In 2009, security consultant and current chief technology officer of IBM Resilient Bruce Schneier wrote about the concept of security theater. “Security theater refers to security measures that make people feel more secure without doing anything to actually improve their security,” he wrote. At the time, there was a lot of fear about information security and a sense of urgency to stem the tide of cybercrime.

Since then, we have learned that fearmongering is counterproductive. Tactics such as creating ID checks and banning liquids and gels from carry-on luggage aren’t really effective. As each measure is put in place to try to protect the public, there are others created to defeat them. Often, these techniques just create more problems.

Setting the Scene

In an earlier article, however, Schneier explained that security theater can be effective under certain circumstances. On a visit to a newborn unit at a local hospital, for example, he noticed that the babies were wearing radio frequency identification (RFID) tags around their ankles. The tags triggered an alarm when a baby passed through the doors, which were equipped with sensors.

Now, the risk to infant abduction from a hospital ward is quite low — about 1 in 375,000 babies, if you average things over the past several decades — and far lower than infant deaths. But that isn’t really relevant. In this case,”RFID bracelets are a low-cost way to ensure that the parents are more relaxed when their baby was out of their sight,” he explained.

The benefits of using RFID technology — in this case, parents’ peace of mind — outweigh the relatively low cost.

Don’t Write Off Security Theater

Yes, the RFID tags are security theater, but they are necessary. “Most of the time security theater is a bad trade-off, because the costs far outweigh the benefits,” Schneier wrote. “But there are instances when a little bit of security theater makes sense.” The potential cost of a lawsuit if a baby is actually abducted, for example, could easily eclipse the cost of the RFID tag program.

The trick is to balance the need for security with its eventual implementation. This holds for IT implementations, too. Sometimes we need to consider both our feelings and the realities of enterprise security.

As Schneier put it, “Security theater is no substitute for security reality, but, used correctly, security theater can be a way of raising our feeling of security so that it more closely matches the reality of security. To write off security theater completely is to ignore the feeling of security.”

More from Risk Management

How TikTok is reframing cybersecurity efforts

4 min read - You might think of TikTok as the place to go to find out new recipes and laugh at silly videos. And as a cybersecurity professional, TikTok’s potential data security issues are also likely to come to mind. However, in recent years, TikTok has worked to promote cybersecurity through its channels and programs. To highlight its efforts, TikTok celebrated Cybersecurity Month by promoting its cybersecurity focus and sharing cybersecurity TikTok creators.Global Bug Bounty program with HackerOneDuring Cybersecurity Month, the social media…

Roundup: The top ransomware stories of 2024

2 min read - The year 2024 saw a marked increase in the competence, aggression and unpredictability of ransomware attackers. Nearly all the key numbers are up — more ransomware gangs, bigger targets and higher payouts. Malicious ransomware groups also focus on critical infrastructure and supply chains, raising the stakes for victims and increasing the motivation to cooperate.Here are the biggest ransomware stories of 2024.Ransomware payments reach record highRansomware payments surged to record highs in 2024. In the first half of the year, victims…

83% of organizations reported insider attacks in 2024

4 min read - According to Cybersecurity Insiders' recent 2024 Insider Threat Report, 83% of organizations reported at least one insider attack in the last year. Even more surprising than this statistic is that organizations that experienced 11-20 insider attacks saw an increase of five times the amount of attacks they did in 2023 — moving from just 4% to 21% in the last 12 months.With insider threats on the rise, it’s critical for businesses to recognize the real dangers that originate from inside…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today