Proving the Program Series

The Compliance Trap: What the Red Team Finds That Audits Miss

Why compliance trap OT cybersecurity programs pass audits but still miss real attack paths

CISA's SILENTSHIELD Red Team operated inside a federal civilian agency's network for five months before anyone in the organization knew. The agency was subject to FISMA, NIST SP 800-53, and the federal zero-trust mandate. Its compliance posture was, by the standards regulators currently measure, in order.

CISA's July 2024 advisory (AA24-193A) documented what the assessment actually found: 16 findings across four lessons, full domain compromise, access to tier-zero assets, and lateral movement into a partner organization through trust relationships compliance frameworks do not require organizations to validate.

Five months. Sixteen findings. In a compliance-audited environment.

What Compliance Measures, and What the Red Team Tests

This is the gap the Red Team measures. Compliance frameworks ask whether required controls exist. Red Team assessments ask whether those controls actually stop an adversary using current techniques. These are different questions. They reliably produce different answers. Knowing the difference is not an argument against compliance. It is the foundation of using compliance honestly.

Dragos describes the major OT frameworks (NIST CSF, ISA/IEC 62443, C2M2) as detailed guidelines for implementing controls, not as validated proof those controls stop attacks. NERC CIP audits the existence and documentation of controls inside the electronic security perimeter. NIST SP 800-82 Revision 3, published September 2023, offers voluntary guidance on OT control families. IEC 62443 defines zones, conduits, and security levels. None mandates adversarial testing to verify controls work against current threat actor tradecraft.

ISACA articulated the structural problem in its 2017 article Compliant, Yet Breached. Drawing on a Fortune 500 ransomware analysis, the article observed that attackers focused on overcoming the actual security controls while internal teams measured security against compliance certification requirements. Two teams, two definitions of secure, one adversary. That phrasing is nearly a decade old. The pattern has not changed.

Red Team assessments measure something different. Not whether a firewall policy is documented. Whether the firewall stops the attacker. Not whether quarterly access reviews are performed. Whether a dormant VPN account that survived three reviews lets the Red Team in. Not whether logs are retained for the audit-required period. Whether analysts notice when those logs record an active intruder. Compliance documents what an organization does. The Red Team documents what happens when an adversary applies real techniques to that documentation.

What the Red Team Finds in Audited Environments

CISA's second public Red Team advisory, AA24-326A (November 2024), opens with a finding no security program wants to read. Initial access to a U.S. critical infrastructure organization was gained through a web shell left behind from a third party's previous security assessment. The Red Team moved from that web shell through the DMZ, into the domain, and onto an HMI: the dashboard for operational technology. CISA documented that leadership had deprioritized a vulnerability the organization's own cybersecurity team had flagged. The leadership misjudgment was logged as a finding in its own right.

That advisory is not an isolated case. Peer-reviewed research from Forescout and TU Clausthal on insecure-by-design conditions in OT products examined 45 deployed product families from 10 major vendors and documented 53 weaknesses in security-certified equipment. Forescout's 2025 Threat Roundup, analyzing more than 900 million attacks, found that 71% of exploited vulnerabilities are not in CISA's Known Exploited Vulnerabilities catalog. Compliance patching programs flag what is in KEV. Attackers exploit the rest.

The patterns are consistent. Default credentials on internet-exposed assets: the Iranian-affiliated CyberAv3ngers compromise of the Aliquippa, Pennsylvania water authority in November 2023 used a Unitronics PLC default password of 1111. Lateral movement in environments with documented perimeters: the east-west traffic gap NERC's CIP-015-1 finally addresses for the bulk electric system, effective September 2, 2025. Trust relationships that compliance does not scope. Living-off-the-land tradecraft that compliance cannot detect because it uses the legitimate admin tools compliance counts as controls. Volt Typhoon, the PRC state campaign CISA, NSA, and the FBI documented in 2023 and 2024, operated for years inside compliance-audited critical infrastructure networks using exactly that technique.

