powering productive workplaces
Front page
NewsTrust & Risk55m · 09:01 BST · 4 min read

Why AI Is Exposing the Limits of Annual Cyber Reviews

As AI accelerates both the way businesses introduce technology and the way attackers exploit weaknesses, annual compliance assessments can quickly become outdated, leaving security teams with evidence that no longer reflects the live risk organizations face

For years, compliance has given security teams a predictable rhythm: set controls, collect evidence, complete an assessment and prepare for the next review. That timetable made sense when systems changed more slowly and a periodic check could offer a reasonable picture of risk. It is becoming much less defensible in today’s cyber ecosystem.

The numbers demonstrate it. Verizon’s 2025 Data Breach Investigations Report found vulnerability exploitation accounted for 20% of breach initial access routes, up 34% year over year. For vulnerabilities in CISA’s Known Exploited Vulnerabilities catalog, the median time to mass exploitation was five days; for a sampled set of edge device flaws, it was zero days. When attacks can move at that pace, compliance programs based on periodic reviews and evidence gathered for an annual audit risk documenting controls that no longer reflect an organization’s live exposure.

Marc Rubbinaccio, Head of Cybersecurity and Compliance at Secureframe, tells UC Today that this is why annual compliance programs are increasingly at odds with the pace of change. With AI adoption accelerating that gap, companies need to act.

Why a Point-in-Time Program No Longer Fits

AI does not need to invent entirely new attack techniques to change the risk equation. The risk comes from its ability to scale reconnaissance, phishing content, coding and exploitation work that attackers already understand. Verizon reported that the share of AI-assisted malicious emails had risen over two years, while the use of synthetically generated text in malicious emails doubled.

The same speed that lets attackers scale familiar techniques also exposes the limits of compliance programs that assess those defenses only once a year. As Rubbinaccio explains,

“organizations are using compliance programs that were built five, 10 years ago.”

These programs are point-in-time annual assessments typically. An annual process can leave organizations focused on proving controls were in place for an audit rather than checking whether they remain effective against a continuously changing threat environment.

The pressure is not only external. While attackers use AI to increase the speed and scale of familiar tactics, businesses are using it to accelerate development and internal workflows. That adoption can outpace the controls intended to govern it, especially as new tools are added or updated regularly. This leaves security teams balancing the benefits of faster iteration against new exposure, with budgets and resources set for a less complex, slower reporting environment.

Annual assessments cannot give security leaders a dependable view of risk when both the threats facing the business and the technology being introduced inside it are changing continuously. Compliance becomes useful only when it helps teams test whether core controls are still working as that change happens.

Making Compliance Useful Between Audits

Rubbinaccio’s answer is not to discard established frameworks. AI-enabled attacks still depend on weaknesses that security teams have long understood: unpatched systems, poor access management, insecure configurations and users fooled into handing over credentials.

But the practical implication is that businesses need to see whether those fundamentals are working throughout the year. Rather than relying on a scheduled access review, for example, teams should be able to monitor who has access to critical systems, what permissions they hold and whether those permissions breach the organization’s own rules as they happen, rather than relying on a record of what happened. The same principle applies to cloud configurations, endpoint coverage and vulnerability management: controls should produce current evidence, not retrospective audit material.

This does not mean treating every finding with the same urgency. Risk-based remediation remains essential, but the pace of exploitation means organizations need to reassess the response windows they have inherited from older programs. Verizon found that the median time to fully remediate edge device vulnerabilities was 32 days, while the median time for vulnerabilities in CISA’s Known Exploited Vulnerabilities catalog to reach mass exploitation was five days. Where a critical, internet-facing flaw is actively exploited, a compliance-approved timetable may not be a security-appropriate one.

FedRAMP’s 20x program reflects the broader shift toward more active compliance. Its model emphasizes automated validation, continuous reporting and Key Security Indicators that provide near-real-time evidence of security posture, rather than a static assessment of policies and documentation. For commercial organizations, the value lies less in copying a government framework than in adopting its underlying discipline: identify the controls that matter most, monitor them continuously and track failures through to a risk-based resolution.

Why This Matters Going Forward

The move toward continuous compliance is not about asking every organization to replicate FedRAMP’s federal authorization model. It is about ending the assumption that an audit is the moment when security becomes visible.

Rubbinaccio expects that shift to become standard practice:

“I think continuous compliance is going to eventually become the norm.”

That will require security, compliance and the teams building or using technology to work from the same current evidence, rather than treating control testing as an annual responsibility.

Annual certification will remain commercially and regulatorily important. It cannot, though, be the primary evidence that an organization is secure. As AI compresses the time between a weakness emerging and an attacker exploiting it, the businesses best placed to respond will be those that turn compliance from a periodic proof exercise into an ongoing test of whether their most important defenses are actually working.

rate this story
helps rank stories across uc today
The discussion0 takes · attributed & checked

Does this reflect your experience?

opening the room…
Read nextordered by techtelligence · every pick explained
picked for this story

You WILL Soon Have a Security Breach, So How Do You Prepare?

24 Sept 2026
picked for this storyWhy Businesses Need to Prepare For Quantum Cryptography Now25 Aug 2026picked for this storyCyber Roundup: Cut-Price AI, Intel Gaps, Expanded Monitoring26 Sept 2026