Overview
Mathew Caplan has spent 25 years watching compliance programs grow more complex without becoming more secure. At DefCamp 2025, he makes the case that overlapping frameworks and bureaucratic process have become the noise, not the signal. His argument: practitioners need to stop treating compliance as an end in itself and start asking which controls actually reduce risk.
Key Takeaways
- Compliance complexity is often self-inflicted — simplifying frameworks reduces noise without reducing security.
- Treat compliance as a means to manage real risk, not an end goal or checkbox exercise.
- Experienced practitioners cut through framework overlap by mapping controls to shared outcomes, not duplicating effort.
About the Speaker
Mathew Caplan
Mathew Caplan is Head of International Professional Services for Orange Cyberdefense based in London, England. He is a highly experienced information security and compliance specialist with over 25 years in the field and a proven record in the implementation of information risk management processes. As a recognised trusted advisor, Mathew has helped many businesses with cybersecurity strategy, governance, process and policy. He works in the Orange Group on many international projects being the go-to guy on security and compliance matters and enjoys finding sustainable solutions to challenging problems. Mathew loves cats, movies and music and wherever possible will combine his audio-visual skills to simplify complex topics and breathe life into cybersecurity.