* [![perspectives](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2025/02/prespective-icon.png)](https://www.paloaltonetworks.com/perspectives)
* How to Build Compliance into Cybersecurity

# How to Build Compliance into Cybersecurity

![How to Build Compliance into Cybersecurity ](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2020/01/how-to-build-compliance-into-cybersecurity.png)  
**By [Sam Greengard](https://www.paloaltonetworks.com/perspectives/author/sam-greengard/ "Posts by Sam Greengard")** | **6 min read** |  
![share icon](https://paloaltonetworks.com/content/dam/pan/en_US/cxo-perspectives/images/cxo-share.svg)

* LinkedIn button ![linkedin-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-linkedin.svg)
* Twitter share button ![twitter-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-twitter-x-black.svg)
* \[Email share button ![email-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-email.svg)\](mailto:?subject=How to Build Compliance into Cybersecurity \&body=Check out this article https%3A%2F%2Fwww.paloaltonetworks.com%2Fperspectives%2Fhow-to-build-compliance-into-cybersecurity%2F "Share in Email")
* ![copy-icon](https://www.paloaltonetworks.com/perspectives/wp-content/themes/csp2025/dist/images/icons/icon-share.svg)
  [](https://www.paloaltonetworks.com/perspectives/how-to-build-compliance-into-cybersecurity/?pdf=download&lg=en&_wpnonce=604c182041 "Click here to download") MEET THE AUTHOR  
  ![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2025/02/panw_master-twitter-profile-pic-400x400-1.png)  
  Independent Writer...

[Learn more](https://www.paloaltonetworks.com/perspectives/author/sam-greengard/)

## IN THIS ARTICLE

It's easy to overlook a basic fact about business in the digital age. Thieves, crooks and hackers aren't as interested in devices and systems as the data that resides within them. Whether they're looking to breach a database or pull off a ransomware scheme, data is what's typically in their crosshairs.

"All paths lead to protecting data and embracing effective risk management. The focus must move beyond technology and tools, which simply enable a task. The objective is to build a strategic framework that maximizes protection," says Todd Bialick, a partner at consulting firm PricewaterhouseCoopers.

Adding to the complexity is the California Consumer Privacy Act (CCPA), which, beginning January 1, 2020, sets far more stringent standards for companies doing business in California. "It has introduced a broad array of new requirements and penalties for violations and data breaches," says Paola Zeni, senior director of global privacy at Palo Alto Networks.

How can an organization juggle regulatory compliance and internal requirements for managing data? How can it approach data classification and protection in a cost-effective way? While there are no easy answers---and every organization is certainly different---it's possible to build a better cybersecurity framework by approaching the task with five steps in mind.

## Step 1. Figure out collaboration

A major challenge for organizations is building effective security across internal teams and groups---and ensuring that the [IT systems in place align with cybersecurity efforts](https://www.paloaltonetworks.com/cybersecurity-perspectives/aligning-the-priorities-of-it-and-cybersecurity-teams/?ts=markdown). Too often, departments duplicate efforts or address security in conflicting ways.

Businesses in highly regulated industries are particularly vulnerable. "It's critical for the security department, legal department and compliance group to be totally synced and operating as a single group," says Adam Shnider, executive vice president of Cyber Assurance Services at advisory firm Coalfire.

In his view, there are two primary ways to approach the challenge. One is to establish a group focused on security compliance and privacy and consolidate those assigned to different tasks within a single task force or group. This helps identify overlaps and gaps. A second approach is to establish virtual panes, sometimes referred to as Tiger Teams, that manage tasks and drive a security framework and performance systems deep into the organization. Oftentimes, it's wise to start with a centralized approach and, as the program matures, seed tasks deeper through collaboration.

## Step 2: Identify your critical data

All data is not created equal. Treating it the same and taking a blunt force approach to cybersecurity guarantees that you won't match resources with risks---and you will probably wind up overspending on regulatory compliance and security protections.

This unbalanced approach isn't just inefficient, it opens the door to problems. "You have to tie the risk back to the business," Shnider explains. "It's all about understanding outcomes and what the impact of lost, stolen, compromised, and deleted data is---and how it impacts the organization."

This means understanding regulatory issues and potential penalties for standards such as GDPR, CCPA, HIPPA, and others. It means understanding the risk of lost or stolen data and its value in the hands of hackers and attackers. "Data classification is at the heart of cybersecurity. You can't design and implement effective protections if you're guessing at how to best protect assets," says Bialick.

## Step 3: Know your real risks

If you're a retailer your cyber-risk profile is very different than if you're a health care organization or an aerospace manufacturer. But there is a common theme: Identifying the business fallout from a potential breach.

Three things serve as the foundation for strong compliance and data oversight: identifying the value of different data to the business; understanding risks related to where data is stored and how it is transported; and knowing how it is used within an ecosystem.

Throughout the risk evaluation process, the focus must involve internal, external and regulatory and compliance risks. It's not just about your own systems, it's also about understanding how data is used by third-party vendors and others. For example, a vendor may subcontract with another vendor but lack essential compliance standards and security protections. This may require audit controls and specific monitoring and having validation requirements set up.

