Strategy, Not Scorecards
How the OT vCISO escapes the OT compliance trap by holding compliance and resilience together
This is the eighth article in The Leadership Layer series, exploring how the OT vCISO builds cyber-resilient industrial organizations. Previous entries covered the vacancy at the top, the accountability gap, building an honest baseline, closing the OT threat intelligence gap, making visibility a funded priority, governing legacy OT risk, and owning the vendor risk.
PwC's 2025 Global Digital Trust Insights survey of more than 4,000 executives found only 2% of organizations have implemented cyber resilience measures across all surveyed areas.
A-LIGN's 2025 compliance benchmark found 92% of organizations now run at least two audits annually, and 35% run six or more. We are auditing more than ever. We are resilient almost nowhere.
What the Frameworks Actually Buy You
The compliance trap is not that compliance is wrong. It is that an organization can satisfy every framework on the list and still fail under a real adversary, because the work that produces audit-ready documentation is not the same work that produces operational resilience. Holding both standards at once is the vCISO's job. Confusing them is the trap.
NERC CIP gives the North American electric sector mandatory rules with $1 million per day penalties and approximately 1,636 unique U.S. entities currently registered for compliance. NIST SP 800-82 Revision 3, published in September 2023, is the federal guide that aligns OT security with the NIST Cybersecurity Framework's five functions. IEC 62443 is the international standard family that fills in engineering specifics, with security levels keyed to threat actor capability. The EU's NIS2 Directive is law, with administrative fines up to €10 million or 2% of global turnover and personal accountability for management bodies, including the possibility of temporary bans for governance failures.
These frameworks buy real things. They establish a documented baseline, force structured risk management, and create defensible evidence that an organization is taking cybersecurity seriously. They do not buy resilience validation, continuous adversarial testing, or proof that controls actually work when something goes wrong. SANS's 2025 State of ICS/OT Security Report, drawn from 330+ practitioners, puts it directly: regulation should serve as a springboard, not a ceiling, treated as the starting point for stronger detection, response, and culture-wide integration.
What the Compliance Trap Costs in 2025
The data tells the same story from several directions at once. Bridewell's survey of UK critical national infrastructure operators recorded that 95% had been breached in the year ending March 2025. Verizon's 2025 Data Breach Investigations Report found that third-party involvement in breaches doubled to 30% year-over-year, exactly the area compliance frameworks have historically been weakest on, and the same architectural gap 7 examined in depth. Waterfall Security's 2025 OT Cyber Threat Report logged a 146% year-over-year increase in sites suffering physical impairment from cyberattacks, rising from 412 in 2023 to 1,015 in 2024. IBM's 2024 Cost of a Data Breach report puts the average industrial-sector breach at $5.56 million, an 18% increase from the previous year.
Jaguar Land Rover crystallizes the lesson. The August through October 2025 cyberattack against JLR is now estimated by the UK's Cyber Monitoring Centre as the most economically damaging cyberattack in British history, with roughly £1.9 billion in total damage and production halted across the UK, Slovakia, Brazil, and India for multiple weeks. JLR was not under-resourced. The company had a substantial multi-year cybersecurity contract with Tata Consultancy Services. Attackers exploited a third-party software vulnerability and used credentials stolen as far back as 2021 that were still working in 2025. Compliance investment was present. Resilience was not.
What Regulators Are Now Demanding
The regulatory ground is moving in the same direction the data points. NERC's CIP-015-1 standard, approved by FERC in Order No. 907 on June 26, 2025, and effective September 2, 2025, requires internal network security monitoring of high-impact and medium-impact bulk electric system cyber systems. FERC's own justification was explicit: current CIP standards leave a reliability and security gap by not implementing internal network security monitoring inside trusted CIP-networked environments. TSA's November 2024 Notice of Proposed Rulemaking on surface cyber risk management requires owner-operators to develop a Cybersecurity Assessment Plan describing how they will proactively, regularly, and completely assess the effectiveness of cybersecurity measures. TSA Administrator David Pekoske framed the shift directly: continuous monitoring and auditing to assess achievement of cybersecurity outcomes.
The SEC's cybersecurity disclosure rule, effective December 2023, requires public companies to describe board oversight of cybersecurity risks and management's role and expertise in addressing them. The convergence is unmistakable. NERC wants continuous internal visibility, the same visibility imperative 5 argued the vCISO has to fund. NIS2 wants demonstrated resilience and personal leader accountability. TSA wants outcomes, not controls. The SEC wants governance quality on the record. The standard the regulator is moving to is no longer that documents exist. It is that outcomes are demonstrated.
The vCISO's Dual Mandate
The trap closes when an organization treats compliance and resilience as sequential, separate, or in tension. The vCISO holds them as simultaneous and sequenced. Compliance is the floor, the work that has to happen for the organization to operate legally and answer regulators credibly. Resilience is what gets built above the floor: continuous visibility, adversarial validation, exercised incident response, threat-informed defense, and continuous governance. SANS's data is the rebuttal to anyone reading this as anti-compliance. Compliance, properly implemented, can consistently reduce incident impact. The argument is not against compliance. It is against confusing compliance with capability, which is the maturity mirage 3 named directly.
