In 2009, security consultant and current chief technology officer of IBM Resilient Bruce Schneier wrote about the concept of security theater. “Security theater refers to security measures that make people feel more secure without doing anything to actually improve their security,” he wrote. At the time, there was a lot of fear about information security and a sense of urgency to stem the tide of cybercrime.

Since then, we have learned that fearmongering is counterproductive. Tactics such as creating ID checks and banning liquids and gels from carry-on luggage aren’t really effective. As each measure is put in place to try to protect the public, there are others created to defeat them. Often, these techniques just create more problems.

Setting the Scene

In an earlier article, however, Schneier explained that security theater can be effective under certain circumstances. On a visit to a newborn unit at a local hospital, for example, he noticed that the babies were wearing radio frequency identification (RFID) tags around their ankles. The tags triggered an alarm when a baby passed through the doors, which were equipped with sensors.

Now, the risk to infant abduction from a hospital ward is quite low — about 1 in 375,000 babies, if you average things over the past several decades — and far lower than infant deaths. But that isn’t really relevant. In this case,”RFID bracelets are a low-cost way to ensure that the parents are more relaxed when their baby was out of their sight,” he explained.

The benefits of using RFID technology — in this case, parents’ peace of mind — outweigh the relatively low cost.

Don’t Write Off Security Theater

Yes, the RFID tags are security theater, but they are necessary. “Most of the time security theater is a bad trade-off, because the costs far outweigh the benefits,” Schneier wrote. “But there are instances when a little bit of security theater makes sense.” The potential cost of a lawsuit if a baby is actually abducted, for example, could easily eclipse the cost of the RFID tag program.

The trick is to balance the need for security with its eventual implementation. This holds for IT implementations, too. Sometimes we need to consider both our feelings and the realities of enterprise security.

As Schneier put it, “Security theater is no substitute for security reality, but, used correctly, security theater can be a way of raising our feeling of security so that it more closely matches the reality of security. To write off security theater completely is to ignore the feeling of security.”

More from Risk Management

Researchers develop malicious AI ‘worm’ targeting generative AI systems

2 min read - Researchers have created a new, never-seen-before kind of malware they call the "Morris II" worm, which uses popular AI services to spread itself, infect new systems and steal data. The name references the original Morris computer worm that wreaked havoc on the internet in 1988.The worm demonstrates the potential dangers of AI security threats and creates a new urgency around securing AI models.New worm utilizes adversarial self-replicating promptThe researchers from Cornell Tech, the Israel Institute of Technology and Intuit, used what’s…

What should Security Operations teams take away from the IBM X-Force 2024 Threat Intelligence Index?

3 min read - The IBM X-Force 2024 Threat Intelligence Index has been released. The headlines are in and among them are the fact that a global identity crisis is emerging. X-Force noted a 71% increase year-to-year in attacks using valid credentials.In this blog post, I’ll explore three cybersecurity recommendations from the Threat Intelligence Index, and define a checklist your Security Operations Center (SOC) should consider as you help your organization manage identity risk.The report identified six action items:Remove identity silosReduce the risk of…

Obtaining security clearance: Hurdles and requirements

3 min read - As security moves closer to the top of the operational priority list for private and public organizations, needing to obtain a security clearance for jobs is more commonplace. Security clearance is a prerequisite for a wide range of roles, especially those related to national security and defense.Obtaining that clearance, however, is far from simple. The process often involves scrutinizing one’s background, financial history and even personal character. Let’s briefly explore some of the hurdles, expectations and requirements of obtaining a…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today