Security != Compliance...But It Should
Chris Honda (Risk, & Compliance @ Plotly | Principal Spreader of Smiles | Teriyaki Chicken Connoisseur · Manager; Security)
SAINTCON 2025 · Day 3 · Main Track 1
Overview
In his SAINTCON presentation, "Security != Compliance...But It Should," Chris Honda, a seasoned professional in risk and compliance at Plotly, tackles a pervasive and often contentious issue within modern organizations: the perceived dichotomy and frequent friction between security and compliance teams. Honda argues that while security and compliance are distinct disciplines with different immediate objectives, their ultimate goals are inextricably linked and should be collaboratively pursued. He challenges the common notion that achieving compliance automatically equates to being secure and advocates for a fundamental shift in perspective, urging both functions to recognize their shared purpose in enabling business success.

Key moments
- 0:00 Speaker introduction, unique background, and talk philosophy
- 3:15 Talk's main thesis: Security and GRC teams should collaborate
- 4:10 Empathy and understanding are crucial for team collaboration
- 5:20 Speaker's unique experience working in mixed security/GRC roles
- 6:30 Core premise: Compliance is not the same as security
Security != Compliance...But It Should
Speakers: Chris Honda, Risk, & Compliance @ Plotly | Principal Spreader of Smiles | Teriyaki Chicken Connoisseur, Manager; Security
Conference: SAINTCON
YouTube: https://www.youtube.com/watch?v=FD5Y00sttfs
Overview
In his SAINTCON presentation, "Security != Compliance...But It Should," Chris Honda, a seasoned professional in risk and compliance at Plotly, tackles a pervasive and often contentious issue within modern organizations: the perceived dichotomy and frequent friction between security and compliance teams. Honda argues that while security and compliance are distinct disciplines with different immediate objectives, their ultimate goals are inextricably linked and should be collaboratively pursued. He challenges the common notion that achieving compliance automatically equates to being secure and advocates for a fundamental shift in perspective, urging both functions to recognize their shared purpose in enabling business success.
Honda emphasizes that the core mission of any business, regardless of its industry or offerings, is to generate and retain revenue. From this foundational principle, he posits that security and compliance, rather than being isolated "cost centers," are vital enablers of this financial objective. The talk highlights the need for these teams to overcome operational silos, foster mutual understanding, and adopt a unified approach centered around risk management. By reframing their activities through a business lens, security and compliance professionals can articulate their value more effectively, secure necessary resources, and ultimately contribute more strategically to their organizations' resilience and growth.
The importance of this talk lies in its practical guidance for bridging a gap that plagues many organizations, leading to inefficiencies, misallocated resources, and a false sense of security. Honda’s insights are particularly relevant in an era of escalating cyber threats and increasingly complex regulatory landscapes. He provides a roadmap for security and compliance teams to transition from an adversarial or siloed relationship to one of synergistic partnership, driven by a shared understanding of business risk and financial impact.
Background
▶ Watch: Speaker introduction, unique background, and talk philosophy (0:00)
The historical context of information security often saw a clearer division between information security (focused on technical protections and incident response) and information assurance (concerned with governance, risk, and compliance). Over time, these functions have frequently been consolidated, or at least expected to overlap significantly, leading to the current state where "the security team deals with compliance as well" (06:00). This consolidation, however, has often masked a deeper organizational and philosophical divide, resulting in the common frustration that "being compliant in something doesn't make you secure" (06:00).
A prevalent issue Honda identifies is the misconception that achieving a compliance certification, such as SOC 2, automatically signifies an adequate level of security. While compliance frameworks provide a baseline and demonstrate adherence to certain standards, they are merely a starting point, not an endpoint. As Honda eloquently puts it, "You've hit one benchmark. There's more to do. There's always going to be more to do" (08:00). This mindset often leads to underinvestment in security post-certification, with leadership mistakenly believing the organization is "secure enough."
Another significant challenge stems from the nature of policies. While essential for documenting processes and defining desired behaviors, policies are frequently crafted in isolation by compliance teams, often becoming "really pretty, get dusted off once a year for your audit, and then it's back onto the shelf" (10:00). Such policies, despite being meticulously written, fail to prevent breaches because they lack actionability and are disconnected from the day-to-day operational realities of security teams. This creates a perception that compliance efforts are bureaucratic and ineffective, further widening the chasm between the two functions.
Furthermore, both security and GRC (Governance, Risk, and Compliance) departments are frequently categorized as cost centers (12:00). This designation implies they consume resources without directly generating revenue, making it challenging to justify budget requests or demonstrate tangible value to executive leadership. This perception often leads to understaffing, underfunding, and a reactive rather than proactive approach to security and risk management. Honda argues that this narrow view overlooks the immense value these teams provide in protecting assets, maintaining customer trust, and ultimately, safeguarding the company's ability to make and keep money. The problem, therefore, is not merely operational but deeply rooted in organizational structure, communication, and a lack of shared understanding regarding the ultimate business objectives.
Key Findings
▶ Watch: Talk's main thesis: Security and GRC teams should collaborate (3:15)
Chris Honda's central thesis is that while security and compliance are distinct, they are not adversaries and should converge on a common strategic objective: the financial success of the organization. The core findings of his talk revolve around redefining the purpose of these functions and establishing risk management as their unifying framework.