What the vCISO brings to that work is the specific combination required: deep enough in the regulatory landscape to ensure the floor is met, deep enough in OT adversarial reality to know where the floor is too low. Fortinet's 2025 State of Operational Technology and Cybersecurity Report found that 52% of organizations now place OT under the CISO, up from 16% in 2022, but title transfer is not capability transfer, which is the accountability gap 2 traced. PwC's 2025 Global Digital Trust Insights captures the same gap from the executive side: a 13-percentage-point confidence gap on regulatory compliance, where CEOs are materially more confident than their CISOs that the organization can meet AI, resilience, and critical infrastructure requirements. The board is more confident than the people doing the work. The vCISO is the executive who closes that gap by holding both standards and translating between them.
What Beyond Compliance Looks Like
The capabilities that distinguish a resilient program from a merely compliant one are concrete. Continuous monitoring and visibility, which CIP-015 now mandates for the electric sector but which SANS reports only 13% of organizations have across the full ICS Cyber Kill Chain. Adversarial validation, which TSA's NPRM codifies as a required component of Cybersecurity Assessment Plans for surface transportation, moving an existing security-directive mandate into permanent federal regulation. Incident response exercised by the engineers who would actually run it, which SANS finds nearly doubles preparedness. Recovery readiness, which is barely addressed by any compliance framework and which a later article in this series will examine. Threat-informed defense, drawing on ICS-specific intelligence rather than generic IT feeds. The vCISO is the executive who sequences these so the compliance baseline is met first and the resilience layer is built deliberately above it.
Compliance is what you owe the regulator. Resilience is what you owe the people on the operations floor.
Treating those as the same obligation produces audit-ready programs that fail under attack. Building genuine capability rather than audit-optimized controls is the strategic challenge.
Compliance Is the Floor, Not the Ceiling
Compliance is what you owe the regulator. Resilience is what you owe the people on the operations floor. Treating those as the same obligation produces audit-ready programs that fail under attack. The vCISO holds them together: meeting the floor, building above it, and refusing to confuse documentation with capability.
The ultimate test of any program is whether it can execute when an incident actually happens. That is what the next article in this series examines, and why OT incident response governance is one of the most critical things the OT vCISO owns.
The broader leadership context is covered in the executive webinar The Missing Layer in Industrial Cybersecurity, which reinforces why governance ownership has to sit above compliance artifacts.
Sources: PwC, A-LIGN, NERC, FERC, NIST, IEC, European Commission, SANS Institute, Bridewell, Verizon, Waterfall Security, IBM, UK Cyber Monitoring Centre, Jaguar Land Rover, Tata Consultancy Services, TSA, Federal Register, U.S. Securities and Exchange Commission, Fortinet.
Audit volume is rising.
Regulator expectations are rising.
Resilience capability still lags.
Compliance proves controls are documented. Resilience proves controls execute during high-stress operational reality. The trap is treating those proofs as identical.
Frameworks force structure, evidence, and accountability. They do not automatically provide adversarial validation, exercise quality, or proven recovery execution.
Bridewell, Verizon, Waterfall, IBM, and JLR outcomes point to the same pattern: audited controls are not enough unless resilience capabilities are continuously tested.
The standard is moving to continuous visibility, validated control effectiveness, and accountable governance quality that can be shown on demand.
Compliance is the legal floor. Resilience is the capability layer above it. Leadership value comes from sequencing both without sacrificing either.
Between August and October 2025, attackers reportedly exploited a third-party software vulnerability and used stolen credentials that remained valid for years. Estimated damage reached roughly £1.9B.
The JLR event demonstrates the compliance trap at scale: spend can be real, documentation can exist, and operational resilience can still fail under adversarial pressure.
NERC now requires internal network monitoring for defined electric-sector systems. TSA calls for proactive and complete assessments of control effectiveness. SEC requires board and management governance disclosures. NIS2 drives demonstrated resilience with leadership accountability.
The common signal is simple: produce measurable outcomes, not only control inventories.
Continuous monitoring and kill-chain visibility, adversarial validation, exercised incident response, recovery readiness, and threat-informed defense form the operational layer that audit programs alone do not provide.
This sequencing model follows the strategic pattern developed in Articles 2, 3, 5, and 7.
Framework alignment, control documentation, policy traceability, and defensible audit evidence are required to operate legally and credibly. This is the minimum line, not the finish line.
Outcome-oriented resilience adds tested detection, rehearsed response, failure-mode recovery, and threat-informed control tuning. This is where programs stop being audit-ready only and become attack-ready.
Boards need evidence that governance produces measurable incident outcomes. The OT vCISO closes the executive confidence gap by translating technical execution into continuity, risk, and accountability language.
Compliance and resilience are related but not equivalent. Treating them as the same creates the OT compliance trap.
Regulators are converging on outcomes, effectiveness evidence, and governance accountability across critical sectors.
The OT vCISO creates value by meeting the compliance floor and deliberately building resilient capability above it.
