Kovr

The Spreadsheet Will Not Save You: Why Cyber Compliance Needs AI

The cybersecurity industry discovered over 40,000 new vulnerabilities in 2024, a 38% increase from the previous year. At this rate, security teams are being asked to manage an average of 108 new Common Vulnerabilities and Exposures daily Yet, the tools most organizations use to track compliance with frameworks like FedRAMP, CMMC, and NIST 800-53 remain stubbornly analog: spreadsheets, checklists, and the occasional heroic effort by overworked compliance officers.

This is not a sustainable model. It is barely a model at all.

Patrick Opet, global CISO at JPMorgan Chase, made this point with unusual bluntness in a recent open letter to software suppliers. “Over the past three years, our third-party providers experienced a number of incidents within their environments.” describing how these breaches forced the bank to isolate compromised providers and dedicate substantial resources to threat mitigation. When one of the world’s most sophisticated financial institutions, with security budgets that would fund small nations, finds itself overwhelmed by supply chain vulnerabilities, something has fundamentally broken.

The Perfect Storm

Three forces are converging to make traditional compliance approaches untenable. 

First, the threat landscape has metastasized beyond recognition. The 40,000 CVEs reported in 2024 mark more than a statistical uptick, they signal  a fundamental shift in the modern attack surface. Opet warned that threat actors are increasingly exploiting third-party technologies and remote-access tools, the very systems compliance frameworks are meant to secure. When vulnerabilities are published faster than security teams can evaluate, let alone remediate, the concept of “keeping up” becomes quaint.

Second, the velocity of software development has accelerated dramatically. DevSecOps and abundant venture capital have created an environment where systems evolve faster than they can be secured. Cloud-native architectures, microservices, and continuous deployment have turned compliance targets  into constantly shifting systems. As Opet noted, modern identity protocols like OAuth create direct connections between third-party services and sensitive internal resources.  A compliance audit that takes six months to complete is obsolete before the auditors pack their briefcases.

Third, regulatory frameworks themselves have grown more complex and numerous. Organizations in highly regulated sectors must now navigate an alphabet soup of standards: FedRAMP, CMMC, DoD SRG, StateRAMP, and various NIST 800-53-based frameworks, each with hundreds of controls. Gartner’s recent Market Guide for DevOps Continuous Compliance Automation Tools notes that these frameworks are “expanding beyond traditional regulations involving health privacy (HIPAA) and personal privacy (GDPR) to include cybersecurity (NIST 800-218) and government (FedRAMP, DORA [EU]) mandates.”

The result? System owners and compliance teams face an impossible task, trying to manage expanding security requirements across rapidly changing infrastructure. The July 2024 CrowdStrike outage impacting 8.5 million Windows devices and halting trading for major institutions such as JPMorgan Chase, shows how fragile the modern software supply chain has become.

The LLM Opportunity (With Caveats)

Large language models represent the first genuinely transformational technology for compliance automation in decades. Unlike previous generations of compliance software, which merely digitized spreadsheets, LLMs can understand the semantic meaning of security controls, map requirements across frameworks, generate evidence documentation, and identify gaps with a sophistication that approaches human expertise.

The promise is considerable: Gartner predicts that by 2028, 65% of organizations will have integrated compliance automation into their DevOps workflows, reducing  risk and improving lead time by at least 15%. Other  research suggests that automated compliance platforms can save security teams over 100 hours annually, freeing time for strategic security initiatives rather than administrative compliance theater.

Yet the path from promise to practice is littered with obstacles. LLMs are computationally expensive and, without expert engineering, can quickly become cost-prohibitive at enterprise scale. They are also prone to hallucination, a charming term for making things up, which in a compliance context could mean generating documentation for controls that don’t actually exist or citing policies that were never implemented. When the consequence of error is a failed audit or, worse, a security breach, “mostly accurate” is not good enough.

Moreover, enterprise compliance exists within a complex ecosystem. Effective automation requires integration with existing Governance, Risk, and Compliance platforms such as Xacta, ServiceNow GRC, and eMASS. It must draw from diverse enterprise sources: vulnerability scanners, configuration management databases, identity and access management systems, and cloud service provider APIs. An AI solution that exists in isolation, however sophisticated, becomes an expensive e novelty.

This is precisely what Opet called for in his letter, improved security standards and more transparency into how suppliers use privileged access. But transparency requires systems that can continuously monitor and report on security posture across interconnected supply chains, a task beyond human capability at current scale.

The Engineering Challenge

The companies succeeding in this space are not simply wrapping GPT-4 in a user interface and calling it a product. They are building AI-native platforms to solve  the fundamental engineering challenges of applying language models to compliance at scale.

This requires several technical capabilities. 

  • First, fine-tuned models trained on security frameworks and compliance documentation to reduce hallucinations and improve domain-specific tasks. 
  • Second, intelligent retrieval systems that can efficiently search across hundreds of thousands of pages of requirements, evidence, and documentation to provide the most relevant context. 
  • Third, cost optimization techniques,  through careful model selection, prompt engineering, and caching strategies that make continuous compliance monitoring economically viable.

Most importantly, these platforms must integrate deeply with enterprise infrastructure. Compliance automation that cannot automatically collect evidence from existing security tools, or export findings to the GRC platforms that auditors actually use, creates more work than it eliminates. The solution must fit the organization, not the other way around.

A New Category Emerges

Against this backdrop, a new category of AI-native compliance automation is taking shape. Gartner defines this category as DevOps Continuous Compliance Automation (DCCA) and it will be a $10B+ category within just a couple of years. Kovr.AI is pioneering this new category of vertical AI built for enterprise cyber, not a GPT-wrapper or general-purpose compliance tool retrofitted with AI features. But rather, the Kovr.AI system is architected from the ground up around large language models, designed to integrate with enterprise data stores and existing GRC platforms.

Surrounding Kovr.AI is an ecosystem of partners and interconnections that provide a rising tide for secure, modern digital systems. Accelerators like Second Front Systems offer an inherited control model to make it faster and easier for system owners to secure their environment. Traditional consultancies are shifting to focus on high end readiness work, securing customer systems rather than copying and pasting around spreadsheets. Established GRC platforms like Xacta, Servicenow GRC, and eMASS maintain their position as systems of record.

For organizations like the U.S. Government, JPMorgan Chase, and any organization doing business in these regulated enterprises, this capability is not a luxury but a necessity. The new tech stack provides continuous monitoring and even evaluation. 

The Spreadsheet’s Last Stand

The spreadsheet had a good run. For decades, it was the universal tool of businesses, flexible enough to handle anything, simple enough for anyone to use. But when spreadsheets run 800 rows deep with a dozen columns and require continuous updates across multiple frameworks, they have outlived their ability to keep pace with the work. There are some problems that flexibility cannot solve, and cyber compliance in 2025 is one of them.

When vulnerabilities arrive at a rate of 108 per day and systems change continuously, compliance cannot be a quarterly event. When frameworks contain hundreds of interconnected controls, manual mapping becomes an exercise in futility. When the cost of non-compliance includes not just failed audits but catastrophic breaches, companies cannot afford to rely on tools that were never designed for the complexity they now face.

Recognition without capability is merely well-intentioned handwringing. The question is not whether AI will transform compliance automation, the engineering is already happening, the products are already being built, and the market is already responding. The real question is whether organizations will recognize the shift quickly enough to adopt these tools before the old approaches fail entirely.

Given the stakes, one hopes they will not wait for a spreadsheet to tell them it’s time to change.