This article is based on the latest episode of CYBR.Minded with Dr. Dustin Sachs. Check out the full episode:

For decades, cybersecurity has rewarded visible effort. More tools. More dashboards. More controls. More metrics.
The problem, according to CISO Tradecraft co-host Ross Young, is that visibility is not the same thing as effectiveness. Organizations have become remarkably good at demonstrating security activity while remaining surprisingly poor at explaining whether any of that activity actually reduces business risk.
That disconnect has quietly become one of cybersecurity's biggest leadership challenges.
Looking busy is easy
Security teams don't intentionally build security theater. It happens naturally.
Executives want measurable progress. Boards want dashboards. Auditors want evidence. Regulators expect documentation.
The easiest response is to produce more numbers. Tool coverage increases. Vulnerability counts shrink. Projects close on schedule. Compliance percentages climb.
None of those metrics are inherently bad. The danger comes when organizations mistake them for proof that attackers are less likely to succeed.
A security program can appear mature while still being built around the wrong priorities.
More CYBR.Minded:


Start with what actually hurts
Young argues that organizations should begin somewhere entirely different.
Before discussing products, frameworks, or budgets, leaders need agreement on the handful of threats capable of causing meaningful damage to the business.
Only after those threats are identified should organizations decide which safeguards deserve investment.
Without that discipline, purchasing decisions become reactive. Every new headline produces another security product. Every vendor promises visibility. Every dashboard claims to improve risk.
Eventually, organizations accumulate dozens, sometimes hundreds, of overlapping technologies that generate alerts without generating clarity.
Governance isn't paperwork
Governance often gets treated as an administrative exercise revolving around policies, committees, and board decks. Young sees it differently.
Governance exists to ensure everyone, from engineers to executives, is solving the same problem.
When organizations share a common understanding of material threats, security investments become easier to justify and easier to measure.
Without that shared language, teams naturally optimize for whatever looks good on quarterly reports instead of what actually changes outcomes.
Vanity metrics create false confidence
The conversation turns especially practical when discussing phishing simulations.
Young jokes that if leadership wants a particular phishing failure rate, he'll happily produce it.
His point is simple: Many cybersecurity metrics are surprisingly easy to manipulate. Organizations can make phishing exercises easier or harder. Change who receives them. Adjust reporting windows. Redefine success. The resulting number may satisfy leadership. But it says very little about whether employees will recognize a sophisticated real-world attack.
Useful measurements become dangerous when they're disconnected from business outcomes.
Better questions produce better security
Young believes security leaders should spend less time asking what to buy and more time asking better questions.
- Which threats matter most?
- Which safeguards demonstrably reduce those threats?
- How do we know they're working?
- What organizational conditions could cause those safeguards to fail?
- Those questions are harder to answer than comparing product feature lists.
They're also far more likely to improve resilience.
Leadership, not technology, is the differentiator
One of the interview's strongest messages is that cybersecurity's biggest challenges are increasingly human. Organizations don't become secure because they deploy another platform.
They become secure because leadership understands which risks deserve attention, funds defenses that materially change outcomes, and resists the temptation to mistake visible effort for meaningful protection.
Security theater may satisfy a board presentation.
It won't stop the next breach.


