How to set up a compliance plan that runs itself, every single day

Unas manos giran el dial de un temporizador de riego montado en un grifo mientras, detrás, una hilera larga de canteros recibe un goteo parejo bajo la luz cálida de la mañana

How to set up a compliance plan that runs itself, every single day

The first time you open the compliance agent’s settings, you don’t find a long form. You find a handful of decisions. Who has to comply, how much time per month you can ask of your people, and when the compliance plan starts running.

None of them is a technical decision. They are judgement calls, and they determine whether the plan moves at a pace your organisation can live with or turns into a source of internal complaints. When we introduced the Compliance Center we covered what the dashboard shows and what the agent does with what it finds. Here we go one level down, into the setup.

What is a compliance plan?

A compliance plan is the sequence of assignments the agent in SMARTFENSE’s Compliance Center builds and carries out day by day to move your awareness programme from the coverage it has today to the coverage each standard requires. It isn’t a document you approve and file away. It’s a live list of actions that gets recalculated every time the organisation or the status of a training changes.

You define it once, and from then on the daily work stops being yours.

How do you define the audience for each standard?

The audience answers the question that breaks most percentages. Who was supposed to comply. A programme can report 100% having trained a fraction of the organisation when the denominator was typed in by hand and went stale.

Here the audience isn’t written out, it’s described. Instead of uploading a list of names, you point at the group, the department or the role inside the directory you already use to grant access to systems. The difference shows up in September, when five new people join. If the audience is a list, someone has to remember to add them. If it’s a rule over the directory, they are already in.

Each standard carries its own audience, and it pays to define them separately from day one. A technical standard such as ISO 27001 may cover the two hundred people in IT and security. An internal policy everyone has to read and accept covers the whole company. A local requirement may stop at the five hundred people in one subsidiary. Those are three different denominators, and averaging them into a single number is exactly what makes the number useless.

How much time per month can you ask of your team?

The monthly budget is the field people argue about most and the one that most shapes how the programme feels from the inside. It’s the training time you’re willing to ask of each person per month, and it works as a hard ceiling. The agent doesn’t exceed it, even with gaps still open.

Choosing it is a straight trade-off. A high budget closes gaps sooner and turns the dashboard green faster, at the cost of overloading people who also have their own jobs to do. A low budget goes down without effort and stretches the plan over months. The logic of sustained microlearning applies here too. Small, frequent doses stick better than one intensive session a year, and they don’t compete with anyone’s calendar.

If your organisation has never run a continuous programme, start below what you think it can absorb and adjust after the first month. Raising the budget once the team has settled into the rhythm meets no resistance. Lowering it after you’ve overloaded everyone does.

What does the agent do with that setup every day?

With those decisions made, the agent works to fixed rules.

It assigns one thing at a time. It doesn’t push a bundle of six trainings on day one or pile up pending items on anyone’s profile. Each person sees what’s due now, and the next item appears once the previous one is closed.

It respects the budget you set. If the month has already used up someone’s available time, that person receives nothing more until next month, even with gaps in their name.

It prioritises the organisation’s biggest gap, not the easiest one to close. This is the rule that changes the outcome most. A plan built by hand tends to move through whatever is comfortable, because clearing twenty pending items on a short training feels productive. The agent orders it the other way round and goes first where the hole is widest, which tends to be the most awkward one to open.

The effect is that the dashboard’s progress becomes boring in the best sense. It climbs a little each week, with no flat months and no spike the night before the audit.

What’s left for you to supervise?

Quite a bit less, and of a different kind. What disappears is the mechanical part, deciding every week who needs what and in which order.

What’s left is checking that the audiences still describe what you mean to require when the company reorganises. Adjusting the budget if the pace grates or if it’s running too slowly for the date you have in mind. And looking at the per-person evidence when someone asks for it, already recorded alongside the component where you publish your standards and policies.

The division of labour is the one we summed up when we introduced the tool. You supervise; it executes.

The start date is counted backwards

It looks like the trivial decision and is the one most often underestimated. The start date marks the moment coverage begins to accumulate, so the sensible way to pick it is to count backwards from your next audit and leave enough room for the monthly budget to close what’s missing.

A plan that starts late doesn’t put you out of compliance. It simply reaches review day with the dashboard halfway there, and that distance can’t be recovered by squeezing the pace at the end. It’s the same underlying problem as when coverage expires quietly and nobody renews it until someone asks.

We’re refining the Compliance Center together with the first teams using it, so the setup we’ve described here will keep moving with what they tell us. If you work in compliance and want to make these decisions over your own audience, you can explore the platform or write to us for a demo and join the Compliance Center early adopter group.

Nicolás Bruna

Product Manager de SMARTFENSE. Su misión en la empresa es mejorar la plataforma día a día y evangelizar sobre la importancia de la concientización. Ha escrito dos whitepapers y más de 150 artículos sobre gestión del riesgo de la ingeniería social, creación de culturas seguras y cumplimiento de normativas. También es uno de los autores de la Guía de Ransomware de OWASP y el Calculador de costos de Ransomware, entre otros recursos gratuitos.

Leave a Reply