Compliance won’t save you, but culture might

by Black Hat Middle East and Africa
on
Compliance won’t save you, but culture might

In recent years, organisations have invested heavily in meeting regulatory requirements, achieving certifications and passing audits. But now those exercises are more likely to be seen as the starting point – not the finish line.

Marcos Marrero (CISO at H.I.G. Capital) believes organisations need to move beyond treating cybersecurity as a compliance exercise – because “that does not make us secure.” 

“Risk is a moving target. Risk is ever-evolving.” 

As cyber threats become more sophisticated and technologies such as AI alter the threat landscape, static controls are becoming less effective on their own. The World Economic Forum's Global Cybersecurity Outlook 2026 found that 94% of cybersecurity leaders believe AI will be the most significant driver of cybersecurity change over the coming year, while organisations continue to balance innovation with governance and human capability.

The implication is that far from being just a checkbox exercise, cybersecurity has become an ongoing organisational capability. 

 

Why culture matters more than controls

For Marrero, building resilience begins by changing how organisations think about risk.

"When you shift over to culture, where everyone is in a risk mindset within your organisation... that's when you start moving away from compliance into a cultural risk shift."

It's a philosophy that extends well beyond the security team.

"I say that I have the largest department in the entire organisation. Every single employee works for me."

Marrero isn’t talking about reporting lines here – he’s talking about responsibility. 

"Every single employee is a human firewall for me. Every single employee is at the front lines of all of the emails that come in, all of the messages, all of the potential cyber risks that they can be dealing with."

This is true in any organisation. Because every phishing email opened, every password reused and every unexpected file downloaded represents a security decision made by an individual – not a technology.

That thinking is increasingly reflected across the industry. The World Economic Forum (WEF) argues that cybersecurity is no longer simply a technical discipline but a strategic business issue requiring leadership, governance and organisation-wide engagement. 

Technology alone isn't enough

Of course, organisations still need strong technical controls. But technology works best when people understand how to use it – and why they should care.

Margarita Rivera (Global CISO at Carnival Corporation) believes the conversation around employees often starts in the wrong place.

"Humans can be the weakest link,” she says. "Humans can be your greatest asset."

And this largely comes down to security leadership. "It really all depends on the job that we're doing with our teams to provide security awareness. Making everybody understand their responsibility. Making that culture pervasive throughout everything that we do."

These comments come at a time when many organisations are rethinking how they develop cyber capability. According to WEF, the proportion of organisations formally assessing the security of AI tools increased from 37% in 2025 to 64% in 2026, reflecting a broader shift towards stronger governance as new technologies are adopted. 

The WEF report also notes that while AI adoption is accelerating, governance frameworks and human expertise continue to struggle to keep pace – highlighting the growing importance of continuous learning and organisational awareness.

From awareness to ownership

Security awareness programmes have existed for decades – but the challenge today is turning awareness into ownership.

Rather than viewing cybersecurity as the responsibility of a specialist team, leading organisations are embedding cyber thinking into everyday decision-making; from finance and HR to operations and customer service.

The WEF describes cybersecurity as "a frontier where collaboration remains not only possible, but powerful," arguing that resilience depends on people working together across functions rather than relying solely on technology. 

That collaborative mindset is exactly what Marrero advocates.

"When you shift your culture so we're having cyber risk at the forefront, you become much stronger as an organisation."

Building a security-first culture

No organisation will ever eliminate cyber risk completely. Threats evolve too quickly, technologies change too rapidly and attackers constantly adapt their tactics.

But organisations can become more resilient.

That starts by recognising that cybersecurity isn't about passing audits or deploying the latest technology. It's about creating an environment where every employee understands that security is part of their job.

Compliance can establish a baseline – but culture is what determines how an organisation responds when something unexpected happens.

In an era shaped by increasingly complex cyber threats, that may prove to be the most valuable security control of all.

Listen to the full interview with Margarita Rivera and Marcos Marrero on The Black Hat Files.

Share on

Join newsletter

Join the newsletter to receive the latest updates in your inbox.


Follow us


Topics

Sign up for more like this.

Join the newsletter to receive the latest updates in your inbox.

Related articles