How to Break the Security Theater Illusion
When security becomes a performance, the fallout isn't just technical. It's organizational.
.jpg%3fwidth%3d1280%26amp%3bauto%3dwebp%26amp%3bquality%3d80%26amp%3bformat%3djpg%26amp%3bdisable%3dupscale&f=jpg&w=240)
While sitting in a board meeting for a healthcare service provider, veteran CISO John Rouffas was struck by a disconnect he said was impossible to ignore. The security update was familiar: Training metrics were high, patching was on schedule, and vendor relationships were in place. Board members walked away reassured about the provider's security program.
They shouldn't have.
The board heard about the 72% completion rate for the security awareness program but not that employees were failing phishing simulations. The success rates had been stuck at 52% for the past two years. Patch reporting sounded thorough, but, in reality, critical Linux servers were not being patched due to internal friction and vendor misunderstandings.
"I was shocked to see the level of security theater in use to provide the board with a false sense of security," Rouffas later wrote on LinkedIn.
The fact that the security awareness program had a 72% completion rate "sounds like a good number, but it doesn't mean anything," Rouffas noted. "What was reported to the board was a false message that all was fine. Security theater is not just an IT problem. ... It is a governance failure."
About the Author
Staff & Contributors
Dark Reading: Connecting The Information Security Community
Long one of the most widely-read cybersecurity news sites on the Web, Dark Reading is also the most trusted online community for security professionals. Our community members include thought-leading security researchers, CISOs, and technology specialists, along with thousands of other security professionals.
You May Also Like
Preparing for the Autonomous Era in ITOps
Tuesday, December 9, 2025 at 1 PM ESTYour Enterprise Cyber Risk Assessment
Thurs, Nov. 6, 2025 at 1pm ESTIT Automation in 2026: It Isn't ALL About AI (Just Mostly)
Oct 23rd, 2025 from 11am - 5pm ET | A Sponsored Virtual Event | Doors Open at 10:30am ET
October 13-17 Dubai World Trade Centre


