From Annual Audit to Continuous Assurance: Professor Kai London on the Future of Operational Resilience
By the Swiss Times Business Desk Professor Kai London — board advisor & interim CISO/CIO/CTO. Credit: professorkailondon.com For decades, financial institutions measured their security posture the way they measured their finances: once a year, in a formal audit that produced a snapshot and a certificate. That model, argues Professor Kai London , a senior CISO and board advisor, is quietly becoming obsolete. “An annual audit tells you whether you were secure on one day, months ago,” he says. “Attackers do not operate on your audit calendar. Resilience has to be continuous, or it is theatre.” “The shift under way is from point-in-time compliance to continuous assurance — from proving you were resilient last spring to proving you are resilient right now.” Why the snapshot fails London's critique is straightforward. Environments change daily — new systems, new suppliers, new access, new vulnerabilities. A control that passed an audit in January may have quietly drifted out of eff...