Are Your Security Controls Still Effective?
Estimated reading time: 8 minutes
A security control can be working as designed and still face threats built specifically to work around it.
Good cybersecurity governance requires organisations to understand not only whether controls exist, but whether they remain effective as threats change.
On 8 September 2026, the Australian Signals Directorate's Australian Cyber Security Centre published an advisory on the growing use of crypters, developed together with the Australian Federal Police, New Zealand Police, Google and the UK National Crime Agency.
Crypters modify malware using techniques designed to make malicious files harder for security software to detect. ASD warns that malware which bypasses system defences may remain active longer and potentially contribute to unauthorised access, credential theft, financial loss, ransomware or operational disruption.
For business leaders, the lesson extends well beyond crypters themselves. The important question is how you know your security controls remain effective against the threats they are expected to manage.
Sources: Australian Signals Directorate's Australian Cyber Security Centre, Digital camouflage: crypters make malware undetectable, 8 September 2026. Full citations in the References section below.
Having a Control Is Not the Same as Knowing It Is Effective
Organisations invest in antivirus, endpoint protection, application controls, monitoring and other security measures. Being able to demonstrate that those controls are installed and operating is important. It does not necessarily answer whether they continue to manage risk effectively.
NIST defines security control effectiveness in terms of both correct implementation and how well the security plan continues to meet organisational needs and current risk tolerance. That second part is easy to overlook. A control assessed as effective on the day it was deployed can drift away from that standard as attackers adapt, without anyone deciding to let that happen.
Do we have the control?
Do we know whether it is still effective?
The governance question therefore needs to move from the first of those to the second. Most organisations can answer the first with confidence. Fewer can answer the second in the same way.
Threats Adapt to Defences
The ASD advisory provides a timely example of why this matters. As malware detection has improved, cybercriminals have developed services specifically intended to help malware avoid those detection mechanisms. Crypters can use obfuscation, anti analysis, anti detection and cryptographic techniques to change malware and make its normal detection fingerprint harder to recognise. Some malware can then be processed repeatedly to produce new variants as existing versions become detectable.
This creates an ongoing contest between attackers adapting their techniques and defenders improving detection. The broader lesson is straightforward. Security effectiveness cannot be assumed to remain static while the threat environment continues to change around it.
Effectiveness Requires Ongoing Assurance
Cybersecurity assurance should not end the moment a control is implemented. NIST's continuous monitoring guidance, set out in SP 800 137, emphasises ongoing visibility into threats, vulnerabilities and the effectiveness of deployed security controls. The objective is to give organisations enough information to respond when observations suggest existing controls may be inadequate.
This does not mean constantly replacing security technology. It means having a process for understanding whether important controls continue to perform the role expected of them, and treating that as a governance responsibility rather than a purely technical one.
| Evidence of Activity | Evidence of Effectiveness |
|---|---|
| The control is installed and enabled | The control is still detecting or blocking the threats it was chosen to manage |
| Updates are applied on schedule | Those updates translate into a measurably lower rate of missed detections |
| A monitoring tool is in place | Someone reviews what it reports, and acts when it flags a gap |
What Business Leaders Can Learn
Implementation is only the beginning. A deployed control still needs ongoing oversight rather than a single point of approval. This is the kind of continuing attention that virtual ISM support is often used to provide once the initial rollout is complete.
Threats change. Attackers can and do adapt their techniques in response to improvements in defensive technology, as the crypter advisory demonstrates. A control that was effective last year deserves the same scrutiny this year, not an assumption that nothing has moved.
Evidence should demonstrate effectiveness. Reporting that a control is enabled is different from demonstrating the outcome it is producing. This distinction sits at the centre of the governance gap explored in The Evidence Gap, where activity and proof are too often treated as the same thing.
Layered security matters. ASD recommends multiple complementary measures rather than reliance on one detection mechanism, including application control, endpoint detection, antivirus configuration, system maintenance and behaviour based techniques. Where new layers need to be added, tools and implementation support can help put them in place without unnecessary overhead.
Leadership does not need every technical detail. It does need confidence that critical controls are being monitored, assessed and improved when necessary, which is the assurance that vCISO advisory is typically brought in to provide at board and executive level.
Questions Every Executive Should Ask
- Which security controls are most important to managing our key cyber risks?
- How do we know those controls are operating effectively?
- What evidence supports that conclusion?
- Are we measuring activity or actual security outcomes?
- How frequently is effectiveness reviewed?
- How do changing threats influence those assessments?
- Are we overly dependent on a single security technology or detection method?
- Who is responsible for identifying when a control is no longer providing sufficient protection?
- What happens when testing or monitoring identifies a gap?
Worth Noting
If these questions are difficult to answer, the issue may not necessarily be the absence of security controls.
It may be a lack of assurance about their continuing effectiveness.
Security Should Evolve With the Risk
The answer to evolving threats is not necessarily to keep buying more security tools. It is to understand what risks matter, what controls manage those risks and whether those controls continue to deliver the expected outcome. The ASD advisory itself recommends a layered approach, combining different preventive and detection capabilities rather than depending solely on traditional signature based detection. Effective cybersecurity therefore requires both controls and continuing assurance that those controls remain appropriate for the risk, a connection also explored in Aligning Security with Strategy.
SeComPass helps organisations approach cybersecurity through governance, risk and evidence. This includes helping leadership understand which controls matter to the organisation, how those controls relate to business risk and what evidence is needed to provide meaningful assurance that cybersecurity governance is working in practice. The objective is not simply to demonstrate that controls exist, but to build better visibility into whether cybersecurity continues to support the organisation's risk and business requirements.
Key Takeaways
- A control being installed and a control being effective are two different questions, and organisations tend to be far more confident answering the first
- Attackers adapt their techniques as defensive technology improves, so effectiveness cannot be assumed to stay constant over time
- Continuous monitoring, as set out in NIST guidance, is about ongoing visibility into whether controls still work, not constant technology replacement
- Evidence should show outcomes, not just activity, a distinction that matters as much for governance as it does for cybersecurity
- Layered security and clear ownership of ongoing review matter more than any single detection mechanism
Understand Whether Your Controls Still Work
Can You Show Your Security Controls Are Still Effective?
The Executive Readiness Review helps leadership teams understand which controls matter most, what evidence demonstrates their effectiveness and whether cybersecurity governance continues to reflect a changing risk environment. It includes:
- Identification of the controls that matter most to your key cyber risks
- Review of the evidence currently used to demonstrate effectiveness
- Assessment of whether current controls remain appropriate as threats change
- Strategic priorities for building ongoing assurance rather than a one off check
Know what protects you, understand whether it works, and keep testing whether it remains effective.
Start the Executive Readiness Review →References
- Australian Signals Directorate's Australian Cyber Security Centre. "Digital camouflage: crypters make malware undetectable," 8 September 2026. cyber.gov.au
- Australian Signals Directorate's Australian Cyber Security Centre. "Digital camouflage: how crypters hide malware," 8 September 2026. cyber.gov.au
- National Institute of Standards and Technology. "Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations," SP 800 137, September 2011. csrc.nist.gov
This article is for general informational purposes only and does not constitute legal, technical, or professional cybersecurity advice. SeComPass recommends engaging a qualified adviser before making decisions based on this content. The ASD advisory referenced above shows that crypters can make malware harder for security products to detect and can undermine traditional signature based detection. It should not be read as a claim that malware is universally undetectable, that antivirus and other controls are ineffective, or that every organisation is currently being targeted by crypters.