Leadership Without Theatre · 6 min read

Compliance without theatre: GDPR, NIS2 and the difference between being certified and being safe

I have spent years inside information security management systems – building them, running them, getting them certified, and auditing other people's. I can say with some confidence that a certificate on the wall tells you very little about how safe an organisation is.

It tells you that, on a particular day, an auditor was shown enough evidence to be satisfied. That is not nothing. But it is not the same as the organisation actually behaving the way the documents describe.

The gap between the two is what I call compliance theatre. And with NIS2, the EU AI Act, DORA and the ever-present GDPR, the temptation to perform compliance rather than practise it has never been greater.

How theatre happens

No one sets out to build a compliance theatre. It grows from reasonable decisions.

A regulation arrives. Someone is asked to "make us compliant". They produce policies, because policies are what auditors ask for. The policies are approved by people who have not read them. Training is rolled out as an e-learning module with a quiz. The register of processing activities is filled in once and never updated. An audit is passed. Everyone relaxes.

Twelve months later a breach happens, and the incident review discovers that the policy said one thing, the system was configured to do another, and the people involved had never heard of either.

I have seen this pattern in organisations of every size. It is not a failure of intelligence or intent. It is a failure of ownership: compliance was treated as a deliverable rather than as a way of running the business.

What actual compliance looks like

The organisations that are genuinely compliant – as opposed to certifiably compliant – share some habits.

The business owns the controls. The security or privacy function defines what good looks like and checks whether it is happening. But the people who run the systems, handle the data and manage the suppliers are the ones responsible for doing it. When compliance sits entirely in a staff function, it has already failed.

Policies describe reality. A good policy is short, specific and true. If the policy says access reviews happen quarterly and they happen never, the honest move is to change the policy or change the practice. Leaving the gap is the worst of the three options, because it documents your own negligence.

Management knows what it is signing. NIS2 places explicit governance responsibilities on management bodies, including approving and overseeing cybersecurity risk-management measures. Approval should therefore be informed: management needs to understand what is being approved, what remains unresolved and where residual risk sits.

Incidents are expected, not embarrassing. Compliant organisations have practised what they will do when something goes wrong: who assesses, who determines whether notification is required, who reports within the applicable deadline, and who talks to customers. GDPR and NIS2 both impose time-sensitive notification obligations in relevant cases. Those timelines are unforgiving for organisations that are improvising.

Suppliers are part of the perimeter. Most data processing and most operational risk now sits with third parties. A data processing agreement you have never read, or a supplier security questionnaire no one has followed up, is a liability with a signature on it.

Do and don't

Do start with a plain-language map: what data you hold, what systems matter, which suppliers you depend on, and what regulations actually apply to you. Most compliance failures trace back to not knowing this.

Do assign each material obligation to a business owner – not to the compliance function – and make it part of their objectives.

Do keep policies short enough to be read and specific enough to be checked. Ten pages that people follow beat a hundred that they don't.

Do test the incident and breach-notification process with the people who would actually run it, including the executive who will sign the notification.

Do make the board's approval meaningful: a briefing on what the measures are, what they cost, what residual risk remains, and what the board is accepting.

Don't buy a compliance framework and assume you have bought compliance. Tools and templates accelerate the work. They do not do it.

Don't let audit readiness become the goal. The goal is not to pass the audit. The goal is to not need the audit to tell you where you stand.

Don't treat training as a tick-box. If the annual awareness module is the only time people hear about security, they will forget it by February.

Don't assume that being outside the direct scope of a regulation means it will never affect you. NIS2 requires in-scope organisations to address supply-chain security, so suppliers may face security requirements through customer governance, procurement and contracts.

A reminder

Regulators are not the audience for your compliance. Your customers, your employees and your own leadership are.

Build it so that it works when no one is checking. The audit will take care of itself.

---

Maj Britt Arberg is the founder of House of Moon. She is an ISO 27001 Lead Auditor and Lead Implementer, has managed national and Nordic information security management systems in Big Four advisory, and has worked with cyber and privacy programmes in organisations of every size.