Movatterモバイル変換


[0]ホーム

URL:


How to Break the Security Theater Illusion

When security becomes a performance, the fallout isn't just technical. It's organizational.

Dark Reading, Staff & Contributors

June 18, 2025

1 Min Read
red theater curtain
Brownstock via Alamy Stock

While sitting in a board meeting for a healthcare service provider, veteran CISO John Rouffas was struck by a disconnect he said was impossible to ignore. The security update was familiar: Training metrics were high, patching was on schedule, and vendor relationships were in place. Board members walked away reassured about the provider's security program.

They shouldn't have.

The board heard about the 72% completion rate for the security awareness program but not that employees were failing phishing simulations. The success rates had been stuck at 52% for the past two years. Patch reporting sounded thorough, but, in reality, critical Linux servers were not being patched due to internal friction and vendor misunderstandings.

"I was shocked to see the level of security theater in use to provide the board with a false sense of security," Rouffas later wrote on LinkedIn.

The fact that the security awareness program had a 72% completion rate "sounds like a good number, but it doesn't mean anything," Rouffas noted. "What was reported to the board was a false message that all was fine. Security theater is not just an IT problem. ... It is a governance failure."

Read the Full Article on Dark Reading

About the Author

Dark Reading

Staff & Contributors

Dark Reading: Connecting The Information Security Community

Long one of the most widely-read cybersecurity news sites on the Web, Dark Reading is also the most trusted online community for security professionals. Our community members include thought-leading security researchers, CISOs, and technology specialists, along with thousands of other security professionals.

You May Also Like


Never miss a beat: Get a snapshot of the issues affecting IT leaders straight to your inbox.
Subscribe to our newsletter today.
Webinars
GITEX Global 2025

October 13-17 Dubai World Trade Centre

Prepare for five exhilarating days filled with conferences, live-action workshops, matched concierge networking and business partnerships. Discover the latest and unseen tech innovations that continue to shape our world.

For More Information

[8]ページ先頭

©2009-2025 Movatter.jp