Due diligence vs due care
"Due diligence" and "due care" come up constantly in security and compliance conversations, and they're easy to confuse. They're related, but they describe two different responsibilities.
Due diligence
Due diligence is the ongoing effort to identify and understand risk. It's the research and investigation: knowing what data and systems you have, what could go wrong, which regulations apply, and how a vendor or partner manages security. Reviewing a supplier's SOC 2 report, running a risk assessment, and keeping an asset inventory are all forms of due diligence.
Due care
Due care is acting on what due diligence reveals. It's implementing and maintaining reasonable safeguards to reduce the risks you've identified — deploying controls, writing and following policies, training staff, and monitoring that the controls keep working. In short, due diligence is knowing; due care is doing.
Why the distinction matters
Regulators, courts, and customers expect both. Due diligence without due care means you understood a risk and failed to act on it. Due care without due diligence means you're implementing controls without knowing whether they address your actual risks. Demonstrating both — that you identified risks and took reasonable steps to address them — is what establishes that an organization behaved responsibly, and it's central to frameworks like NIST and to standards of "reasonable" security.
In practice
- Maintain an up-to-date inventory of systems and data (diligence).
- Run regular risk assessments and vendor reviews (diligence).
- Implement and maintain controls mapped to those risks (care).
- Keep evidence — policies, logs, training records — that the controls operate (care).
Do both continuously, and you're not just more secure — you can show it.