Cyber and compliance leaders are being asked to do more with less, and faster than ever. Attack surfaces are expanding as cloud, SaaS and third-party integrations multiply. Regulators are tightening expectations – DORA, NIS2, the FCA’s operational resilience rules, and an ever-growing list of frameworks all demand evidence that controls aren’t just in place, but actually working. And boards are asking sharper questions about cyber risk than they were five years ago.
The go-to response usually revolves around periodic audits, manual spreadsheets and point-in-time assessments, but now they fall short. Controls drift the moment they’re documented, environments change daily and attackers don’t schedule themselves around your audit cycle.
This is why Continuous Controls Monitoring (CCM) has moved from a “nice to have” to a foundational capability for resilient organisations. But knowing CCM is the goal is one thing; getting there is another.
If you’re new to the concept, start with our companion piece on what Continuous Controls Monitoring is and why it matters. This blog is about how organisations get there, the challenges they encounter, the maturity stages they move through and how Quod Orbis supports them at each step.
Why the move to Continuous Controls Monitoring can feel like a challenge
In our work with security, risk and compliance leaders across regulated industries, three challenges come up again and again. None of them are unsolvable. But together, they explain why so many organisations feel stuck.
1. You can’t monitor what you can’t see
The first obstacle is almost always visibility. You can’t continuously monitor controls across assets you don’t know exist – and the scale of that gap is larger than most organisations realise. Gartner’s 2024 research found that the average enterprise operates with around 40% of its infrastructure unaccounted for by IT, and that up to 30% of purchased IT assets are never entered into the system of record in the first place. A further 24% of organisations haven’t verified their asset inventory in the past five years. There is a vast unmanaged layer running alongside the sanctioned IT estate.
We know the culprits well: cloud workloads spun up by individual teams, SaaS tools procured outside of IT, inherited estate from acquisitions, shadow services running on developer accounts, and devices reconnecting to the network after months away.
IBM’s 2024 Cost of a Data Breach Report found that more than one-third of breaches involved shadow data – data stored in unmanaged sources – and that 40% of breaches involved data stored across multiple environments, making it harder to track and secure. And in our own work with enterprise clients, we routinely unearth around 1,000 assets they didn’t know they had once we connect to their environment.
“We’ve had some light bulb moments in the platform where particularly around vulnerabilities, the CCM platform has highlighted things we simply didn’t know and the trending information will start to demonstrate areas we need to keep an eye on.”
— Chris Taylor, Information Technology Manager, Martin-Baker Aircraft
This is the heart of cyber asset attack surface management (CAASM): you need a live, accurate, continuously updated picture of every asset in your environment – across cloud, on-premises, endpoints, identities and SaaS – before you can sensibly talk about controlling them. Without that foundation, every other security and compliance activity is built on guesswork.
2. Control coverage gaps hide in plain sight
Even when organisations know what they have, they often don’t know how well it’s protected. A control might exist in policy but not be enforced in production. A tool might be deployed but misconfigured. A process might work for the on-premises estate but break down in cloud environments. A control that passed audit in January might have quietly failed in March.
These gaps rarely announce themselves. They surface during incidents, during regulator visits, or during the next external assessment – by which point the cost of remediation is multiples of what it would have been to catch the gap early. Manual sampling and quarterly reviews simply can’t keep pace with the rate of change.
3. Compliance pressure is exhausting manual processes
Regulatory demands are intensifying across the board. DORA brings new operational resilience expectations for financial services. NIS2 expands scope dramatically across critical sectors. ISO 27001, SOC 2, PCI DSS and sector-specific frameworks all require continuous evidence of control effectiveness, not annual snapshots.
This is an unsustainable approach for teams still gathering that evidence through screenshots, spreadsheets and email chains. Audit preparation takes months of senior time and evidence-gathering pulls technical staff away from their day jobs. Alongside the enormous amounts of time wasted, errors still creep in, findings repeat year on year because nobody has the bandwidth to fix the root cause, and the cost of compliance keeps rising while confidence in it falls.
The stages of Continous Controls Monitoring maturity
Organisations don’t achieve mature CCM overnight. In our experience, they move through four broad stages, and recognising where you sit helps clarify what the next move should be.
