DEV Community

Cover image for Security Theatre
Cristiano Gabrieli
Cristiano Gabrieli

Posted on

Security Theatre

Introduction
They call it “security,” but it isn’t.
It’s a performance staged for executives who want reassurance, not protection.
A ritual of dashboards, certifications, and policy documents designed to imitate maturity while the infrastructure underneath is held together with tape, hope, and denial.
Security theatre is the art of pretending that risk can be controlled with paperwork.
It’s the belief that a checklist can stop an adversary who doesn’t care about checklists.
It’s the fantasy that a junior salary can buy senior expertise, that one person can replace an entire team, that complexity can be managed by people who don’t understand it.
In this industry, the surgeon is paid like a janitor and expected to perform both jobs.
The expert is downgraded, overloaded, and blamed for failures engineered by management decisions made years before they arrived.
Responsibility is infinite. Authority is zero.
Security theatre is not an accident.
It’s a system built to look safe, not to be safe.
A façade maintained because the truth — the real state of most environments — is too expensive, too inconvenient, and too politically dangerous to acknowledge.
This article is not for the actors.
It’s for the engineers who see the cracks, who know the lies, who understand that real security begins where the theatre ends.

  1. The Surgeon and the Janitor — The Industry’s Favourite Fantasy

The comparison is brutal because it’s true.
Imagine a surgeon — years of training, precision, responsibility, life‑and‑death decisions — suddenly reassigned to clean hospital bathrooms. Same building, same badge, same expectations, but stripped of authority, tools, and respect. And then management tells him he must still perform surgery when needed, but with janitor pay, janitor resources, and janitor status.
This is cybersecurity today.
Companies want experts but treat them like general labor.
They want a specialist who understands adversaries, architecture, cloud, identity, risk, compliance, and incident response — but they offer a salary that barely matches entry‑level IT support. They want a surgeon, but they hire a cleaner. They want senior responsibility, but they pay junior wages. They want miracles, but they provide mops.
And when something breaks, they blame the surgeon for not cleaning fast enough.
This is not an exaggeration.
It’s the operational reality inside many organizations: cybersecurity roles collapsed into a single overloaded position, stripped of authority, buried under compliance paperwork, and expected to carry the weight of an entire security department alone.
The surgeon analogy fits because cybersecurity is treated the same way:
a critical discipline downgraded to a maintenance task, performed under the illusion that “anyone in IT can do it.”
The industry pretends complexity doesn’t exist, risk doesn’t accumulate, and expertise doesn’t matter — until the breach arrives and the theatre collapses.
Security theatre begins exactly here:
with experts forced into janitor roles while still expected to perform surgery.

  1. Tearing Down the Theatre — The Illusion Was Never Real

Security theatre doesn’t collapse.
It disintegrates the moment you stop pretending it exists.
The industry builds elaborate stages:
policies nobody reads, controls nobody enforces, dashboards nobody understands, and certifications nobody respects.
They call it “governance.”
They call it “maturity.”
They call it “best practice.”
But underneath the stage lights, the truth is embarrassingly simple:
none of it stops an adversary who actually wants in.
The theatre survives only because everyone agrees to play their part.
Executives pretend the controls work.
Managers pretend the reports are accurate.
Auditors pretend the evidence is real.
Engineers pretend the architecture is stable.
Analysts pretend the alerts matter.
Compliance teams pretend the paperwork reflects reality.
Everyone performs.
Nobody protects.
The surgeon analogy returns here with full force.
The surgeon is told the hospital is “state‑of‑the‑art,” but the equipment is broken, the staff is missing, and the operating room is a repurposed storage closet.
Management insists everything is fine because the brochure says so.
The surgeon knows the truth, but the theatre demands silence.
Cybersecurity works the same way.
Experts see the cracks — the misconfigurations, the blind spots, the unpatched systems, the fake controls, the political decisions disguised as technical ones — but the theatre demands applause, not honesty.
Tearing down the theatre means saying what nobody wants to hear:
the controls don’t work, the maturity is fake, the compliance is decorative, and the risk is far higher than the reports claim.
The industry doesn’t fear breaches.
It fears embarrassment.
It fears admitting that the theatre was never real.
This is why tearing it down feels violent.
Because truth always is.

