Security Theater


Security theater is the practice of performing security processes or maintaining security solutions that make people feel more secure without actually improving security. In cybersecurity, security theater may be the result of maintaining old, outdated tools and processes that were effective for the threat environment when it was first conceived.

These efforts have proven to be ineffective or have become less useful over time, and now do not provide enough visibility into the risks the organization faces. Many organizations continue to do what they have done in the past even as these activities provide insufficient visibility to overall risks.

