
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.

Most compliance work goes into proving security, not improving it.
Summary
That isn’t because the rules are unreasonable. Regulators, customers, and cyber insurers are right to expect organizations to implement hundreds of technical and administrative controls, monitor their environments, respond to incidents, and prove that all of it works. The problem is the cost of delivering it.
The Pentagon’s own estimate puts a small contractor’s CMMC level 2 compliance at roughly $105,000 over three years.
KazaSec's take
AI-related security incidents are a genuinely new category, prompt injection, model manipulation, and data leakage through an LLM integration don't map cleanly onto traditional application security testing, and are worth assessing deliberately rather than assuming existing controls already cover them.
Coverage details
We've archived 828 other articles touching the same topic (opinion, don't miss, compliance) , see the full security news archive.
Relevant from KazaSec
More coverage on this topic
We help organizations find and fix the gaps before they make headlines.