{"id":4422,"date":"2024-07-11T14:08:55","date_gmt":"2024-07-11T19:08:55","guid":{"rendered":"https:\/\/www.darkreading.com\/cyber-risk\/trade-the-comfort-of-security-theater-for-true-security"},"modified":"2024-07-11T14:08:55","modified_gmt":"2024-07-11T19:08:55","slug":"trade-the-comfort-of-security-theater-for-true-security","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/07\/11\/trade-the-comfort-of-security-theater-for-true-security\/","title":{"rendered":"Trade the Comfort of Security Theater for True Security"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt2a98f57f6f30574e\/668eef8e180fc319c27aa307\/stagemakeup-Andrii_Lysenko-alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/trade-the-comfort-of-security-theater-for-true-security.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/trade-the-comfort-of-security-theater-for-true-security.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">COMMENTARY<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">With all the recent cyberattacks, data breaches, lawsuits, enforcement actions, and regulatory investigations, I am often surprised by the number of companies I see engaging in security practices that are more focused on a compelling marketing campaign than on mitigating business, financial, and legal risks. This is &#8220;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/boarding-pass-brouhaha\" rel=\"noopener\">security theater<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">,&#8221; a program that gives the illusion of security without meaningful defensive substance. It is meticulously crafted for C-suite executives and leaders who demand a feel-good performance at bargain-basement production costs, often led by a cast of actors more concerned with the audience than the substance.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Beware, though! Companies and the individuals working for them are being sued, fined, and issued consent decrees on cybersecurity and data protection practices despite their good security theater. Corporate lawsuits, regulatory investigations, and Senate demands for CEO accountability can and should drive actions to create robust security programs. Whether you are a CEO, CISO, general counsel, or just the highest-level security, risk, compliance, or legal resource within your organization (regardless of title), you should learn how to tell when there is an effective security program and when you are merely witnessing a performance of <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/time-to-close-curtain-on-security-theater\" rel=\"noopener\">security theater<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Security Theater Is Only a Paper Moon\">Security Theater Is Only a Paper Moon<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The cast of security theater includes standards-setting bodies, third-party certifiers, and security vendors, all being directed by security personnel for the benefit of the audience. Some of the actors are double-cast in multiple roles. Standards-setting bodies may be played by security professionals at big tech companies or security vendors, influencing the standards to reflect the work they already do. Certification bodies, the guardians of compliance, occasionally double as security vendors, offering consulting services designed to help companies meet the standards they will certify.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Now, this does not mean conflicting interests should prevent all parties from providing related services. In many instances, holding multiple roles allows for knowledge sharing between well-funded incumbents and newer entities. However, sometimes charlatans peddle a quick fix of checklists-style compliance documentation wrapped in the illusion of security because they can all-but-guarantee that a certification will be granted.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Unfortunately, behind the dazzling facade lies the chaotic backstage reality. While security theater provides a sense of reassurance, it often falls short in terms of tangible risk mitigation and legal compliance. The audience leaves patting each other&#8217;s backs because their employees are regularly getting phishing tests (and retraining when they inevitably click). They breathe a sigh of relief knowing they have a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/palo-alto-network-issues-hot-fixes-for-zero-day-bug-in-its-firewall-os\" rel=\"noopener\">network firewall<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in place and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/hacker-pwns-uber-via-compromised-slack-account\" rel=\"noopener\">VPN for remote employees<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. A few might even exit with the smug sense of self-satisfaction because they have an <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/compliance-certifications-worth-the-effort-\" rel=\"noopener\">ISO 27001 certification<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> that some of their competitors lack.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Truly effective security, unlike its theatrical counterpart, is not a source of comfort but a constant reminder of vulnerability. It recognizes that common practices \u2014 even best practices \u2014 do not always work. True security knows that data breaches happen to ISO certified companies. True security knows both that people are its weakest link and that being human is not a moral failing. Truly effective security plans for compromise by incorporating layered defenses and response plans for compromise rather than trying to train around it, ready to simply blame or punish individuals for merely being human. True security is a state of constantly evolving engineering and vigilance that is built with our <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/why-layer-8-is-great\" rel=\"noopener\">human nature<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in mind: People may be fallible, but they are a feature, not a bug.