From Annual Audit to Continuous Assurance: Professor Kai London on the Future of Operational Resilience

 By the Swiss Times Business Desk

Professor Kai London, board advisor and interim/fractional CISO, CIO and CTO
Professor Kai London — board advisor & interim CISO/CIO/CTO. Credit: professorkailondon.com

For decades, financial institutions measured their security posture the way they measured their finances: once a year, in a formal audit that produced a snapshot and a certificate. That model, argues Professor Kai London, a senior CISO and board advisor, is quietly becoming obsolete. “An annual audit tells you whether you were secure on one day, months ago,” he says. “Attackers do not operate on your audit calendar. Resilience has to be continuous, or it is theatre.”

“The shift under way is from point-in-time compliance to continuous assurance — from proving you were resilient last spring to proving you are resilient right now.”

Why the snapshot fails

London's critique is straightforward. Environments change daily — new systems, new suppliers, new access, new vulnerabilities. A control that passed an audit in January may have quietly drifted out of effectiveness by March. “The gap between audits is where risk accumulates,” he says. “And it is precisely the period nobody is measuring.” For a sector where a single lapse can move markets, that blind spot is untenable.

What continuous assurance looks like

Continuous assurance, London explains, means instrumenting controls so that their effectiveness is monitored constantly rather than confirmed occasionally. Is multi-factor authentication actually enforced everywhere it should be, today? Are privileged accounts still limited? Have critical systems drifted out of their secure configuration? “The technology now exists to answer those questions continuously,” he says. “The change required is one of mindset — treating assurance as a live signal, not an annual event.”

The regulator is moving the same way

This shift is not merely good practice; it is where regulation is heading. Modern operational-resilience regimes expect institutions to test continuously, including through threat-led exercises, and to demonstrate resilience as an ongoing state. “Regulators increasingly ask for evidence that spans time, not a single certificate,” London notes. “They want to see that you monitor, detect and correct on a rolling basis — that resilience is something you do, not something you passed.”

Testing that reflects reality

London places particular weight on realistic, threat-led testing — exercising the organisation against the tactics real adversaries use, rather than checking boxes. “A test that assumes the attacker plays fair is not a test,” he says. He advocates regular tabletop exercises for the board and executive team as well, so that decision-makers rehearse the hard choices — containment, disclosure, communication — before a crisis forces them. “You want the first time your board makes a breach decision to be in a rehearsal, not at three in the morning.”

From burden to intelligence

Handled well, London argues, continuous assurance turns compliance from a periodic burden into a source of live management intelligence. Leaders gain an always-current picture of their resilience, can spot drift before it becomes exposure, and can answer a regulator or a client instantly rather than scrambling. “The institutions that instrument their controls do not fear the examination,” he says. “They can produce the evidence on demand, because they were watching all along.”

How to begin the transition

London counsels starting where the risk is greatest. Identify the handful of controls whose failure would be catastrophic — access to core systems, protection of critical data, the integrity of payment processes — and instrument those for continuous monitoring first. Build the rolling testing and reporting rhythm around them, then extend outward. “You do not have to instrument everything at once,” he says. “You have to stop flying blind on the controls that matter most.”

For a financial community whose credibility rests on prudence, London's message is a modernising one: the annual audit had its era, but the threats no longer wait for it. The institutions that move to continuous assurance will not only satisfy tomorrow's regulators — they will simply know, at any moment, whether they are as resilient as they claim.


About Professor Kai London. Professor Kai London is a senior technology, security and transformation executive with more than 25 years of board- and C-suite leadership across banking, aviation, defence, government and critical national infrastructure. He is Founder & CEO of Quantum AI Systems Security, an Honorary Professor in Cybersecurity, AI & Quantum Computing, and a UCL researcher, holding CISSP, CISM, CCISO, ISO 27001 Lead Auditor, ISO 42001, DORA and NIS2 credentials. He is available for board advisory, NED and interim or fractional CISO/CIO/CTO mandates across the UK and internationally. Learn more at professorkailondon.com.

Popular posts from this blog

Combating the CISO Exodus: New ‘90-Day Command Framework’ Stabilizes Cyber Risk During Executive Transitions

Why Governance Wins Deals: Professor Kai London on Turning Cyber Evidence Into Revenue