Skip to content
atlas

Don't confuse these

Compliance vs Cyber and information security

Why they differ

Being compliant means meeting a set of rules; being secure means actually being protected. One does not guarantee the other.

Compliance

Fundamentals

Living up to the laws, rules and standards that apply - for example NIS2, GDPR or ISO 27001.

Formal

The state of meeting the requirements set by laws, contracts, standards and the organisation's own policies, and being able to show proof that they are met.

In plain English

Like a car passing its road-worthiness check - it proves the car meets the rules, but not that it is driven safely.

In practice

Before the yearly audit, the compliance officer at a Danish pension fund gathers proof that backups have been test-restored and that every employee has completed the required security training.

Why it matters

Failing to comply can mean fines, lost customers and personal liability for managers - and requirements often force needed work that would otherwise be put off.

Cyber and information security

Fundamentals

Protecting an organisation's data, systems and ways of working against loss, misuse and interruption.

Formal

The discipline of keeping information, and the systems that handle it, confidential, correct and available - whether the information is digital or on paper. It covers technology, processes, people and physical surroundings.

In plain English

Like looking after a house - you lock the doors, check nothing has been tampered with, and make sure the family can still get in when they need to.

In practice

A small Danish accounting firm turns on encryption on its laptops, keeps offline copies of client files and teaches staff to spot fake emails that pretend to come from the tax authorities - all parts of one security effort.

Why it matters

Nearly every business now depends on its data and systems; losing them, even for a day, can halt work, break the law and cost customers' trust.

Shared connections

Atlas is in beta.