The Cadence Problem: Why Posture Drifts Between Audits

Compliance audits validate a posture that exists during the assessment window. Red Team engagements find what that posture looks like six months later. Configurations drift. MFA gets disabled temporarily. A vendor adds a remote access tool nobody inventories. A dormant account survives a quarterly review because no one owns the cleanup. None of that breaks the framework on paper. All of it changes the picture.

The audit burden makes this worse. MetricStream's 2025 review found that 58% of organizations conduct four or more audits annually, and 35% conduct six or more. Secureframe's 2026 Cybersecurity & Compliance Benchmark Report adds that security and compliance teams spend an average of eight hours per week on manual compliance tasks like evidence collection, documentation, and customer questionnaires.

The 2025 SANS State of ICS/OT Cybersecurity Survey, which Article 7 of this series drew on for its third-party access findings, recorded the corresponding capability gaps: only 13% of organizations have fully implemented advanced remote access controls, only 21% have integrated OT threat intelligence, and only 17% run ICS-specific tabletop exercises.

This is not a moral failure. It is the structural pull of work with external deadlines versus work without. American Gas Association's Kimberly Denbow described TSA's pipeline directives as having redirected cyber resources away from security and towards compliance. A Red Team finding resets that pull. It carries the same deadline an audit finding carries, but documents actual exposure rather than a paperwork gap.

How Regulators Are Closing the Gap

The frameworks themselves are moving. NERC CIP-015-1 mandates internal network security monitoring inside the electronic security perimeter, codifying lateral-movement visibility that decades of perimeter-only compliance never required. TSA Security Directive Pipeline-2021-02F, effective May 3, 2025, requires owners and operators to test at least two of five Cybersecurity Incident Response Plan objectives annually. TSA Administrator Pekoske framed the change directly when the earlier version landed: earlier directives required development of plans; the updated version requires operators to test and evaluate them.

NIS2, in force across the EU since October 2024 transposition deadlines, attaches personal accountability to management bodies, including potential temporary bans from leadership roles for governance failures. The Department of Defense's CMMC final rule, effective November 10, 2025, makes compliance representations legal facts under the False Claims Act, even where no cyber incident has occurred. The DOJ Civil Cyber-Fraud Initiative recovered $52 million in FY2025 alone.

On December 11, 2025, CISA published Cybersecurity Performance Goals 2.0, framing it as outcome-driven guidance. The same agency that runs SILENTSHIELD reshaped its framework around what its Red Team has been finding. Morgan Lewis's 2026 cybersecurity outlook summarized the direction: regulators are focusing less on one-off compliance artifacts and more on whether programs operate coherently at scale.

The 2025 SANS ICS/OT Cybersecurity Survey found 72% of organizations have increased investment in logging, monitoring, and detection because of regulations. The spend is following the regulatory shift, and the regulatory shift is following what adversarial validation has been documenting for years.

Compliance Is a Floor, Not a Ceiling

SANS 2025 data is candid about both halves of that proposition: sites under mandatory compliance have similar incident rates to their peers, but roughly 50% lower financial and safety impacts. Compliance reduces consequences. It does not eliminate exposure. Treating it as the ceiling is what creates the trap.

The vCISO series Article 8 covers how leadership positions compliance as a baseline rather than a destination, using adversarial evidence to argue for investment compliance does not require. The CFC series Article 8 covers how a properly built fusion center produces compliance as a byproduct of operational capability.

Article 5 of this series documented what the Red Team finds in the visibility space audits do not cover, and Article 6 traced the legacy ceiling that compliance frameworks cannot remediate. Shadow Current Blog 10 traced how attackers move through compliance-audited environments. This article is where adversarial validation meets that current and documents, with specific findings, where the audit ends and the attack path continues.

A compliance-shaped IR plan is a documented plan. The Red Team's next question is whether that plan holds together when a live attacker is already inside, when escalation authority is unclear, and when the IT-OT boundary is the line the incident has to cross. Article 9 is incident response under adversarial conditions. The plan is on paper. The adversary is in the network. We go there next.

