← Blog
5 min readOlesia Shelestova

The Evidence Was Already There

A vendor's login without network segmentation. A patch that sat unapplied for four months. Two of the most expensive breaches in recent history trace back to a single unanswered compliance question. A look at why audit prep is exhausting, what it's actually protecting against, and why the proof usually already exists before anyone goes looking for it.

complianceauditevidenceiso 27001gdprnis2

On November 15, 2013, someone logged into Target's network using credentials that belonged to Fazio Mechanical Services, a small Pennsylvania refrigeration and HVAC contractor. Fazio's access existed for billing and project management. Nobody had segmented it away from the systems that talked to payment terminals. Three weeks later, malware was sitting on point-of-sale registers in Target stores across the country. By the time it was over, the breach touched about 40 million card accounts and personal data on as many as 70 million people.

There's a line item for exactly this, in almost every compliance framework written since. Something like: review and restrict third-party access to the minimum necessary, and keep it segmented from sensitive systems. On a questionnaire it reads as one bored little checkbox. In 2013 it was the whole story.

A patch that waited four months

Here's the other one. On March 7, 2017, the Apache Software Foundation published a fix for a flaw in Struts, a framework used to build web applications. A day later, the U.S. government was already notifying large credit bureaus, Equifax among them, that the flaw needed attention. Equifax's own security team sent an internal email telling administrators to patch it.

The patch sat unapplied until July 29, 2017, when someone finally noticed strange traffic on a dispute portal and went looking. By then, the data of 143 million people was gone.

Ask what standard covers this and the honest answer is: several, worded differently, meaning the same thing. Vulnerability and patch management. Another bored checkbox. Four months is the gap between a checkbox and a 144-million-person disclosure.

What the checklist is actually for

It's tempting to read compliance frameworks as bureaucratic noise, and plenty of it is. But strip the acronyms away and most individual clauses turn out to be scar tissue. Somebody's incident, generalized into a sentence, so the next company doesn't have to learn it the same way. Access review exists because someone's login outlived their employment. Vendor segmentation exists because Target's HVAC contractor could reach further than a thermostat. Patch management exists because Equifax had a fix sitting in an email for four months.

Security researcher Sarah Clarke put the honest version of this well: "compliance is transient comfort" while real risk management is "persistent, but better informed, discomfort." A checklist tells you what you promised on the day you signed it. It doesn't run continuously, and it doesn't know what changed at 2 a.m. last Tuesday. That gap, between what was promised and what's actually true right now, is where both of the breaches above happened.

Which is also, not incidentally, why the fines have gotten large enough to notice. UK regulators initially proposed fining British Airways £183.39 million over its 2018 breach, before mitigating factors and remediation evidence brought the final number down to £20 million. Whatever else that case says, it says the difference between those two numbers was, in real money, what BA could show it had already fixed.

Why gathering the proof is worse than having it

None of this means companies are lying when they fill out a questionnaire. Most of the time the control genuinely exists. Access probably is reviewed. Patches probably do get applied eventually. What's missing isn't the security work, it's a paper trail connecting that work to the specific sentence an auditor is reading.

So someone becomes a translator for three weeks. They ask infrastructure for a screenshot of the patch dashboard. They ask legal for a supplier contract. They dig through an eight-month-old pentest PDF hoping a paragraph answers row forty-two. Industry estimates put manual SOC 2 evidence collection alone at somewhere between 300 and 600 staff hours per audit cycle, most of it spent re-pulling data that didn't quite satisfy the sampling the first time. None of those hours make anything more secure. They just make security legible to a stranger on a deadline.

Attaching the proof at the moment it's produced

The more interesting question isn't how to survive the next audit faster. It's why the proof has to be assembled after the fact at all. A vulnerability scan already knows, the moment it runs, whether a port is exposed. A verified pentest finding already knows which control it speaks to. There's no reason that evidence has to wait for someone to go looking for it in March, already four months stale by definition.

That's the gap our compliance module is built to close. Point it at a company's domains and infrastructure, and every technical control that can be answered from vulnerability scanning, pentest results, OSINT, External Exposure monitoring, or DevGuard's code and pipeline findings fills itself in automatically, evidence attached, across thirteen frameworks (NIS2, GDPR, ISO 27001, ISO 27701, DORA, SOC 2, NIST CSF, PCI DSS, CMMC, TISAX, the EU Cyber Resilience Act, HIPAA, NYDFS 500) at once instead of one spreadsheet per standard. When two modules disagree, say a pentest finds a gap while a passive scan for the same control looks clean, both stay visible instead of quietly averaging toward "met," because that's exactly the kind of gap an auditor finds anyway, just later and more expensively. Controls an assessor tends to scrutinize hardest get flagged up front, with MITRE ATT&CK technique IDs attached where there's real technical evidence behind them, so preparation time goes to what actually gets asked about, not spread evenly across two hundred rows. The organizational questions, the ones only a person can answer, get a fast in-app Yes / Partly / No / N/A, or export to a spreadsheet, hand it to whoever holds the answer, import it back. And because the evidence is live, not archived, network segmentation doesn't quietly go stale the way Fazio Mechanical's access did, and a missing patch doesn't get four months to sit unnoticed the way Struts did. When an auditor finally does ask, the answer is a one-click bundle instead of an archaeology dig.

The point of the exercise

An audit is a photograph. Security is what's happening between photographs, every day, whether or not anyone's scheduled to check. The honest goal was never to pass the audit. It was to be able to answer the question at any moment, not just the one week a year someone asks it out loud, because the two breaches above didn't wait for an audit either. They happened on a random Tuesday, in the gap nobody was looking at.


Sources: Krebs on Security - Target Hackers Broke in Via HVAC Company · The Apache Software Foundation - Statement on the Equifax Security Breach · The Hacker News - Equifax Suffered Data Breach After It Failed to Patch Old Apache Struts Flaw · TechCrunch - UK's ICO Fines British Airways a Record £183M · HSF Kramer - ICO Fines British Airways £20 Million · Tripwire - Compliance Does Not Equal Security: 7 Cybersecurity Experts Share Their Insights · Secure.com - How to Pass SOC 2 Without Weeks of Manual Evidence Collection

Share on LinkedInhttps://pentesterra.com/blog/the-evidence-was-already-there

Take Control of Your Attack Surface.

Start with the free tier or talk to us about your environment - network, web, cloud, or on-prem.