All articles
'Certified and Still Breached' Is Forcing CISOs To Look Beyond A Badge
Adedayo Adetoye, CISO at GLG, makes the case for running security as dollar-denominated risk management, where compliance builds useful organizational muscle but never substitutes for knowing what an attack would actually cost the business.

Make The Security Digest one of your go-to sources on Google
Compliance is useful, but it's not sufficient. So many organizations that have been breached are actually compliant. They have certifications all over the place, yet they still got breached.
The views and opinions expressed are those of Dr. Adedayo Adetoye and do not represent the official policy or position of any organization.
Breach reports keep featuring companies with current certifications. SOC 2 complete, ISO 27001 renewed, auditors satisfied, while the attacker breaches anyway. The pattern says less about compliance than about what the badge was never designed to measure – and as AI shortens the distance between a vulnerability being found and being used, the price of confusing the two keeps climbing.
Dr. Adedayo Adetoye is the Chief Information Security Officer at GLG, the world's leading platform for trusted human expertise. He holds a PhD in computer science and did postdoctoral research on critical infrastructure resilience at Oxford and Warwick. He spent nearly a decade at Mimecast, finishing as director of security architecture and engineering. A certified CISO and Open FAIR risk professional, his through line is that risk came first in his career and compliance was a stop along the way.
"Certifications are useful, but they're not sufficient. So many organizations that have been breached are actually compliant," Adetoye says. "They have certifications all over the place, yet they still got breached."
What certifications actually buy
None of that makes him dismissive of the badge. In regulated markets, it's the ticket to doing business at all, and elsewhere it reassures customers during the sales motion. The deeper value, however, is internal.
"The biggest value compliance brings to the table is the permission structure. We need to do this to be certified. Over time, that builds muscle memory within the organization," he says. Access reviews and pen test evidence become routine because certification demands them, and the executive alignment does real work. "Because you have that alignment, it's easier to get those requests serviced. The business wants the certification badge."
The appetite has to land somewhere
The job itself is different. "As a CISO, your job is to manage the business risk within appetite. Being compliant to a given standard may be part of that job, but it's not your primary job," Adetoye says. "A CISO that builds their whole strategy around gaining badges is not doing a proper job for their company."
Managing within appetite means forcing the appetite to mean something. Every business claims it can't afford for anything to go wrong. "You've got to find where that risk appetite really lands. What does that mean in dollar terms?" The conversation with the board starts from the high-value assets – whether that's intellectual property, service availability, or client data – and works backward to the scenarios that threaten them.
Shields and shock absorbers
Adetoye sorts the resulting controls into two kinds. "Shields are controls that prevent attacks from materializing. Shock absorbers are the controls that reduce the impact when they do materialize," he says. "In a car you have brakes. They prevent you from having a crash, but there's no guarantee you won't have one. That's why you have airbags."
Run ransomware through the frame and the roles separate cleanly. MFA on data processing systems and EDR on endpoints are shields. Tested backups are the shock absorber, the thing that turns a detonation into a restore instead of a catastrophe.
Three surfaces where AI goes wrong
AI pressures both columns at once. Attackers needed skill to weaponize a vulnerability, and now pointing a model at a platform lowers that bar, compressing the discovery-to-exploit timeline. His response is symmetrical. "You fight AI with AI, to find the vulnerabilities myself, before the bad guys do."
On the risk side, he maps three work surfaces. The browser, where employees can feed business data into unsanctioned chatbots no matter which ones are approved. The endpoint, where coding agents inherit whatever their operator can touch. "The agent is working in the context of those privileges, and hallucination or prompt injection could lead to the agent acting with the same permissions as the privileged engineer, causing serious damage." And the product itself – where AI features in a SaaS platform can be steered into behavior nobody designed. The same triage capability, pointed inward, relieves SOC teams drowning in alerts before burnout does the attackers' work for them.
What he won't do is stand in the doorway. Engineers arrive already using agents at home and push to bring them to work. "A CISO can't afford to be the innovation killer. The smart move is to say yes, we understand, but let's put guardrails in. Let's work together," Adetoye says. Even that is provisional. "The field is evolving so fast that the guardrails you provide today are obsolete by tomorrow. You've got to evolve as well."






