Chapter 27
27Continual Improvement and Adapting to a Changing Landscape
“A system that never changes protects against yesterday’s threats.”
With a strong set of controls in place, the journey to secure the creative cyberspace has not ended; it has only just begun. The most important stage in the standard is the continual maintenance and improvement of the system. This chapter discusses strategies for keeping security practices effective and adapting to a landscape that never stops evolving.
The Plan-Do-Check-Act (PDCA) Cycle
Management systems rest on the PDCA cycle, the model of continual improvement that makes it easy to evaluate and develop the system without pause. This iterative process keeps the system effective in the face of new challenges and organisational change.


Text in this figure
Management · system · Plan · Risks and objectives · Do · Controls, training · Check · Audit, measure · Act · Correct, update · Figure 34
- Plan: Setting the objectives and processes needed to deliver results in line with the policy: risk assessment, the treatment plan, and selecting controls.
- Do: Implementing and operating the planned processes and controls: training staff, deploying new technologies, and putting procedures into practice.
- Check: Monitoring and reviewing performance against the policy, objectives and practical experience: internal audit, security metrics and management reviews, then reporting results to management.
- Act: Actions for continual improvement: correcting nonconformities, updating the risk assessment and treatment plan, and every adjustment needed to strengthen the system.
Nonconformity and Corrective Action
When a nonconformity is found, in an audit, an incident or a complaint, Clause 10 requires: acting to contain it, analysing its root cause, taking action to prevent recurrence, and verifying the effectiveness of that action. The difference between a “correction” and a “corrective action” is fundamental: the first fixes the problem; the second fixes what allowed it to happen.
Adapting to New Threats
The creative industries are at the forefront of innovation, using technologies and collaborative platforms that bring unexpected challenges. To adapt the system to evolving risks:
- Stay informed with threat intelligence: New threats targeting creative content and intellectual property, through threat intelligence feeds, security conferences and networking with professionals. It is an explicit control in 2022 (5.7).
- Flexible, agile policies: Not rigid, but adaptable to the changing nature of creative work and technology use, so they stay relevant and effective.
Emerging Technologies and Their Impact on Creative Security
- Artificial intelligence: A double-edged sword: it automates threat detection, response and vulnerability identification with unprecedented speed and accuracy, and brings new challenges: securing generated content, protecting systems from manipulation and adversarial attacks, and the ethics of using it for security. We devoted all of Part Five to it.
- Blockchain: New ways to manage copyright and intellectual property with a transparent, immutable record that guards against plagiarism and piracy, and new business models such as micropayments and fractional ownership.
- Internet of Things (IoT): From smart cameras and microphones to connected printers and displays, every device is a potential entry point, and securing it is essential against unauthorised access and data leakage.
2026 Update
Add to the list today: quantum computing, which threatens current encryption algorithms in the medium term; in 2024 the US National Institute of Standards and Technology (NIST) approved the first post-quantum cryptography standards, so start by inventorying where you use encryption. And AI-generated fake content, which makes proving the authenticity of creative work a necessity rather than a luxury.
The future of creative security is not only about defence; it enables new forms of expression through innovative, proactive security practices. Maintaining and improving security is a continuous journey that demands vigilance, adaptation and a steadfast commitment to improvement.
Lessons Learned
- 1The PDCA cycle drives improvement in both standards.
- 2Corrective action addresses the root cause, not the symptom.
- 3Threat intelligence and flexible policies keep the system relevant.
- 4AI, blockchain, IoT and quantum computing are redrawing the risk map.
Tip: use ← → to move between sections.

