Devensa Advisory
Get started

Five Security Findings That Show Up in Every Audit

The same five cybersecurity gaps show up in audit after audit. See why they keep recurring and how continuous governance closes them.

Devensa Advisory 6 min read
Shield with a check mark on a continuous timeline. Oversight without pauses.

Vulnerability exploitation overtook stolen credentials as the top way attackers get in, for the first time in the Data Breach Investigations Report's 19-year history, now involved in 31% of breaches1. Most cybersecurity programs still get reviewed on a quarterly or annual cycle, while the risk underneath them changes every week. Cybersecurity governance is the layer that keeps a program accountable between those reviews, not just during them, and it's usually the layer that's missing.

Auditors don't need much time to find that missing layer. The same five gaps turn up in company after company, regardless of size or budget, because they're gaps in accountability, not technology.

The Same Five Gaps, Every Time

Cybersecurity governance is the set of policies, ownership, and continuous oversight that decides what gets protected, who's accountable for it, and how a program proves it's actually working, not just documented as working on paper. It isn't a tool sitting next to a firewall, and it isn't a binder that comes out once a year for the auditor. It's the layer that keeps every control accountable to a person, continuously, not just during the week someone's checking.

Access That Outlives the Employee

Someone leaves the company, and their VPN access doesn't leave with them. Access reviews that run on a fixed quarterly schedule catch this eventually. A trigger tied directly to offboarding catches it immediately.

Exceptions That Never Expire

A system misses a patch deadline, someone logs a thirty-day exception, and the tracking sheet never gets revisited. Eighteen months later, the exception is still open and the vulnerability it covers has a public exploit.

The One System Nobody Wants to Touch

Most organizations have gotten reasonably good at multi-factor authentication everywhere except one legacy system nobody wants to be responsible for breaking during a migration. That one system usually carries more risk than the other fifty combined.

A Response Plan That's Never Been Tested

An incident response plan can read well and still fail completely, because it names an escalation contact who left eighteen months ago and nobody's run a tabletop exercise against it since.

Alerts Nobody Has Time to Read

Logging is on, alerts are firing by the thousands, and a small team triages the loudest ones while the rest age out unread. The tooling isn't the problem. The volume outpaced the headcount two budget cycles ago.

Why These Gaps Keep Winning

None of the five gaps above are technology failures. They're maintenance failures, and maintenance is exactly what periodic review misses.

The Cost Keeps Climbing

The global average cost of a data breach climbed 12% this year to $4.99 million2, the highest figure IBM has recorded. Breaches that take longer than 200 days to contain, and breaches at organizations without a tested response plan, consistently cost more than that average.

Boards Want Proof, Not a Briefing

96% of audit teams now have activities planned specifically to provide assurance over cybersecurity vulnerabilities in 2026.3 “We were briefed” no longer counts as evidence of oversight. Boards want documented proof that risk was tracked continuously, not summarized once.

Patching Is Losing Ground, Not Gaining It

Only 26% of critical vulnerabilities were fully remediated in 2025, down from 38% the year before, and the median time to patch stretched from 32 days to 43.1 A governance program that reviews exceptions once a quarter is reviewing them on the wrong clock.

What Continuous Governance Actually Looks Like

Most cybersecurity controls still trace back to the same three properties: confidentiality, integrity, and availability, the CIA Triad. What's changed isn't the framework. It's how often a program actually checks itself against it.

  • Confidentiality: information stays accessible only to those authorized to see it, tracked continuously against access changes, not reviewed in a batch.
  • Integrity: data stays accurate and unaltered except through an authorized process, with change logs monitored as they happen.
  • Availability: systems and data stay accessible to authorized users, with disaster recovery tested against a real restore, not just discussed in a tabletop.
31 percent. Vulnerability exploitation overtook stolen credentials as the leading breach vector for the first time in the DBIR's 19-year history, Verizon 2026.

Closing the Gaps for Good

  • Move access reviews off a calendar and onto a trigger: tie deprovisioning directly to the offboarding event, not the next scheduled review.
  • Set exceptions to expire automatically: no silent renewals, and no exception that outlives the vulnerability it was meant to cover temporarily.
  • Find the one system everyone avoids: and put a real remediation date on it, not an indefinite deferral.
  • Test the incident response plan against a real scenario: at least once a year, with current contacts, not the names that were accurate two roles ago.
  • Size alerting to the team that has to read it: a SIEM generating more noise than a team can triage is a maintenance debt, not a security control.

Frequently asked questions

What is cybersecurity governance, and how is it different from cybersecurity?

Cybersecurity is the technical controls that stop a specific attack. Cybersecurity governance is the layer above it: who decides what gets protected, who's accountable for that decision, and how the organization proves the program is actually working on an ongoing basis, not just during a scheduled review.

Why do the same audit findings keep coming back year after year?

Because most of them are maintenance failures, not technology failures. A control that looked fine at launch drifts out of alignment the moment nobody's assigned to keep checking on it between formal reviews.

How often should a cybersecurity governance program be reassessed?

At minimum annually, and immediately after any material change: a new regulatory requirement, a significant infrastructure change, or a real incident. Waiting for the calendar alone to trigger reassessment is one of the most common gaps auditors find.

How do I know if my organization has one of these five gaps right now?

Ask who is accountable, by name, for closing the last open vulnerability exception, and ask when the incident response plan was last tested against a real scenario. If either answer takes longer than it should to find, that's usually the sign. Could you answer both right now?

Where would your cybersecurity program land if it were assessed this week?

Sources

  1. Verizon, 2026 Data Breach Investigations Report. https://www.verizon.com/business/resources/reports/dbir/
  2. IBM Security, Cost of a Data Breach Report 2026. https://www.ibm.com/reports/data-breach
  3. Gartner, 2026 Audit Plan Hot Spots, cited in Ascent Business Consulting. https://www.ascentbusiness.com/blog/cyber-risk-management-in-2026-five-trends-every-board-needs-to-understand/

Originally published on the Devensa blog.

Keep reading

All insights →
Cybersecurity

Security Ownership: Why “IT Handles That” Is Usually Wrong

IT and security get treated as one job. They aren't. See where that confusion actually breaks, and what the 2026 DBIR shows about the cost of unassigned risk decisions.

AI Governance

Is Your AI Governance Tool Actually Governance?

Many AI governance tools are controls tools. Learn how governance and controls differ, why it matters, and what to ask before you buy.

Privacy

Who Owns Privacy? Why a DPO Title Doesn't Guarantee Accountability

Twenty US states now have comprehensive privacy laws in effect. See why an independent DPO still isn't the same as owning privacy operationally.

Put a name next to every gap.

A Current State Assessment scores where you are across the six domains and sequences what comes next, with owners attached.

Get started Explore Cybersecurity