security theater
expressionsecuritygovernance & risk
Bruce Schneier's term for measures that perform protection visibly while providing little of it.
The value of the term is the test it implies: does this control change an attacker's calculus, or an observer's feelings? Some theater is even defensible - visible deterrence has effects - but only if someone, somewhere, knows which category the measure is in.
Security theater is a measure that produces the feeling of security without meaningfully reducing risk, and Schneier coined it about airport screening. The distinguishing feature is that it is visible: the point is to be seen, because reassurance is the actual output.
In technology it is easy to find. A password policy demanding complexity that produces predictable passwords, an annual awareness course nobody remembers, a questionnaire answered by a vendor's sales team, a dashboard nobody reads, an approval step performed by someone with no basis to evaluate what they are approving. Each consumes real effort and each is defended on the grounds that it is better than nothing.
The honest complication is that it is not always worthless. Visible measures deter opportunists, reassurance has genuine value when fear is itself a harm, and a control that is theatre for a sophisticated attacker may be effective against a casual one. The problem is the opportunity cost and the false confidence: effort spent on the visible thing is not spent on the effective one, and an organization that believes it is protected stops asking. The test worth applying is whether anyone can state which specific threat the measure stops.
Also known as: security theatre