The standard is not about “absolute invulnerability”. Instead, it focuses on practical matters such as access control, backup procedures, incident response, continuous risk assessment. In other words, “we think everything is fine” gets replaced with documented processes, accountability, and external audits