  1. The Funeral — Autopsy of a Theatre That Never Lived

The theatre didn’t die.
It was never alive.
So we treat it like any failed patient:
a surgeon standing over a body that was declared “healthy” by people who never understood anatomy.
The autopsy begins not with grief, but with recognition — the recognition that the cause of death was negligence disguised as expertise.
The surgeon opens the chest cavity and finds what everyone suspected:
controls that never worked, policies that were never enforced, systems that were never patched, and a heartbeat that was simulated for the sake of quarterly reports.
The organs of “governance” and “compliance” are intact only on paper.
In reality, they are hollow, brittle, and long since disconnected from anything that resembles real security.
Around the table stand the actors of the theatre — the ones who applauded the performance while the patient deteriorated.
They wear badges, titles, and confidence, but none of it survives the autopsy.
Their competence dissolves under the surgical light, revealing the truth:
they were never practitioners, only performers.
The surgeon documents the findings with clinical detachment:
· cause of death: unmanaged risk
· contributing factors: political decisions disguised as technical strategy
· secondary complications: role collapse, underfunding, denial
· time of death: the moment reality exceeded the script
No anger.
No insults.
Just anatomy.
The funeral is quiet because there is nothing to mourn.
Security theatre was a façade, a cardboard set built to reassure people who preferred illusion over engineering.
Its death is not a tragedy — it is a diagnosis.
The surgeon closes the report and steps away.
The theatre is gone, and what remains is the truth:
real security begins only after the autopsy.

  1. Post‑Mortem Forensic Evidence — Catalogue of the Theatre’s Dead

The autopsy is complete, but the surgeon is not finished.
Now comes the forensic cataloguing — the slow, clinical documentation of every failure that contributed to the death of the theatre.
The room is quiet.
The bodies are symbolic.
But the evidence is real.
The first body on the table is labelled “Recruitment.” Cause of death: chronic misdiagnosis. The recruiters insisted the patient was “junior,” even as the symptoms showed advanced complexity. They prescribed entry‑level salaries for senior‑level pathology, convinced that expertise could be bought at discount. The surgeon notes the irony: the theatre collapsed partly because the gatekeepers could not tell the difference between a surgeon and a cleaner.
Next is “Management.” Cause of death: untreated denial. The managers believed the theatre was healthy because the reports said so. They ignored the lesions of unmanaged risk, the fractures of misconfiguration, the hemorraging of technical debt. They insisted the patient was stable while the vital signs were screaming. The surgeon records the truth: management died from believing its own script.
The third body is “Stakeholders.” Cause of death: prolonged exposure to optimism. They demanded green dashboards, compliant checkboxes, and reassuring narratives. They mistook comfort for control, and metrics for protection. Their organs show no signs of ever encountering reality. The surgeon marks the file: stakeholders died from a fatal addiction to good news.
The fourth body is “The C‑Suite.” Cause of death: executive distance. The autopsy reveals a heart that never touched the system it claimed to protect. Decisions were made far from the operating room, guided by budget charts instead of anatomy. The surgeon notes the final detail: the C‑Suite died from believing cybersecurity was a cost center instead of a life‑support system.
The final body is “Te
chnical Leadership.” Cause of death: role collapse. The spine shows signs of carrying too much weight — architecture, operations, compliance, incident response, cloud, identity, risk, all compressed into one overloaded vertebra. The surgeon recognizes the pattern: the theatre demanded superhuman performance from human staff. The body broke exactly where expected.
The forensic report is complete.
Every failure is documented.
Every contributor is accounted for.
The surgeon closes the file with clinical detachment.
The evidence is clear:
the theatre did not die from a single mistake.
It died from a system that preferred performance over protection, illusion over engineering, and comfort over truth.
The ticking bomb was never outside the theatre.
It was inside the cast.