Firstly, Honda asserts that the ultimate goal of every department within a company, from marketing to finance to security, is to make and keep as much money as possible (10:00-12:00). This reorientation from technical mandates or regulatory checklists to a business-centric financial outcome is critical for bridging the divide. When security professionals articulate the value of their efforts in terms of protected revenue or avoided losses, and compliance professionals frame their work as building customer trust and mitigating financial penalties, they begin to speak a common language that resonates with executive leadership.
Secondly, the talk highlights that compliance is a starting point, not an end state, for security (08:00). Achieving a compliance certification, such as SOC 2, merely signifies meeting a baseline of requirements. It does not guarantee comprehensive security against evolving threats. Honda emphasizes that organizations must continuously strive for improvement beyond regulatory mandates, using compliance as a foundation upon which to build a more robust security posture. This perspective shifts the focus from merely "checking boxes" to fostering continuous improvement and proactive defense.
Thirdly, Honda underscores that risk management is the overarching discipline that effectively integrates security and compliance (18:00-20:00). Both functions are fundamentally concerned with identifying, assessing, and mitigating risks to the organization. Security identifies technical vulnerabilities and threats, while compliance identifies regulatory, contractual, and reputational risks. When these are viewed through the lens of organizational risk, particularly quantified in financial terms, collaboration becomes natural and necessary. The concept of being "de-risked" is dismissed as a fallacy; every organization must accept some level of risk, and the goal is to manage and control what is not acceptable (20:00).
Finally, a crucial finding is that ownership of risk often resides outside the security or GRC team (21:00-22:00). While security professionals are experts in identifying vulnerabilities (e.g., unpatched systems), the ultimate responsibility for remediation often lies with product teams, engineering departments, or other asset owners. The role of security and GRC, in this context, is to surface these risks, ensure they are understood, and facilitate their resolution by the appropriate responsible parties. This finding challenges the common internal burden security teams often feel, redirecting efforts towards enablement and communication rather than sole responsibility for every fix.
Technical Deep Dive
▶ Watch: Empathy and understanding are crucial for team collaboration (4:10)
While Chris Honda's talk does not delve into specific code examples, protocols, or architectural diagrams in the traditional sense of a technical deep dive, it offers a profound "deep dive" into the strategic and operational frameworks that underpin effective security and compliance in a business context. The technical content here refers to the systematic approaches and conceptual tools discussed for integrating these functions.
A cornerstone of this integration is the emphasis on risk quantification and business acumen for security professionals (18:00-20:00, 24:00). Honda challenges security engineers to move beyond purely technical explanations (e.g., "we need to add MFA because of technical reasons") and instead articulate security needs in the language of the C-suite, particularly the CFO. This involves translating technical risks into potential financial losses, reputational damage, or competitive disadvantages. For instance, instead of merely stating a vulnerability exists, a security professional should be able to explain, "If this vulnerability were exploited, it could lead to a data breach costing X dollars in fines, Y dollars in customer churn, and Z dollars in incident response, impacting our quarterly revenue by P percent." This approach moves security from a technical "fix-it" function to a strategic business partner.
The discussion around policies (08:00-10:00) also contains a crucial technical-operational insight. Honda argues that policies should not just be "pretty" documents for audits but must be actionable, readable, and accurate. This means they need to be designed with implementation in mind, guiding operational security practices rather than merely stating aspirations. For example, an incident response policy is only valuable if it clearly outlines roles, procedures, communication channels, and technical steps to be taken during a breach. If it's not documented and actionable, the organization cannot react quickly or effectively. This calls for security and compliance teams to collaborate on policy creation, ensuring technical feasibility and operational relevance.
Honda also touches upon vulnerability management (21:00-22:00) from an organizational perspective. He clarifies that while security teams identify vulnerabilities, the responsibility for patching or remediating them often lies with the teams owning the affected product or system. This implies a need for robust vulnerability tracking systems and clear lines of responsibility within an organization. Security's role transforms from being the sole "fixer" to being an enabler, providing the necessary information, context, and prioritization guidance to asset owners. This aligns security efforts with broader code quality and product quality initiatives, integrating security as a fundamental aspect of engineering excellence rather than an external imposition.
Finally, the talk implicitly advocates for the adoption of more dynamic and integrated GRC platforms over traditional spreadsheet-based approaches (22:00-24:00). While not naming specific tools, the desire to move "out of spreadsheets" suggests leveraging technologies that can automate compliance tracking, integrate with security tooling, and provide real-time visibility into risk posture. Tools that can manage risk registers as living documents, facilitating collaboration and tracking remediation efforts, are essential. This technical shift supports the goal of making GRC more effective and impactful, allowing compliance teams to better understand technical realities and security teams to contribute to compliance efforts more efficiently. The "technical deep dive" here is less about specific exploit techniques and more about the architectural design of an effective, integrated security and compliance program within a business.
