Compensating Controls: When the Ideal Security Control Isn’t Possible

Imagine a building where the main entrance should have a modern electronic access-control system.

The organisation wants to install one, but the building is old and the door cannot support the required system without major structural work.

Does that mean the entrance has to remain completely unprotected?

No.

Instead, the organisation might use a combination of:

  • A physical key
  • A security guard
  • CCTV
  • An access register
  • Regular checks of who has access

These controls don’t provide exactly the same protection as the planned electronic system, but together they can reduce the risk to an acceptable level.

This is the basic idea behind a compensating control.

A compensating control is an alternative security measure used to reduce a risk when the preferred or required control cannot be implemented fully.

Why Do We Need Compensating Controls?

In an ideal world, every organisation would implement the strongest and most appropriate security control for every situation.

In reality, this isn’t always possible.

There may be:

  • Legacy systems
  • Technical limitations
  • Compatibility problems
  • Financial constraints
  • Operational requirements
  • Business requirements
  • Physical limitations
  • Availability requirements
  • Regulatory requirements
  • Systems that cannot easily be changed

For example a policy that states “This application must use MFA.” sounds straightforward, but what if the application was written 20 years ago and doesn’t support MFA?

The organisation still has a security risk.

A compensating control may provide another way of reducing that risk.

Compensating Controls Aren’t a Free Pass

A compensating control shouldn’t simply mean “We can’t be bothered to implement the proper control.”

There should be a genuine reason why the preferred control cannot be implemented.

For example “This legacy system cannot support MFA.” is very different from “MFA is inconvenient.”

The organisation should understand why the original control isn’t possible and then determine how the risk can be reduced.

The objective isn’t necessarily to recreate the original control – The objective is to reduce the risk created by its absence.

Compensating Controls Don’t Have to Be Technical

This is an important point.

A compensating control can be technical, but it can also be

  • Physical
  • Administrative
  • Procedural
  • Personnel-based

It doesn’t have to be another piece of technology.

Where technically possible, the original control type may still be preferable.

Technical Compensating Controls

Technical controls use technology to compensate for the missing or weaker control.

Examples include:

  • Network segmentation
  • Firewalls
  • VPNs
  • Application gateways
  • Additional authentication layers
  • EDR
  • Application allowlisting
  • Increased logging
  • DLP
  • Privileged Access Management
  • Network Access Control
  • Encryption

Physical Compensating Controls

Compensating controls can also be physical.

For example, imagine a server room has an old mechanical lock that cannot be replaced immediately.

The organisation could introduce:

  • Security guards
  • CCTV
  • Additional physical barriers
  • Restricted building access
  • Security patrols
  • Access registers

Administrative Compensating Controls

Administrative controls rely on policies, processes and people.

Examples include:

  • Additional approval
  • Manual checks
  • Dual authorisation
  • Security procedures
  • Staff training
  • Increased auditing
  • More frequent reviews
  • Restricted responsibilities

Temporary vs Permanent Compensating Controls

A compensating control can be:

  • Temporary – Used until the preferred control can be implemented.
  • Long-term – Used where the preferred control genuinely cannot be implemented.

Temporary compensating controls should ideally have a defined end date otherwise they can inadvertently become permanent ones.

There is a danger here.

An organisation might say “We’ll use this workaround until the system is upgraded.”

Five years later, the workaround is still there.

This creates a security debt.

Compensating controls should therefore be reviewed regularly.

Compensating Controls Should Be Documented

An organisation should know:

  • What control is missing?
  • Why can’t it be implemented?
  • What risk does this create?
  • What compensating control is being used?
  • Who approved it?
  • Who owns it?
  • How effective is it?
  • When will it be reviewed?

This creates accountability.

Risk Assessment

A compensating control should be selected based on risk.

Consider a critical server which cannot be patched due to incompatibility with software.

First determine:

  • What vulnerability exists?
  • How exploitable is it?
  • What data does the server contain?
  • Can the attacker reach it?
  • What would happen if it were compromised?

Then consider possible controls. The control should address the actual risk.

Don’t just pick a convenient control. If the system cannot be patched against a vulnerability, don’t just put an antivirus solution on it.

That might help – but is antivirus actually addressing the risk? Perhaps the vulnerability is remotely exploitable through a network service, in which case, network isolation might provide significantly more risk reduction.

Compensating controls should be chosen deliberately.

A Compensating Control May Be Cumulative

Sometimes one alternative control isn’t enough. The organisation may need several controls working together.

This is often more realistic than looking for a single replacement control.

Compensating Controls and Compliance

Compensating controls are particularly important in regulated environments.

A standard or regulation may specify that a particular control should be implemented. If it cannot be implemented, there may be a defined process for demonstrating that alternative measures provide sufficient protection.

However, organisations should be careful:

A compensating control is not automatically acceptable simply because it reduces some risk.

The relevant regulatory or contractual requirements may specify exactly how exceptions and compensating controls must be handled.

Compensating Controls Should Be Measurable

If an organisation claims that a compensating control reduces risk, it should ideally have evidence to back this claim.

For example:

  • Firewall rules reviewed regularly
  • Access logs monitored
  • Security alerts investigated
  • Privileged access reviewed
  • Network isolation tested
  • Manual procedures audited

Compensating Controls Need Testing

A compensating control that exists only on paper isn’t much use.

For example, stating that “The legacy server is isolated from the network because we cannot install the latest patch” doesn’t prove that the risk has been mitigated.

Is it actually isolated?

Testing might reveal otherwise

Controls should be tested just like other security controls.

Compensating Controls Need Monitoring

Threats change, technology changes, the business changes.

A compensating control that was effective two years ago may no longer provide sufficient protection.

Where practical, organisations should eventually implement the preferred control.

Compensating controls should not become an excuse to avoid improving security.

The Limitations of Compensating Controls

Compensating controls aren’t perfect.

They can introduce:

  • Complexity – More controls mean more things to configure and manage.
  • Cost – Additional controls may themselves require investment.
  • Human dependency – Manual controls can depend on people following procedures correctly.
  • Operational overhead – Extra monitoring and approval can slow down business processes.
  • Residual risk – The original weakness may still exist.

An organisation should consider whether the alternative control introduces new problems.

For example, a legacy system which cannot support MFA, so users are required to access it through a shared administrator account, could actually make things worse.

A compensating control needs to be evaluated rather than accepted simply because it is available.

In Summary

Compensating controls are alternative security measures used when the preferred security control cannot be implemented or cannot fully address the risk.

They are particularly useful when dealing with:

  • Legacy systems
  • Technical limitations
  • Compatibility problems
  • Business requirements
  • Physical limitations
  • Temporary security gaps
  • Operational constraints

They can take many forms.

Technical

  • Firewalls
  • Network segmentation
  • VPNs
  • EDR
  • Application allowlisting
  • Additional authentication
  • PAM
  • Increased monitoring
  • DLP

Physical

  • Security guards
  • CCTV
  • Locks
  • Fences
  • Security lighting
  • Physical isolation
  • Restricted areas

Administrative

  • Manual approval
  • Dual control
  • Additional auditing
  • Security procedures
  • Training
  • Access reviews
  • Increased supervision

A compensating control isn’t necessarily the same type of control as the one it replaces. It simply needs to provide meaningful risk reduction for the problem being addressed.

  • A firewall can compensate for a limitation in an application.
  • A security guard can compensate for a failed access-control system.
  • Network isolation can compensate for an unpatchable server.
  • Manual approval can compensate for a system that cannot enforce Separation of Duties.

The objective is always the same:

When you can’t implement the ideal control, don’t simply accept the weakness—find another way to reduce the risk.