Learn more about the OT vCISO role in this Executive Brief: The Missing Leadership Layer in Industrial Cybersecurity.

Sources: CISA Advisory AA24-193A (SILENTSHIELD), CISA Advisory AA24-326A, CISA Advisory AA24-038A (Volt Typhoon), CISA Advisory AA23-144A, CISA Advisory AA23-335A (Aliquippa), CISA Cybersecurity Performance Goals 2.0 (December 2025), Federal Register: NERC CIP-015-1 (July 2025), FERC Order No. 907, TSA Security Directive Pipeline-2021-02F, DoD CMMC final rule, European Commission NIS2 Directive 2022/2555, NIST SP 800-82 Rev. 3, ISA/IEC 62443 standards, Dragos Industrial Cybersecurity Compliance content, ISACA Journal Compliant, Yet Breached (2017), Forescout and TU Clausthal Insecure by Design in the Backbone of Critical Infrastructure, Forescout 2025 Threat Roundup, SANS 2025 State of ICS/OT Cybersecurity Survey, MetricStream 2025 IT Compliance Audit research, Secureframe 2026 Cybersecurity and Compliance Benchmark Report, Morgan Lewis Cybersecurity and Privacy 2026 Enforcement and Regulatory Trends, American Gas Association commentary via Cybersecurity Dive, DOJ False Claims Act Settlements and Judgments FY2025 Fact Sheet.

Audit proof is not attack proof.
Compliance can pass while exposure persists.
Red Team findings measure the difference.

5Months undetected in CISA SILENTSHIELD assessment
16Findings across four lessons in AA24-193A
71%Exploited vulns not listed in KEV per Forescout
58%Organizations running 4+ audits annually
72%Increased logging and detection investment due to regulation
Framework vs Adversary

Compliance asks if controls exist. Red Team asks if controls hold.

Click to explore

Both questions matter. The risk appears when organizations assume one answer automatically proves the other.

Audit Cadence Drift

Posture can drift faster than assessment windows detect.

Click to explore

Temporary exceptions, dormant accounts, and unmanaged remote access compound between audits and expand live attack paths.

Regulatory Shift

CIP-015-1, SD-02F, CMMC, and NIS2 push toward outcomes.

Click to explore

Regulators are increasingly asking programs to demonstrate operational effectiveness, not just policy and control documentation.

Living-off-the-Land Risk

Legitimate admin tools can carry attacker activity quietly.

Click to explore

When threat behavior matches normal operations tooling, checklist compliance rarely surfaces the active intrusion path in time.

Compliance Floor

Mandatory controls reduce consequence, but do not remove exposure.

Click to explore

The resilient program combines framework discipline with adversarial validation and cross-boundary incident execution readiness.

SILENTSHIELD SignalFive months undetected in an audited environment

CISA's AA24-193A demonstrates how documented compliance posture can coexist with deep adversary persistence and tier-zero compromise paths.

Audit-to-Operations TensionManual evidence burden vs capability maintenance

As audit frequency and manual compliance hours increase, unattended operational hardening work creates a recurring drift window attackers exploit.

Article 9 SetupIncident response under adversarial conditions

The next stage is validating whether incident response authority, IT-OT coordination, and escalation design hold under active adversary pressure.

Audit programs validate documented control posture within defined framework scope and assessment windows.

Red Team operations validate whether controls resist current adversary behavior in the live environment under realistic conditions.

Current regulation is increasingly converging on outcome evidence, tested plans, and accountable governance performance.

Takeaway 1

Compliance can reduce impact while still leaving exploitable attack paths unresolved.

Takeaway 2

Adversarial validation explains why audits and incidents can diverge in the same environment.

Takeaway 3

The compliance trap closes when programs treat compliance as baseline and test capability continuously.

Scroll to Top