  1. Post‑Mortem Rebuild — Blueprint for a Real Security Discipline

The surgeon closes the autopsy report.
The theatre is gone, the bodies are documented, and the evidence is undeniable.
Now begins the reconstruction — the part nobody in the theatre ever attempted.
This is not a revival.
It is a rebuild from the ground up.
The surgeon lays out the blueprint with the same precision used in the autopsy:
no illusions, no theatre, no actors — only anatomy, engineering, and truth.
I. Salaries — Pay for the Organ You Want to Save
Cybersecurity cannot be rebuilt on janitor wages.
If you want a surgeon, you pay a surgeon.
If you want expertise, you compensate expertise.
If you want responsibility, you match it with authority.
The blueprint is simple:
· Entry level: operational support, limited scope, supervised tasks
· Intermediate: independent analysis, architecture awareness, incident participation
· Senior: system ownership, architectural decision‑making, risk authority
· Principal: cross‑domain leadership, strategic influence, organizational impact
Anything less is malpractice.
II. Responsibilities — One Role, One Function
The autopsy showed the fatal flaw: role collapse.
The rebuild eliminates it.
A real security program separates:
· Identity engineering
· Cloud security architecture
· Incident response
· Threat detection
· Governance & compliance
· Risk management
· DevSecOps pipeline security
· Vulnerability management
· Forensics & investigation
One person cannot be all organs at once.
The body dies when everything depends on a single heart.
III. Achievements — Measured by Reality, Not Dashboards
The theatre rewarded green dashboards.
The rebuild rewards outcomes.
Real achievements look like:
· reduced blast radius
· hardened identity boundaries
· measurable risk reduction
· incident containment time improvements
· architecture simplification
· elimination of legacy vulnerabilities
· removal of systemic single points of failure
No applause.
Just anatomy.
IV. Promotion — Based on Competence, Not Performance
The theatre promoted actors.
The rebuild promotes practitioners.
Promotion criteria:
· demonstrated technical depth
· proven architectural thinking
· successful incident leadership
· ability to mentor and elevate others
· capacity to translate risk into engineering
· ownership of systems, not slides
The surgeon notes:
competence is the only organ that regenerates.
V. Empowerment — Authority Must Match Responsibility
The autopsy revealed the fatal mismatch:
infinite responsibility, zero authority.
The rebuild corrects it:
· engineers must be able to block deployments
· security must have veto power on architecture
· incident responders must override politics
· risk teams must define acceptable exposure
· cloud security must dictate identity boundaries
· DevSecOps must enforce pipeline controls
If you ask someone to save the patient, you give them access to the operating room.
VI. Asset Ownership — Every System Has a Surgeon
The theatre had no owners.
Everything was “shared,” which meant nothing was protected.
The rebuild assigns:
· system owner
· security owner
· risk owner
· operational owner
· architectural owner
Every organ has a responsible surgeon.
No more anonymous failures.
VII. Evaluation — Based on Anatomy, Not Illusion
The theatre evaluated people by:
· dashboards
· compliance checkboxes
· performance reviews
· political alignment
The rebuild evaluates by:
· system stability
· incident outcomes
· architectural clarity
· risk reduction
· technical mastery
· contribution to resilience
The surgeon writes the final line:
evaluation must reflect the body, not the brochure.
VIII. The Individual — Empowered, Respected, and Paid for Reality
The autopsy proved the theatre killed its own experts.
The rebuild protects them.
The individual receives:
· authority equal to responsibility
· compensation equal to expertise
· recognition equal to impact
· autonomy equal to trust
· career paths equal to ambition
Cybersecurity is not a performance.
It is a discipline.
And disciplines are built on empowered practitioners, not actors.

  1. The Abyss — Post‑Mortem of a Grid Collapse
    The surgeon steps into a different room now — not the morgue, but the incident war room.
    The screens are dark.
    The logs are frozen.
    The grid is down.
    This is where the theatre finally met reality.
    A criminal adversary — not a genius, not a nation‑state, just a determined attacker — walked through the network like it was an abandoned building.
    Not because the attacker was extraordinary, but because the defenses were imaginary.
    The autopsy begins.
    I. Initial Breach — The Door That Was Never Locked
    The attacker didn’t “break in.”
    They walked in.
    A forgotten identity account.
    A stale credential.
    A misconfigured cloud role.
    A legacy VPN endpoint left running “just in case.”
    The theatre had declared all of these “low risk.” The surgeon marks the first finding: the breach occurred through a control the theatre insisted was safe.
    II. Lateral Movement — The Hallways With No Doors
    Once inside, the attacker moved freely.
    No segmentation.
    No identity boundaries.
    No privilege separation.
    No monitoring that actually detected movement.
    The theatre had diagrams showing “zero trust.”
    The surgeon finds no evidence of it in the body.
    The attacker pivoted from:
    · corporate network
    · to OT network
    · to SCADA systems
    · to grid controllers
    · to substations
    · to load‑balancing nodes
    Not because they were skilled —
    but because the architecture was flat.
    The surgeon writes: the attacker moved laterally because there was nowhere to stop them.
    III. Control Manipulation — The Hands That Should Never Touch the Heart
    The attacker reached the grid control plane.
    Not through brilliance, but through absence — absence of boundaries, absence of monitoring, absence of engineering.
    They manipulated:
    · frequency regulation
    · load distribution
    · substation switching
    · cooling system telemetry
    · grid balancing algorithms
    The theatre had dashboards showing “all green.”
    The surgeon finds the sensors were reporting stale data.
    The attacker didn’t bypass controls.
    The controls simply weren’t connected.
    IV. Collapse — The Moment the Theatre Went Silent
    The grid failed.
    Lights went out.
    Systems shut down.
    Backup generators kicked in late.
    Hospitals switched to emergency mode.
    Traffic systems froze.
    Industrial plants halted.
    The theatre had promised resilience.
    The surgeon finds no redundancy in the architecture.
    The collapse wasn’t caused by the attacker.
    It was caused by the theatre.
    V. The Charlatans — Revealed by the Autopsy, Not by Insults
    The surgeon documents the “contributors” to the collapse — not as accusations, but as forensic evidence.
    Each item begins with a Guided Link.
    · Recruiters — hired performers instead of practitioners
    · Managers — ignored warnings, trusted dashboards
    · Stakeholders — demanded green metrics instead of real protection
    · C‑Suite — treated cybersecurity as a cost, not infrastructure
    · Compliance teams — certified systems that were already failing
    · Technical leadership — overloaded, unsupported, denied authority
    No insults.
    No names.
    Just anatomy.
    The charlatans were not malicious.
    They were simply part of the theatre — actors performing roles they never understood.
    The attacker didn’t defeat them.
    Reality did.
    VI. The Surgeon's Final Note — The Abyss Was Always There
    The surgeon closes the incident report.
    The grid didn’t fall because of a criminal adversary.
    It fell because the theatre insisted the abyss didn’t exist.
    The deep dive reveals the truth: the attacker exploited weaknesses created by the theatre, not by the engineers.
    The abyss wasn’t outside the system.
    It was inside the culture.

