Skip to content
Review Open access

The Compliance Gap: Why Audit-Based Cybersecurity Models Fail Critical Infrastructure and the Case for Continuous Control

Sep 2026 · Global Journal of Engineering and Technology Research · 0 citations

TL;DR

A conceptual review argues that this model is structurally incapable of guaranteeing security in modern CI environments and develops the case for a transition to continuous monitoring and continuous control and traces the intellectual and regulatory lineage of the alternative.

Abstract

Critical infrastructure (CI) sectors, including energy, water, transportation, healthcare, telecommunications, and finance, continue to anchor their cybersecurity assurance in periodic, audit-based compliance: scheduled assessments that certify, at a point in time, that mandated controls exist and are documented. This conceptual review argues that this model is structurally incapable of guaranteeing security in modern CI environments and develops the case for a transition to continuous monitoring and continuous control. Drawing on standards literature, empirical studies of operational technology (OT) security, documented attacks on industrial systems, and the continuous auditing tradition in accounting information systems, the paper synthesizes five interlocking failure modes of periodic compliance: (a) the static-snapshot problem, in which audit findings describe a past state rather than the present one; (b) the error-proneness and limited depth of manual, checklist-driven assessment; (c) configuration drift, through which compliant systems silently degrade between audits; (d) the asymmetry between adversary operational tempo and annual or multi-year audit cycles; and (e) an audit-centric organizational culture that substitutes evidence production for risk reduction. The analysis situates these failures against a threat landscape defined by IT/OT convergence, industrial Internet of Things expansion, deep infrastructure interdependencies, nation-state pre-positioning, and ransomware economics. The paper then traces the intellectual and regulatory lineage of the alternative (continuous auditing, information security continuous monitoring, continuous diagnostics and mitigation, zero trust architecture, and emerging continuous control validation) and discusses implications for regulators, operators, and researchers. The compliance gap, it concludes, is not a maturity deficit but a design flaw requiring an architectural response. As a conceptual review the paper offers an analytic framework rather than an effect estimate: it presents no new data and does not establish that continuous regimes reduce realized risk relative to periodic ones, a limitation stated in full in Section 7.

Read PDF

Similar papers

Open access Aug 2026

INTEGRATING CONTINUOUS AUDITING INTO SOC OPERATIONS: AN AUDIT-DRIVEN THREAT MONITORING FRAMEWORK

A model that integrates real-time Security Operations Center log analytics with continuous auditing processes and aims to bridge the technical gap between operational threat monitoring activities and the internal audit function indicates that log-level visibility reduces blind spots in internal audit, strengthens contr...

Kübra Aslan, Azze Özel, Onur Ceran · 0 citations
Sep 2026

Beyond the Checklist: Modernizing Cybersecurity Regulation for the U.S. Power Grid

The NERC CIP standards have been mandatory for more than fifteen years and are widely regarded as a baseline for securing the bulk power system, yet little is known about how the people who implement, audit, and write them experience the regulatory lifecycle in practice. Drawing on interviews with twenty two auditors,...

Sena Şahin, Burak Sahin, Robin Berthier et al. · 0 citations
Review Open access Aug 2026

From It Audit Findings to Cybersecurity Governance: A Risk-Based Remediation Framework for Critical Digital Infrastructure

This article proposes an eleven- stage risk-based remediation framework running from finding validation through continuous monitoring, together with eight measures spanning timeliness, ownership, verification quality, and business linkage, which is proposed rather than empirically validated.

Josephat Deogratius Katundabwile, David Mbui Kamau · 0 citations
Preprint Sep 2026

AspisAI: A Canonical, Machine-Interpretable Governance Framework for Automated Multi-Standard Compliance Monitoring

Organisations operating in regulated and critical-infrastructure sectors must satisfy multiple, heterogeneous cybersecurity and privacy instruments simultaneously, including but not limited to ISO/IEC~27001, the NIST Cybersecurity Framework~2.0, Cyber Essentials, and the GDPR. In practice, these obligations are managed...

Tsafac Nkombong Regine Cyrille, Hasan Dağ, R. Creutzburg et al. · 0 citations
Preprint Sep 2026

Continuous Assurance of Agentic Security Auditors for Software Delivery Decision Gates

Large language model (LLM)-based repository auditors are increasingly deployed as security controls within continuous integration (CI) pipelines, where their findings admit, block, or delay software changes. As Agentic Software Development Life Cycle (SDLC) Security Controls, their non-deterministic behaviour changes t...

Guy Lupo, Nguyen Hung Nguyen, V. Vo et al. · 0 citations
Review Open access Sep 2026

Cyber Resilience for Industrial Control Systems in Saudi Arabia: An Asset-Specific Framework for SCADA, PLC, DCS and HMI Protection and Trusted Recovery

Industrial Control Systems (ICS) are increasingly connected to enterprise networks, cloud platforms, remote engineering services, and industrial Internet of Things devices. Saudi Arabia is a particularly relevant setting because NCA OTCC-1:2022 establishes minimum cybersecurity requirements for relevant government orga...

Ishaq Siddiqui Mohammed · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.