OneClickComply
    Back to BlogBest Practices

    The forgotten parts of cybersecurity and compliance

    Finn O’Brien
    4 November 2025

    When most organisations think about cybersecurity, they picture technical defences such as firewalls, encryption, and access controls. Yet many of the core weaknesses uncovered during audits aren’t the result of missing technology. They’re the result of everyday oversights; the procedural gaps, physical vulnerabilities, and poor information management.

    These are the forgotten fundamentals. The parts of cybersecurity that rarely make it into boardroom discussions, but are often the most essential to achieving and maintaining compliance. They’re also the issues that most commonly surface when businesses work towards standards like ISO 27001, SOC 2, and Cyber Essentials.


    Physical Security - The First Layer

    Despite its importance, physical security is often one of the least prioritised aspects of cybersecurity. Businesses are quick to invest in digital tools, but will continually overlook the physical environment those tools depend on. A single point of weak access control, such as an unlocked office, unattended reception desk, or shared key code, can undermine every digital safeguard in place.

    Auditors frequently discover gaps such as missing visitor logs, uncontrolled contractor access, or servers located in unlocked rooms. Finding these issues during a review is often a clear indication that the business lacks a systematic approach to managing who can access physical assets and when.

    This area becomes especially relevant in hybrid or co-working environments where boundaries are less defined. Shared office spaces often lack the same level of access control or security awareness as traditional workplaces, which can expose sensitive data or equipment to unauthorised access.

    What auditors look for:

    • Controlled access to buildings and server rooms.
    • Evidence of visitor management processes.
    • Secure handling of hardware and devices, especially portable ones.
    • Policies covering physical security, with proof of staff awareness.

    How to strengthen it:

    Establish individual access credentials, maintain detailed logs of entry and exit, and ensure regular reviews of physical security arrangements. Physical access should be treated with the same scrutiny as user permissions in a digital system.


    Clear Desks and Locked Screens - An Everyday Discipline

    The clear desk and locked screen principles are among the simplest, yet most neglected, security controls. Their effectiveness lies in consistency, but it’s that very same consistency that is often the hardest to actually implement within a business.

    During an audit, it’s not uncommon to find unattended laptops displaying sensitive data, meeting notes left on whiteboards, or documents discarded in open bins. These issues are rarely malicious, instead being the result of familiarity and routine, but over time, staff grow too comfortable in their environment and stop viewing it as a potential risk surface.

    A clear desk policy is as much about reinforcing culture as it is about reducing risk. It demonstrates that protecting information is part of everyday behaviour, not something reserved for IT teams or senior management. Locked screens and clean workspaces prevent accidental exposure of confidential information to visitors, contractors, or even other employees who shouldn’t have access.

    What auditors look for:

    • Evidence that clear desk and screen policies are documented and communicated.
    • Observations of whether desks and screens are compliant during site visits.
    • Proof of employee awareness or training on these policies.

    How to strengthen it:

    Regular internal spot checks can help reinforce habits and maintain accountability. Conduct training on the importance of clear desks and locked screens. Enforce auto-locking mechanisms on devices.


    Document Control: Knowing What’s Current and Correct

    Document control remains one of the most persistent challenges when managing compliance and cybersecurity. While most organisations produce detailed policies and procedures, few can actually guarantee they’re always current or that staff are working from the latest version.

    Auditors often encounter outdated documents stored in multiple locations, conflicting versions of the same policy, or evidence that key documents haven’t been reviewed for an extended period of time. In some cases, employees reference locally saved copies that no longer align with approved practices.

    The issue here isn’t a general lack of care by staff - it’s oversight. Without centralised management and effective version control, documentation can quickly become fragmented, especially as teams grow or processes evolve. This leads to uncertainty about which controls are actually in force and undermines the organisation’s ability to prove compliance.

    What auditors look for:

    • Controlled repositories for documentation (with access logs).
    • Version history and approval records for policies, procedures, and other core documentation.
    • Regular review cycles with clear evidence of updates.
    • Defined ownership of each document.