Stage 1: Fragmented and reactive.
Visibility is patchy. Controls are documented but not continuously verified. Compliance is a once-a-year scramble. Risk reporting is largely qualitative. Most organisations recognise themselves somewhere here.
Stage 2: Foundational visibility.
A live, centralised asset repository exists. The organisation knows what it has. This is the gateway to everything that follows — without it, monitoring has nothing reliable to monitor.
Stage 3: Domain-led continuous monitoring.
Continuous monitoring is established in the control domain causing the most pain or carrying the most risk — most commonly vulnerability management, identity and access management, or cloud security posture. Dashboards replace spreadsheets in that area. Audit evidence is generated on demand. The platform proves its value where the business already feels the gap, and coverage expands from there.
Stage 4: Real-time CCM as a single source of truth.
Continuous monitoring spans the full control landscape. Security, compliance and risk posture are visible in real time to the people who need them — from operational teams to the board. Audits become a by-product of how the organisation already runs, not a separate exercise.
The right next step depends entirely on where you are now. An organisation at Stage 1 shouldn’t be chasing a board-level real-time dashboard before it has solved asset visibility. An organisation at Stage 3 shouldn’t be re-procuring foundational tooling – it should be expanding coverage and integrating sources.
How Quod Orbis approaches Continuous Controls Monitoring
Gartner refers to this category of technology as Continuous Compliance Automation – automated, continuous evidence of regulatory compliance. Our approach to Continuous Controls Monitoring takes that further, combining compliance with asset visibility and security posture monitoring in a single source of truth. It is built around two capabilities that map directly onto the stages above.
- A live asset repository as the foundation
We connect to any data source you already have – security tools, cloud platforms, identity providers, IT service management, CMDBs, SaaS estates – and build a single, continuously updated inventory of your assets and the data they hold. This is the prerequisite that opens the gateway to Continuous Controls Monitoring. Without it, metric reporting is unreliable and monitoring has no anchor. With it, everything that follows becomes possible. Read more about our approach to continuous asset visibility.
- Real-time monitoring of security, compliance and risk posture
Once assets are visible, we layer on automated, continuous monitoring of your controls across the frameworks and domains that matter to you. You see your posture as it actually is, not as it was at the last point-in-time assessment. Gaps surface immediately. Evidence is generated automatically. Reporting flexes from technical detail for operational teams to board-ready summaries – all drawn from the same underlying truth.
What changes when Continuous Controls Monitoring matures
The benefits of getting CCM right go well beyond compliance.
Audit cycles compress dramatically as preparation that used to take weeks of senior time runs in hours, drawn from evidence the platform has been gathering continuously. Conversations with regulators shift from defensive to confident, because you can answer questions in real time rather than promising to come back with the data.
Risk reporting also becomes credible, so boards get answers grounded in live data, not stale quarterly snapshots. CISOs are given the insights to demonstrate not just that controls exist, but that they’re working – and where the residual risk actually sits.
Operational resilience improves because gaps are caught and closed quickly, not at the next audit. Security and compliance teams stop spending their time gathering evidence and start spending it on the work that actually reduces risk. And the organisation gains something it rarely has: a single, defensible source of truth that everyone – security, risk, compliance, audit, the board – can rely on.
Value at every stage of Continuous Controls Monitoring
The most common reason organisations delay implementing CCM is the belief that they need to fix everything else first: close every gap, complete every project, mature every capability. But that’s not true. Deploying CCM starts with visibility, and every step from there compounds.
So you don’t need to be at Stage 4 to benefit from Continuous Controls Monitoring; you just need to take the next step from wherever you are. For many organisations, that means starting with the single control domain causing the most pain right now – vulnerability management, identity and access management, or cloud security posture. For others, it’s establishing the live asset repository that opens the door to everything else, or integrating CCM into board-level risk reporting. The path forward is incremental and the value compounds at every stage.
We’ve explored the belief (myth!) that organisations need to be mature before adopting CCM, as well as others in our booklet, 5 Myths About Continuous Controls Monitoring. It’s worth a read if you’d like a deeper dive into the common blockers we see, and how to move past them.
If you’d like to talk about where you are today and what your next step could look like, get in touch.