  2. The Engineers’ Manifesto — End of the Theatre

The theatre is dead.
The autopsy is complete.
The bodies are catalogued.
The grid collapse has been dissected.
The evidence is undeniable.
Now the surgeon steps away from the corpse and turns to the only people who ever understood the anatomy of the system: the engineers.
This is their manifesto — not a speech, not a plea, not a performance.
A declaration.
A reconstruction.
A line in the sand.
I. We Reject the Theatre
Each item begins with a Guided Link.
· Fake dashboards — we reject metrics that lie
· Compliance illusions — we reject paperwork that replaces protection
· Role collapse — we reject being the entire department alone
· Budget theatre — we reject security treated as a cost
· Green‑washing of risk — we reject comfort disguised as control
The theatre demanded silence.
We refuse.
II. We Demand Authority Equal to Responsibility
The autopsy proved the fatal mismatch:
infinite responsibility, zero authority.
The manifesto corrects it:
· if we own the system, we own the decisions
· if we carry the risk, we define the boundaries
· if we respond to incidents, we dictate the architecture
· if we protect the grid, we control the identity plane
· if we are accountable, we are empowered
The surgeon writes: no more saving patients without access to the operating room.
III. We Define Security as Engineering, Not Performance
Security is not:
· a dashboard
· a certification
· a compliance checkbox
· a quarterly report
· a marketing slogan
Security is:
· architecture
· identity
· boundaries
· telemetry
· resilience
· incident response
· risk reduction
· engineering
The theatre pretended otherwise.
The manifesto ends the lie.
IV. We Expose the Charlatans Through Evidence, Not Insults
The autopsy already revealed them:
· recruiters who misdiagnosed roles
· managers who ignored warnings
· stakeholders addicted to optimism
· executives who treated security as decoration
· compliance teams who certified failure
· technical leaders overloaded into collapse
We do not insult them.
We simply show the evidence.
The manifesto states: competence is not optional in critical infrastructure.
V. We Rebuild the Discipline From the Abyss Up
The grid collapse taught the lesson:
the attacker exploited weaknesses created by the theatre, not by the engineers.
The rebuild begins with:
· segmentation
· identity boundaries
· telemetry that reflects reality
· architecture that resists failure
· systems with owners
· pipelines with controls
· risk with teeth
· salaries that match expertise
· authority that matches responsibility
The surgeon writes: the abyss is not a threat — it is a blueprint.
VI. We Declare the End of the Theatre

The manifesto ends with a single line, written with surgical precision:
Security begins where the theatre ends.
No applause.
No performance.
No actors.
Only engineers, anatomy, and truth.

Conclusion — Mission Accomplished

The theatre is gone.
The autopsy is complete.
The bodies are catalogued.
The manifesto is written.
The engineers have spoken.
There is nothing left to dismantle.
Nothing left to expose.
Nothing left to pretend.
Security theatre died exactly the way it lived —
quietly, decoratively, and under the weight of its own illusions.
It collapsed not because of an adversary, but because of the culture that insisted fantasy was safer than truth.
The surgeon closes the final report with clinical detachment.
The engineers step forward.
The abyss is mapped.
The rebuild begins.
Mission accomplished.
Not because the theatre was destroyed,
but because the truth was finally louder than the performance.

“We end the theatre so reality can breathe again.”

Top comments (0)