Security theater refers to the practice of implementing security measures in the form of people, processes, or technologies that give the illusion of improved security. Simply put, it means something is happening, but what that is and how it actually provides protection is questionable.
It is essentially the illusion of security that often results from prioritizing actions that appear effective but fail to improve security.
Read More about Security Theater
The term was coined by Bruce Schneier way back in 2009. Learn more about it below.
Why Do Some Widely Implemented Policies Result in Security Theater?
Implementing cybersecurity policies is definitely the way to go. But some experts like Schneier say enacting them and letting them do all the work without due diligence and vigilance won’t work. Want to know some examples? Here they are.
Security Awareness Training Gone Bad
Yes, every organization needs to make all its employees security-aware. But making them listen to an hour-long mandatory lecture probably won’t help. It’s not enough for them to hear, they should put what they learned into practice. So, instead of lecturing them and asking them to answer a quiz afterward, try putting them through an exercise. Send them a fake phishing email and see how well they avoid falling for it.
Complex Passwords Alone Won’t Cut It
While password complexity indeed helps enhance security, using a long, random mix of lower- and uppercase letters, numbers, and symbols isn’t enough to protect accounts from hackers. What would actually work better is to mix complex passwords with encryption and multifactor authentication (MFA).
Compliance Isn’t Security
Some industries, like the healthcare and financial service sectors, require organizations to comply with strict regulations, such as the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Payment Card Industry Data Security Standard (PCI DSS), respectively. And given that no company these days is safe from cyber attacks, almost all comply with regulations like the General Data Protection Regulation (GDPR) and the National Institute of Standards and Technology (NIST) Cybersecurity Framework to assure their customers they are protected against cyber threats.
But while ensuring adherence to the bare minimum that such regulations mandate may save organizations from legal woes, it doesn’t guarantee protection against breaches or advanced and new threats.
What Are the Effects of Security Theater?
The concept can result in tangible (money) and intangible (time) costs. When organizations get hacked, they not only lose time and money putting everything back together—recovering lost data, repairing damaged systems, and others—their reputation also gets tarnished, resulting in customer confidence and revenue loss. They also need to pay fines and other legal fees.
How Can Organizations Prevent Security Theater from Happening?
So, how can anyone stop suffering from security theater? Experts named some best practices.
- Comply with regulations, but don’t stop there. Companies should have a comprehensive security strategy that gets reviewed and updated regularly.
- Encourage every employee, not just the members of the security department, to adopt a security-first mindset. That means not just memorizing what to do when they see a phishing email, for instance, but putting their knowledge into action.
- Stop relying on checklists because that translates to complacency. Constantly monitor for vulnerabilities instead.
- Start building applications and systems with security in mind. Leverage DevSecOps.
- Test how effective your security is. Security shouldn’t stop at Implementing solutions. Do penetration tests and other assessments to really see if your strategies work.
—
When Schneier first talked about security theater, he explained the concept with an example—aviation security. He said while many may think airport security is airtight, it actually isn’t. If it were, then planes would never get hijacked.
Key Takeaways
- Security theater refers to the practice of implementing security measures through people, processes, or technologies that give the illusion of improved security.
- Bruce Schneier coined the term as far back as 2009, comparing it to aviation security.
- While implementing security policies is the way to go, remaining complacent after they’re up and running gives a false sense of security.
- Cybersecurity awareness training done right, combined with the use of complex passwords, encryption, and MFA, can prevent security theater.
- The illusion of being cyber secure or security theater can result in tangible and intangible costs.
Sources
- https://www.linkedin.com/pulse/security-theater-worst-lee-vorthman-53zdc/
- https://www.schneier.com/blog/archives/2009/11/beyond_security.html
- https://www.paloaltonetworks.com/blog/prisma-cloud/compliance-security-theater/
- https://www.linkedin.com/pulse/security-theater-worst-lee-vorthman-53zdc/






