Skip to content

By Colin Riddle, Chief Product Officer, Ekco Cloud & Security

Most security conversations get framed around a single question: are we secure enough. It’s a reasonable question, but it tends to obscure a more useful one: could we prove it, specifically and quickly, to whoever just asked.

The gap that’s easy to miss

There’s a distinction that gets lost in most security conversations: the gap between having reasonable controls and being able to produce specific, current, documented evidence of them. Most mid-market organisations we talk to have the former. Fewer have the latter ready to hand when it’s actually asked for.

That distinction used to matter less. A board could be reassured by a confident description, “we’ve got MFA, we review access periodically, we take this seriously” and move on.

Why this matters more than it used

That’s changing, from several directions at once.

Insurers are pricing premiums against evidence of specific controls, not general assurances. Regulators across sectors have shifted from issuing guidance to actively enforcing it.

Funders and grant-makers are asking for cyber attestations alongside financial reporting. Boards and trustees are being told, increasingly explicitly, that awareness of a risk isn’t the same as demonstrating that it’s managed.

It’s an evidence problem, not a security problem

The organisations caught out by this shift aren’t usually the ones with bad security. They’re the ones who can describe their posture accurately but can’t produce it, a documented, specific, current answer, quickly enough when someone finally asks.

That’s an evidence problem more than a security problem, and it’s a solvable one.

What closes the gap

Two things typically do it. The first is a baseline review of identity and device security against a recognised standard – where are the gaps in multi-factor authentication, conditional access, and security policy, mapped specifically rather than described generally.

The second is a compliance-side review: a clear strategy for how sensitive data is labelled, how data-loss-prevention policies are applied, and how retention schedules align with data protection obligations.

Together, these produce something a description never can: a paper trail.

Where this gets specific

There’s a version of this that’s particular to organisations under active regulatory reporting obligations.

For UK financial services firms, from March 2027 all FCA-authorised firms will need to report operational incidents through a standardised process, and that applies broadly. A further requirement, an annual register of material third-party arrangements, applies only to a defined subset of larger firms: enhanced-scope firms, insurers subject to Solvency II, banks, building societies and similar.

The evidence-building exercise described here is useful preparation either way, and it’s important to know which obligation actually applies to your firm, rather than assuming the broadest version of the rule.

The same principle holds outside financial services. UK charities reported a meaningful rate of cyber breaches in the most recent Cyber Security Breaches Survey, and the Charity Commission has been explicit that it expects trustees to demonstrate awareness and management of the risk, not simply express concern about it.

Professional services firms are seeing their own regulators move from guidance toward enforcement on the same questions, with insurers pricing premiums accordingly.

What this isn’t asking you to assume

None of this requires assuming your controls are inadequate. It requires assuming that, at some point soon, someone is going to ask you to prove them, and building the evidence before that conversation happens rather than during it. Ekco’s M365 Security Baseline Assessment and Purview Compliance Assessment are built to do exactly that, typically within a week combined.

The goal isn’t to become more secure than you already are. It’s to be able to prove, specifically and quickly, what’s already true.

Explore the full AI-Ready Suite

And why not sign up for our short webinar series on how to get AI-Ready?

Four short webinars available to watch live or on demand after each session.

Sign up here

Question?
Our specialists have the answer