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Stakes of Missing True Security Are High and Growing\">Stakes of Missing True Security Are High and Growing<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Perhaps you are in the audience of Security Theater, thinking that True Security would be great, but is too expensive. Look out, though: Existing and new laws are demanding True Security as table stakes for digital businesses. For example, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.edps.europa.eu\/data-protection\/our-work\/publications\/investigations\/2024-03-08-edps-investigation-european-commissions-use-microsoft-365_en\" rel=\"noopener\">EU regulators recently issued an opinion<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> that compliance with a standard on data anonymization did not mean that it was <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/data-privacy\/companies-anonymized-data-may-violate-gdpr-privacy-regs\" rel=\"noopener\">sufficient anonymization<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> under the law. And fines are piling up: A variety of new laws coming into effect in Europe engender fines of 2%-7% of an enterprise&#8217;s global annual revenue for violations of each law. This means that a single incident leading to a data breach may trigger multiple instances of revenue-based fines \u2014 and that&#8217;s just in Europe. When you consider other jurisdictions that are following Brussels&#8217; lead, this adds up fast.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The US is also focusing on these issues, albeit in a different matter. The Securities and Exchange Commission, Federal Trade Commission, Department of Justice, and state-level attorneys general have investigated companies and filed civil and criminal claims against companies and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/sec-charges-against-solarwinds-ciso-send-shockwaves-through-security-ranks\" rel=\"noopener\">individual leaders<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, alleging wrongdoing. Senator Ron Wyden (D-Wash.) wrote to the FTC and SEC suggesting that <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/the-ceo-is-next\" rel=\"noopener\">CEOs should be held personally accountable<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> for ineffective cybersecurity programs.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It is time to wake up to the security, economic, and legal risks associated with Security Theater. Its toughest critics \u2014 global lawmakers \u2014 are paying a lot more attention to this show. It is time to stop focusing on making the audience comfortable and start making them feel the discomfort that comes with risk, change, and, eventually, growth.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This will be particularly difficult in organizations that have long valued comfort more than growth \u2014 leadership will not know they are watching Security Theater when they have cultivated a culture of being entertained at the expense of being educated. Boards and C-suites must therefore eschew the role of spectator and instead become the most effective critic in the audience of Security Theater.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Growth does not need to be at record-breaking speed, nor does it have to be tied to a certain end state. There are many ways to do security and compliance in a manner that is both risk-based and appropriate for the business. But it takes work. Growth always takes work.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A competent, experienced cybersecurity leader with curiosity and a growth mindset can help build an amazingly effective security program \u2014 when they are listened to. Listening to these folks can cause uncomfortable feelings of inadequacy and overwhelm. So, it is time to get comfortable with being uncomfortable. Kill the culture of comfort and demand to hear things that are not easy to hear. Growth is what will truly provide the customers in the audience with lasting satisfaction and happiness, and it will ensure that the protection of our digital world evolves with the technology that has created it.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyber-risk\/trade-the-comfort-of-security-theater-for-true-security\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>COMMENTARY With all the recent cyberattacks, data breaches, lawsuits, enforcement<\/p>\n","protected":false},"author":12,"featured_media":4423,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4422","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/trade-the-comfort-of-security-theater-for-true-security.jpg?fit=1800%2C1013&ssl=1",1800,1013,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/trade-the-comfort-of-security-theater-for-true-security.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/trade-the-comfort-of-security-theater-for-true-security.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/trade-the-comfort-of-security-theater-for-true-security.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/trade-the-comfort-of-security-theater-for-true-security.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/trade-the-comfort-of-security-theater-for-true-security.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/trade-the-comfort-of-security-theater-for-true-security.jpg?fit=1800%2C1013&ssl=1",1800,1013,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/trade-the-comfort-of-security-theater-for-true-security.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/trade-the-comfort-of-security-theater-for-true-security.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/trade-the-comfort-of-security-theater-for-true-security.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/trade-the-comfort-of-security-theater-for-true-security.jpg?fit=1800%2C1013&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4422","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4422"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4422\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4423"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4422"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4422"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4422"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}