Demo / Proof of Concept
▶ Watch: Speaker's unique experience working in mixed security/GRC roles (5:20)
Chris Honda's presentation "Security != Compliance...But It Should" is primarily a strategic and philosophical discussion aimed at redefining the relationship between security and compliance functions within an organization. As such, the talk does not include a live demonstration or a technical proof of concept. The content focuses on conceptual frameworks, communication strategies, and organizational shifts rather than hands-on technical execution.
Defensive Implications
▶ Watch: Core premise: Compliance is not the same as security (6:30)
The insights shared by Chris Honda have significant implications for how organizations approach their defensive strategies, particularly by fostering a more integrated and business-aligned security posture. The core defensive implication is the necessity for security and compliance teams to operate as a unified front, driven by a shared understanding of organizational risk and financial impact.
For security professionals, the primary defensive implication is the imperative to develop strong business acumen and communication skills (18:00, 24:00). Defenders must learn to translate technical vulnerabilities and threats into quantifiable business risks, speaking the language of the CFO and other C-suite executives. This means moving beyond technical jargon and articulating the potential financial losses, reputational damage, or operational disruptions that security incidents can cause. By framing security investments as risk mitigation strategies that protect revenue and ensure business continuity, security teams can secure better funding and executive buy-in for their initiatives, ultimately strengthening the organization's defensive capabilities.
Furthermore, security teams should actively engage with compliance professionals to understand customer and regulatory demands (16:00-18:00). Compliance often serves as the direct interface with customers regarding security assurances. By understanding what customers "care about" and what compliance frameworks (e.g., FedRAMP, SOC 2) require, security teams can better prioritize their defensive efforts. This collaboration ensures that security controls are not only technically sound but also meet market expectations and regulatory obligations, thereby building customer trust and reducing the likelihood of compliance-related penalties.
For compliance professionals, the defensive implication is a call to transition from "checkbox compliance" to actionable, impactful governance (22:00-24:00). This involves working closely with security teams to ensure that policies are not merely documents for audits but are practical, enforceable, and aligned with operational realities. Compliance teams should strive to understand the technical feasibility and impact of their requirements, leveraging security expertise to craft policies that genuinely enhance the organization's defensive posture. Moreover, compliance's role in identifying and tracking risks, particularly through tools like risk registers, becomes a critical defensive mechanism. These registers must be living documents, actively managed to surface risks to the correct owners and track their remediation, preventing critical issues from being overlooked (20:00-21:00).
A key defensive shift for both teams is to clarify and distribute risk ownership (21:00-22:00). Security teams are responsible for identifying vulnerabilities, but the ultimate responsibility for fixing them often rests with the product or engineering teams who own the underlying assets. This distributed ownership model enhances defense by embedding security considerations directly into product development and operations, making security an inherent part of code quality and product quality. Security and compliance teams become facilitators, ensuring that asset owners are aware of their risks and empowered to address them, rather than shouldering the entire burden themselves.
In essence, the defensive implications revolve around fostering empathy, understanding, and robust communication across organizational silos (04:00, 25:00). When security and compliance teams collaboratively assess risk, prioritize initiatives, and communicate effectively, the entire organization benefits from a more coherent, resilient, and strategically aligned defensive strategy that directly supports its primary business objectives.
Key Takeaways
- Shared Business Objective: Both security and compliance functions ultimately serve the same overarching business goal: to help the company make and keep money, protecting assets and ensuring continuity.
- Risk Management as Unifier: Risk management provides the essential framework for integrating security and compliance efforts, allowing both teams to identify, assess, and mitigate threats and vulnerabilities through a unified, business-centric lens.
- Compliance as a Starting Point: Achieving compliance (e.g., SOC 2) is a necessary benchmark and a demonstration of foundational practices, but it should be viewed as a minimum baseline rather than the ultimate measure of an organization's security posture.
- Actionable Policies and Risk Registers: Policies must be practical, readable, and actionable, serving as operational guides rather than static audit artifacts. Similarly, risk registers should be dynamic tools for surfacing and tracking important risks, facilitating remediation by designated owners.
- Speak the Language of Business: Security and compliance professionals must cultivate business acumen and learn to quantify risks and benefits in financial and strategic terms, enabling effective communication and resource allocation with C-suite executives.
- Distributed Risk Ownership: The responsibility for remediating identified risks (e.g., vulnerabilities) often lies with the asset or product owners, not solely the security or GRC teams. Security's role is to surface these risks and enable their resolution.
About the Speaker(s)
Chris Honda is a professional specializing in Risk & Compliance at Plotly, where he manages and scales security and compliance programs. Known for his title as "Principal Spreader of Smiles" and "Teriyaki Chicken Connoisseur," Chris brings a unique perspective to the security field. His academic background is notably non-traditional for the tech industry, having studied Korean at BYU for his undergraduate degree before pursuing further schooling in security.
Throughout his career, Chris has gained diverse experience, including teaching, sales, programming, and finance, admitting to being "bad at a lot of different things" before finding his calling in security and compliance. He previously contributed to building and scaling security and compliance programs at Wistik. This is Chris Honda's third or fourth year presenting at SAINTCON, reflecting his dedication to sharing insights and fostering community within the security space. He is also open to sharing his teriyaki chicken recipe.