In the case of CCPA, the penalties for non-compliance can be significant, Zeni notes. A major violation could result in fines of $2,500 to $7,500 per each violation as well as action from the California attorney general's office. Class action lawsuits and bad press could also result. "It's an issue you don't want to ignore."

## Step 4: Formulate a plan

Don't get caught up in hype and headlines, says Bialick. "Companies must develop processes for handling the end-to-end use of data across a lifecycle."

The goal isn't to react to the endless litany of threats and risks but to build a more holistic cybersecurity model that's deeply linked to compliance and controls. Moreover, the framework must include the flexibility to address changes in external regulations as well as industry requirements and internal requirements.

This may involve completely rethinking and rewiring security controls, including moving away from a reactive point solution model and toward a more sophisticated zero trust model that takes a datacentric view. It may also require adding staff that an organization doesn't currently have.

"The focus must be on streamlining, simplifying and automating processes within a central dashboard," according to Shnider. Revisiting the topic regularly is important. "You have to continually ask whether you are devoting adequate resources and budget to the task and whether you are abdicating any part of your control framework," Zeni adds.

## Step 5: Establish robust controls

Spreadsheets and manual processes and balances leave plenty of room for failure. "It's essential to have a single source of truth," Shnider points out. Automation is critical. "There is no way to inspect everything manually, scale resources up and down, and ensure that you're meeting compliance requirements."

Once you know exactly where and when data is at risk---what Shnider refers to as "the business problem to understand"---it's possible to deploy the right technologies in the right places. Tech solutions may include encryption, endpoint monitoring, data loss prevention and more. It may require different authentication methods along with AI tools that can spot anomalies and pinpoint events that fall outside authorized parameters.

At the end of the day, Shnider says there are three key areas to focus on when designing a security framework around regulation and compliance. First, it's critical to build a collaborative enterprise-wide program rather than focus on one-off tools and technologies. Second, regulations exist to promote assurance in the market and the use of an effective framework can build greater trust among customers and across an ecosystem. Finally, "Even after you build a program you have to continually review processes and technologies in order to have maximum visibility into your risks."

To be sure, well-thought-out compliance isn't easy, but it is necessary. As Bialick notes, "Every organization must frame risk in terms of what is important and how it can impact the business. When organizations succeed, they're in a position to focus on the things that really matter."

* [Addressing Regulatory Issues](https://www.paloaltonetworks.com/perspectives/all-articles/?cat=addressing-regulatory-issues)
* [Third Party Risk Assessment](https://www.paloaltonetworks.com/perspectives/all-articles/?cat=third-party-risk-assessment)

## Related Content

![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2025/08/CtrlAltDelusion-Header-WarGames2.png) BLOG

### Addressing Regulatory Issues

**Ctrl + Alt + Delusion: Revisiting "WarGames" 42 Years Later**

Shall we play a game? Auditing the classic cyber-thriller "WarGames."...

[Ben Hasskamp](https://www.paloaltonetworks.com/perspectives/author/ben-hasskamp/ "Posts by Ben Hasskamp")
[](https://www.paloaltonetworks.com/perspectives/ctrl-alt-delusion-revisiting-wargames-42-years-later/)  
![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2025/06/third-party-risks-are-rising-featured.jpg) BLOG

### Staying Ahead of Evolving Threats

**The Weakest Link in Your Cybersecurity Isn't What You Think**

Third-party risks are rising --- is your supply chain prepared?...

[Michael Sikorski](https://www.paloaltonetworks.com/perspectives/author/michael-sikorski/ "Posts by Michael Sikorski")
[](https://www.paloaltonetworks.com/perspectives/the-weakest-link-in-your-cybersecurity-isnt-what-you-think/)  
![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2025/05/nation-states-are-reshaping-threat-landscape.jpg) BLOG

### Addressing Regulatory Issues

**Is There a Cyber Cold War? How Nation-States Are Reshaping the Threat Landscape**

Why today's geopolitical risks are every CIO's security problem....

[Wendi Whitmore](https://www.paloaltonetworks.com/perspectives/author/wendi-whitmore/ "Posts by Wendi Whitmore")
[](https://www.paloaltonetworks.com/perspectives/is-there-a-cyber-cold-war-how-nation-states-are-reshaping-the-threat-landscape/)  
STAY CONNECTED

## Connect with our team today

Job Level  
Sign me up to receive news, product updates, sales outreach, event information and special offers about Palo Alto Networks and its partners.  
By submitting this form, I understand my personal data will be processed in accordance with Palo Alto Networks [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) and [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown).  
This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.
Reach out  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security?ts=markdown)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs?ts=markdown)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/unit42/respond/managed-detection-response?ts=markdown)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown)

* Observability

* [Cortex XCOR](https://www.paloaltonetworks.com/cortex/xcor?ts=markdown)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira?ts=markdown)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/prepare-for-emerging-risks/continuous-frontier-ai-defense?ts=markdown)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses?ts=markdown)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy?ts=markdown)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence?ts=markdown)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond?ts=markdown)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown)

* [Customers](https://www.paloaltonetworks.com/customers?ts=markdown)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown)

* [Communities](https://www.paloaltonetworks.com/communities?ts=markdown)

* [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications?ts=markdown)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown)

* [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown)

* [Documents](https://www.paloaltonetworks.com/legal?ts=markdown)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language
