Which Compliance Signals Lead Risk Reduction, and Which Only Lag

A person with long hair sits at a desk, reviewing a printed report next to a computer monitor displaying data.

A compliance lead signs off a clean quarterly access review, files the Sarbanes-Oxley (SOX) attestation, and moves on. Three weeks later an offboarded contractor’s credential, one the review had marked active, pulls a payroll export, and the control meant to catch it had run only once, in the past. Compliance signals split into two kinds. Leading signals catch a problem before it becomes an incident; lagging signals document it after the fact. Know which is which, and you’ll know whether your program is risk-driven or just checking boxes.

Which compliance signals lead risk, and which only lag

Start by sorting the signals each framework produces. SOX governs access to financial-reporting systems through periodic IT general controls. HIPAA (Health Insurance Portability and Accountability Act) governs data protection for US health records. NIST SP 800-53 is the US government’s catalog of security and privacy controls. DORA (the EU Digital Operational Resilience Act) has, since January 2025, required EU financial firms to prove they can absorb IT disruption. A point-in-time attestation says a control existed on one date; a live measurement says whether it works now.

  • Lagging indicators: the SOX quarterly access certification, the annual HIPAA risk analysis, and the yearly NIST SP 800-53 assessment. Each certifies a state on a past date.
  • Leading indicators: exception rates on those same controls, mean time to revoke access, and live third-party concentration, which is DORA’s real concern. Each moves before an incident does.

Why an annual assessment lags the attacker’s tempo

The framework is rarely the problem; the sampling rate is. A control checked once a quarter produces a signal that is stale the day after it is checked, and attackers work in the gaps between audits. The offboarded contractor’s credential was compliant on review day and dangerous three weeks later, and nothing in the quarterly cadence was built to notice the change. We have made this case before: DORA compliance has to be more than a tick-box exercise.

The fix sits in the frameworks already. NIST 800-53 includes continuous monitoring as control CA-7, and NIST SP 800-137 defines information security continuous monitoring (ISCM) in full. Most programs run the point-in-time assessment and skip the continuous half, so a control that could lead risk ships as a lagging one instead. Your sampling rate can’t keep up with how fast the risk changes, and that is the real operational risk. No auditor checks for it.

How to turn a lagging signal into a leading one

Work in the order that closes the widest gap first: instrument the control, measure the cadence, then report the trend. Each step turns one lagging attestation into a signal that moves ahead of the risk.

Pair every periodic attestation with a continuous measurement – Behind the SOX quarterly access review, run automated recertification that alerts the day a dormant or orphaned credential is used, mapping to NIST 800-53 CA-7. The offboarded contractor’s export would have tripped it in minutes.

Measure the cadence gap for each lagging control – Write down how fast the risk can change against how often it is sampled. Where attacker tempo outruns the sample rate, add upstream telemetry per NIST SP 800-137 instead of waiting for the next assessment.

Report leading indicators to the board, not just the pass – Give risk owners exception rates, mean time to revoke, and the live third-party concentration DORA cares about. Report only a pass or fail and you hide where the risk is heading. The best programs are already moving toward proactive compliance that watches risk continuously.

Sort your compliance signals into lead and lag for one reason: a risk-driven program moves ahead of operational risk instead of just documenting it. The compliance lead who signs next quarter’s SOX attestation should already know the contractor’s credential was killed in minutes, because a leading signal fired the moment it went dormant.

Join our LinkedIn group Information Security Community!

Holger Schulze
Holger Schulze is the founder and publisher of Cybersecurity Insiders, an independent cybersecurity research and media company. He writes about how AI is reshaping cybersecurity, where attackers are moving faster than defenses, and what security leaders can do about it. His work draws on original research and real-world incidents, translating both into practical guidance for security teams. Holger moderates the Information Security Community on LinkedIn, one of the largest professional networks in cybersecurity. Connect at linkedin.com/in/holger-schulze

No posts to display