain competitive in today's business landscape. At the same time, observability has become even more critical with the complexity of a hybrid multi-cloud environment. To add to the challenges and complexity, the term "observability" has not been clearly defined ...

November 28, 2022

Many have assumed that the mainframe is a dying entity, but instead, a mainframe renaissance is underway. Despite this notion, we are ushering in a future of more strategic investments, increased capacity, and leading innovations ...

November 22, 2022

Most (85%) consumers shop online or via a mobile app, with 59% using these digital channels as their primary holiday shopping channel, according to the Black Friday Consumer Report from Perforce Software. As brands head into a highly profitable time of year, starting with Black Friday and Cyber Monday, it's imperative development teams prepare for peak traffic, optimal channel performance, and seamless user experiences to retain and attract shoppers ...

November 21, 2022

From staffing issues to ineffective cloud strategies, NetOps teams are looking at how to streamline processes, consolidate tools, and improve network monitoring. What are some best practices that can help achieve this? Let's dive into five ...