Skip to content

Security Theater Is Costing CISOs More Than They Think

Security theater wastes budgets and creates false confidence. Here's why CISOs must prioritize threats instead of buying more tools.

This article is based on the latest episode of CYBR.Minded with Dr. Dustin Sachs. Check out the full episode:

Busy is the New Stupid with Ross Young
Ross Young joins Dr. Dustin Sachs to explore why cyber budgets, tools, and compliance often fail to reduce meaningful organizational risk at all

For decades, cybersecurity has rewarded visible effort. More tools. More dashboards. More controls. More metrics.

The problem, according to CISO Tradecraft co-host Ross Young, is that visibility is not the same thing as effectiveness. Organizations have become remarkably good at demonstrating security activity while remaining surprisingly poor at explaining whether any of that activity actually reduces business risk.

That disconnect has quietly become one of cybersecurity's biggest leadership challenges.

Looking busy is easy

Security teams don't intentionally build security theater. It happens naturally.

Executives want measurable progress. Boards want dashboards. Auditors want evidence. Regulators expect documentation.

The easiest response is to produce more numbers. Tool coverage increases. Vulnerability counts shrink. Projects close on schedule. Compliance percentages climb.

None of those metrics are inherently bad. The danger comes when organizations mistake them for proof that attackers are less likely to succeed.

A security program can appear mature while still being built around the wrong priorities.

More CYBR.Minded:

Trust Is the Missing Layer in Security with Tammy Moskites
In this episode of CYBR.Minded, Dr. Dustin Sachs sits down with Tammy Moskites, founder and CEO of CyAlliance, to discuss how trust, communication, leadership, and risk translation shape security outcomes.
The Human Factor with Dr. Calvin Nobles
Dr. Dustin Sachs sits down with Dr. Calvin Nobles to explore why security awareness alone is insufficient when it comes to changing human behavior.

Start with what actually hurts

Young argues that organizations should begin somewhere entirely different.

Before discussing products, frameworks, or budgets, leaders need agreement on the handful of threats capable of causing meaningful damage to the business.

Only after those threats are identified should organizations decide which safeguards deserve investment.

Without that discipline, purchasing decisions become reactive. Every new headline produces another security product. Every vendor promises visibility. Every dashboard claims to improve risk.

Eventually, organizations accumulate dozens, sometimes hundreds, of overlapping technologies that generate alerts without generating clarity.

Governance isn't paperwork

Governance often gets treated as an administrative exercise revolving around policies, committees, and board decks. Young sees it differently.

Governance exists to ensure everyone, from engineers to executives, is solving the same problem.

When organizations share a common understanding of material threats, security investments become easier to justify and easier to measure.

Without that shared language, teams naturally optimize for whatever looks good on quarterly reports instead of what actually changes outcomes.

Vanity metrics create false confidence

The conversation turns especially practical when discussing phishing simulations.

Young jokes that if leadership wants a particular phishing failure rate, he'll happily produce it.

His point is simple: Many cybersecurity metrics are surprisingly easy to manipulate. Organizations can make phishing exercises easier or harder. Change who receives them. Adjust reporting windows. Redefine success. The resulting number may satisfy leadership. But it says very little about whether employees will recognize a sophisticated real-world attack.

Useful measurements become dangerous when they're disconnected from business outcomes.

Better questions produce better security

Young believes security leaders should spend less time asking what to buy and more time asking better questions.

  • Which threats matter most?
  • Which safeguards demonstrably reduce those threats?
  • How do we know they're working?
  • What organizational conditions could cause those safeguards to fail?
  • Those questions are harder to answer than comparing product feature lists.

They're also far more likely to improve resilience.

Leadership, not technology, is the differentiator

One of the interview's strongest messages is that cybersecurity's biggest challenges are increasingly human. Organizations don't become secure because they deploy another platform.

They become secure because leadership understands which risks deserve attention, funds defenses that materially change outcomes, and resists the temptation to mistake visible effort for meaningful protection.

Security theater may satisfy a board presentation.

It won't stop the next breach.

HOU.SEC.CON CTA

Latest