More than one-third of organisations (34.2%) hope to achieve their KPIs for compliance benchmarks by incentivizing success or by penalizing failure, or by implementing both incentives and penalties.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceKPIsIncentivesPenalties
69.7% of CISOs said cost is most important when selecting tools/vendors to provide governance and continuous controls monitoring.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceResourcesPersonnelSkill
Over a billion credentials were stolen in malware attacks within a 12-month period.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
Of the 1.8 million breached administrator credentials, 40,000 admin portal accounts had the password ‘admin’.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceAuditReadinessRegulatory Requirements
53.2% of CISOs take note of their organisation's regulatory requirements.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceDuplicationProcessEfficiency
Roughly 50% of CISOs expect automation to optimize compliance through a single pane of glass.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceAutomationGovernanceTechnology
50% of CISOs said that, on an annual basis, they spend more than $200,000 worth of capital and dedicated staff resources to achieve and maintain compliance across their organisation.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceCostBudgetResources
46.2% of organisations said they don’t have a sufficient budget to invest in GRC tools.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceGRC ToolsBudgetResources
Roughly two-fifths of CISOs are challenged by evidence gathering (41.5%) as a challenge in satisfying regulatory requirements.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
Almost one-third (31.1% of CISOs) believe that their company’s resistance to change is primarily driven by financial matters.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceCI/CDIntegrationAutomation
26.1% of CISOs cited the rate of regulatory change as a challenge in implementing new or updated compliance frameworks.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceRegulatoryCompliance frameworks
43.6% of CISOs cited control mapping as a challenge in implementing new or updated compliance frameworks.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceControl MappingCompliance frameworks
38.5% of CISOs said GRC tools are too expensive.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceGRC ToolsCostResources
17.6% of CISOs believe that manual processes are easier than using Compliance as Code.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceProcessEfficiencyImprovement
Just over 13% of CISOs are looking to technology to help solve their problems and have started to adopt or have plans to adopt Compliance as Code (OSCAL or OCSF).
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceCompliance as CodeTechnologyAdoption
35% of CISOs said that, on a scale of 1 to 5, they would rate their compliance program a 3 (“Defined: early-enterprise, standardized and structured”).
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceCompliance program
53.7% of CISOs stated that compliance is not embedded into their CI/CD pipeline.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceCI/CD
20% of CISOs spend between $100,000 and $200,000 annually on compliance.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceCostBudgetResources
Just over a quarter (26.4%) of CISOs said that compliance has been embedded into 26-50 percent of their pipeline, while 27.4% have embedded compliance in as much as 75 percent of their pipeline.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceCI/CD
Less than one-sixth (14.2%) of CISOs have embedded compliance into the majority (76-100 percent) of their pipeline.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceCI/CD
Less than half of the respondents (44.1% of CISOs) described the relationship between compliance and security as completely synchronized.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceSecurity
One-third (33% of CISOs) see an opportunity to supercharge staff through automation.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceAutomationROITools
Almost one in ten (9.6% of CISOs) said their relationship between compliance and security is in a period of complex negotiations while 8.5% said their relationship is out of sync.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceSecurity
Roughly one-sixth (15.8% of CISOs) endure quite a bit of duplication and 37.4% have some duplication in their compliance efforts.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceCompliance efforts
Only a fifth (20.5% of CISOs) said they have very little duplication in their compliance efforts.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceCompliance efforts
Roughly half of CISOs (47.9%) cited evidence gathering as one of their greatest challenges in implementing new or updated compliance frameworks.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
Roughly 22.6% of CISOs rate their compliance program a 4 (“Adherence: measured with metrics to support audit and risk mitigation”), but only 5.3% believe their program is a 5 (“Optimized: continuous improvement and efficiency”).
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceCompliance program
More than one-third (37.2% of CISOs) said that no platform has demonstrated its reliability for Compliance as Code.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceMetricsAuditRisk management
Just 17.9% of CISOs are using GenAI tools within their compliance program.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceGenAIToolsTechnology
41% of CISOs said that OSCAL adoption is hindered by both a lack of usage and a difficulty in understanding its importance.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceDocumentationProcessStandardization
More than four-fifths (82.1% of organisations) are not currently using GenAI tools or functions within their compliance program.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceGenAIToolsTechnology
Two-thirds (66.3% of all CISOs) surveyed said that their organisation does not measure the operational cost of managing compliance.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceSecuritySynchronizationManagement
Of the organisations that measure the operational cost of managing compliance, more than three quarters (75.4%) track all costs.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceSecurityNegotiationsManagement
Of the organisations that measure the operational cost of managing compliance, 14.5% track compliance expenses.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceSecurityNegotiationsComplexity
60% of manufacturers and 52.5% of software and IT services companies see the biggest barrier to adopting Compliance as Code is that no one is using the technology.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
33.5% of CISOs are challenged by audit readiness in satisfying regulatory requirements.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceAudit ReadinessRegulatory Requirements
75% of retail and consumer goods and 62.5% of entertainment and media corporations are coping with the lack of a centralized system, but retailers are also challenged by silos within their data (75%).
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceRegulatoryChange ManagementProcess
Almost all (94.2% of CISOs) believe that continuous controls monitoring will improve both compliance and security.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceContinuous ControlsSecurityImprovement
54.2% of respondents to the CISO Society survey feel that they have the talent to meet future regulatory requirements.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceCostBudgetResources
Research shows over 210 million compromised passwords.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceDataSystem SilosRegulatory Requirements
Only 5% of CISOs consider their organisation's compliance program to be optimised for efficiency and continuous improvement.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceCompliance progran
Nearly 22% of CISOs said they haven’t looked at GRC tools yet.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceGRC ToolsEvaluationResources
Nearly one-third (33.2% of organisations) have incorporated automation without GenAI tools.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceAutomationTechnologyProcess
Approximately four out of five (79.8% of CISOs) believe that a reduction in manual processing is the biggest opportunity to add automation to their compliance and risk management program.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceAutomationRisk ManagementProcess
Just 16.3% of CISOs said they experienced cost savings when using technology to enhance their compliance program.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceEvidenceResourcesImplementation
A staggering 80% of CISOs admit to unnecessary duplication in their compliance efforts.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceSkillStaffResources
The most commonly compromised password was "123456", being found in over 1.4 million breached credentials.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025
ComplianceRegulatoryChange ManagementManagement
42% of CISOs are challenged by data and system silos as a challenge in satisfying regulatory requirements.
RegScaleThe CISO Society 2025 State of Continuous Controls Monitoring Report·Jan 1, 2025