    How to strengthen it:

    Implement a structured document management system with clear ownership, approval, and review systems. Make it easy to track revisions and ensure only approved versions are visible to employees. Regular internal reviews should also be conducted to verify that policies align with current internal practices.


    Access Management - The Balance of Control and Convenience

    Access management is a cornerstone of both cybersecurity and compliance - yet it’s another key area where even the most mature organisations frequently fall short.

    The most common findings include former employees retaining access to systems, shared accounts without identifiable owners, and a lack of evidence that access rights were reviewed or approved. These are not always the result of carelessness but of scale. As systems multiply, it becomes increasingly difficult to maintain a clear overview of who can access what, and whether that briefly elevated account was properly managed.

    In many cases, access management processes are reactive rather than proactive. User provisioning and deprovisioning happen manually, and periodic reviews are skipped due to time pressures. The result is what auditors often describe as “access creep”, where users accumulate unnecessary permissions over time, increasing both the risk of error and the impact of potential compromise should a threat gain access to a user’s elevated account.

    What auditors look for:

    • Clearly documented joiner, mover, and leaver procedures.
    • Evidence of access approval and removal records.
    • Regular, logged access reviews and audits.
    • Segregation of duties to prevent excessive privilege.

    How to strengthen it:

    Adopt role-based access controls and automate access reviews where possible. Maintain a clear link between HR processes and system permissions, ensuring accounts are adjusted or removed immediately when roles change.


    Information Storage, Printing, and Disposal - Managing the Data Lifecycle

    Data doesn’t stop being sensitive once it’s printed, stored on a removable drive, or archived in an old folder. Yet many organisations fail to treat physical and legacy information with the same care as active digital assets.

    Auditors have found unsecured filing cabinets, forgotten USB devices, and printed reports containing personal or confidential data left in general waste. Similarly, backups or archived data are often stored indefinitely without review, increasing the risk of exposure and complicating data protection compliance.

    The principle of secure disposal applies equally to paper, devices, and digital storage. Every piece of information has a lifecycle. It is created, stored, used, and ultimately destroyed. A lack of defined retention periods or disposal procedures can expose businesses to unnecessary risk long after data has outlived its purpose.

    What auditors look for:

    • Defined retention and disposal policies.
    • Evidence of secure waste management (e.g., shredding or certified disposal).
    • Controls for removable media and backups.
    • Records of disposal or data destruction.

    How to strengthen it:

    Regularly review stored data, both digital and physical, to confirm it’s still needed and properly protected. Ensure secure destruction methods are used and documented, and keep disposal records as part of audit evidence.


    How OneClickComply Brings the Overlooked into Focus

    The challenge with these overlooked areas isn’t awareness, but visibility. Businesses rarely ignore these controls intentionally; they simply lose track of them amidst the ever-growing complexity of daily operations and frameworks.

    That’s where OneClickComply bridges the gap.

    Our platform transforms compliance from a reactive process into a continuous one. By breaking every supported standard into specific, actionable tasks, OneClickComply helps organisations maintain control over even the most easily forgotten areas of cybersecurity.

    • Automated scanning identifies missing or misconfigured controls before they escalate into audit findings.
    • Our OneClickFix technology implements technical settings automatically, patching security and compliance gaps in an instant.
    • Continuous monitoring keeps every aspect of compliance aligned with real-world configurations, policies, and processes.
    • Automated policy generation ensures that policies are always up-to-date, using your currently implemented controls and settings to build accurate content.

    Beyond automation, OneClickComply helps makes the invisible visible. By breaking compliance standards down into clear, manageable sections, it helps surface the physical, procedural, and human aspects of cybersecurity that are too often missed, ensuring nothing falls through the cracks. Coupled with built-in device vulnerability management, questionnaire automation, and other industry-leading features, OneClickComply truly helps businesses manage and achieve their compliance goals.

    Because genuine security isn’t defined by technology alone. It’s built on disciplined processes, well-maintained evidence, and a business that doesn’t forget the fundamentals.

    Want to see OneClickComply in action?

    Book a demo and see how we automate compliance for organisations like yours.

    Book a Demo