Integrating Security and Compliance Teams to Curb Modern Risks
July 12, 2022

Colin Fallwell
Sumo Logic

Share this

As the world's technology rapidly evolved and threats skyrocketed in the cloud, the need for security and compliance teams to come together to protect organizations and their customers has never been more important. Unfortunately, this hasn't happened yet.


In partnership with Enterprise Management Associates (EMA), we polled 204 technology and business leaders in North America from more than ten industry verticals to investigate this theme. The research found that most organizations recognize the importance of managing both compliance and security functions in-house. Nearly 83% of respondents said that a corporate employee was responsible for information security and 88% said that IT audit and compliance functions are also handled internally.

Yet, while most organizations run internal compliance and security teams, their status is not weighted equally. Compliance imperatives typically drive security priorities. However, organizations' combined security and compliance postures will be better served when both teams work together, and budgets and investments should reflect that equal importance.

Key takeaways from the research include:

Security and compliance ownership and budgets are splintered

Security and compliance ownership and budgets are splintered. They often operate with different teams, budgets and investment levels, but they need to work together to better protect the organization's posture instead.

■ 47% said that IT owns the security budget, while 11% noted that compliance is the security budget owner.

■ In the future, 86% of those surveyed plan to make a significant investment in compliance solutions and data privacy, while just over half (52%) will make a significant investment in a security management suite.

Compliance challenges amplified by rapidly growing IT environments

Compliance challenges are amplified by rapidly growing and global IT environments with different regulatory climates.

■ 39% of respondents said having multiple IT environments with different requirements is their primary compliance challenge.

■ 40% of organizations have postponed security projects to address regulatory compliance concerns.

■ 68% believe their regulatory compliance programs are a competitive differentiator.

■ 75% said that they are using existing tools or evaluating new tools to address data privacy.

compliance needs driving cybersecurity priorities

Organizations' compliance needs are driving cybersecurity priorities, causing teams to alter security strategies to align with requirements.

■ 67% said that data privacy regulations like GDPR, CCPA or changing data controls were their biggest compliance challenges.

■ 38% said that data security and privacy was the greatest security challenge in their organization

■ 25% stated that information security projects are dependent on compliance projects

■ 76% said that compliance has completely or significantly shifted their security strategy

Compliance and security teams must work together

Compliance and security teams must work together to best manage a mature and robust program, while maintaining numerous attestations and controls globally.

■ 89% indicated that the priorities of the security and compliance teams were aligned.

■ 85% stated that the security tools used adequately address compliance considerations.

■ 59% indicated that data privacy regulations have impacted their approach to security.

Integrated Security and Compliance Solutions

This survey also signaled the growing demand for integrated security and compliance solutions that increase visibility while mitigating emerging threats and privacy regulations. When organizations prioritize DevSecOps, they can better maintain compliance, especially as they are expected to comply with multiple standards, including PCI, HIPAA, PII, SOC and GDPR, in highly regulated industries.

It is undeniable that all organizations will benefit from incorporating a security-centric culture and fostering better collaboration between security and compliance teams. Organizations must adopt solutions that provide real-time monitoring for continuous compliance and help maintain system security.

Colin Fallwell is Field CTO of Sumo Logic
Share this

The Latest

May 23, 2024

Hybrid cloud architecture is breaking the backs of network engineering and operations teams. These teams are more successful when their companies go all-in with the cloud or stay out of it entirely. When companies maintain hybrid infrastructure, with applications and data residing across data centers and public cloud services, the network team struggles. This insight emerged in the newly published 2024 edition of Enterprise Management Associates' (EMA) Network Management Megatrends research ...

May 22, 2024

As IT practitioners, we often find ourselves fighting fires rather than proactively getting ahead ... Many spend countless hours managing several tools that give them different, fractured views of their own work — which isn't an effective use of time. Balancing daily technical tasks with long-term company goals requires a three-step approach. I'll share these steps and tips for others to do the same ...

May 21, 2024

IT service outages are more than a minor inconvenience. They can cost businesses millions while simultaneously leading to customer dissatisfaction and reputational damage. Moreover, the constant pressure of dealing with fire drills and escalations day and night can take a heavy toll on ITOps teams, leading to increased stress, human error, and burnout ...

May 20, 2024

Amid economic disruption, fintech competition, and other headwinds in recent years, banks have had to quickly adjust to the demands of the market. This adaptation is often reliant on having the right technology infrastructure in place ...

May 17, 2024

In MEAN TIME TO INSIGHT Episode 6, Shamus McGillicuddy, VP of Research, Network Infrastructure and Operations, at EMA discusses network automation ...

May 16, 2024

In the ever-evolving landscape of software development and infrastructure management, observability stands as a crucial pillar. Among its fundamental components lies log collection ... However, traditional methods of log collection have faced challenges, especially in high-volume and dynamic environments. Enter eBPF, a groundbreaking technology ...

May 15, 2024

Businesses are dazzled by the promise of generative AI, as it touts the capability to increase productivity and efficiency, cut costs, and provide competitive advantages. With more and more generative AI options available today, businesses are now investigating how to convert the AI promise into profit. One way businesses are looking to do this is by using AI to improve personalized customer engagement ...

May 14, 2024

In the fast-evolving realm of cloud computing, where innovation collides with fiscal responsibility, the Flexera 2024 State of the Cloud Report illuminates the challenges and triumphs shaping the digital landscape ... At the forefront of this year's findings is the resounding chorus of organizations grappling with cloud costs ...

May 13, 2024

Government agencies are transforming to improve the digital experience for employees and citizens, allowing them to achieve key goals, including unleashing staff productivity, recruiting and retaining talent in the public sector, and delivering on the mission, according to the Global Digital Employee Experience (DEX) Survey from Riverbed ...

May 09, 2024

App sprawl has been a concern for technologists for some time, but it has never presented such a challenge as now. As organizations move to implement generative AI into their applications, it's only going to become more complex ... Observability is a necessary component for understanding the vast amounts of complex data within AI-infused applications, and it must be the centerpiece of an app- and data-centric strategy to truly manage app sprawl ...