The Dog and Pony Show

Corporate cybersecurity is a theatrical production for auditors, regulators, and insurance underwriters. The hackers are extras on set.

#security#compliance#incentives

Hi frens,

Every quarter, somewhere in a windowless conference room, a CISO clicks through a slide deck with a padlock icon on it. The board nods. Nobody asks what the padlock is locking.

This is the state of corporate cybersecurity: not a war against hackers, but a long running theatrical production for an audience of auditors, regulators, and insurance underwriters. The hackers are almost incidental. They’re merely extras on set dressed in black hoodies.

Consider the evidence: Companies will spend seven figures on a SOC 2 audit and forty five minutes on the incident response plan that audit is supposed to validate. They’ll mandate phishing simulation training and a compliance officer will chase a KPI with the fervor of a dog chasing a bone. A DevOps engineer will then leave the same S3 bucket public for three years because nobody’s KPI covers that. The training exists to generate a training record. The record exists to survive a subpoena. The subpoena, not the breach, is the thing that everyone’s afraid of.

Ask yourself why “compliant” and “secure” have become nearly antonyms in practice. It’s not incompetence: assume malice. Look at the incentives before you assume stupidity. Compliance is legible. A checkbox can be shown to a board, a regulator, a jury. Security is not legible; it’s the absence of an event, which is a hard thing to put in a slide. So companies optimize for the thing that can be measured and displayed, and the thing that can’t gets whatever budget is left over, which is to say: not much.

Security vendors know this too, and they’ve built an entire economy around selling the appearance of defense. Dashboards with more colors than insight. “AI powered” detection tools bought because the RFP asked for them, not because anyone modeled the threat they’re supposed to stop. Pentests are scoped narrowly enough to guarantee a clean report, because a clean report is the deliverable, not the security.

None of this means nobody is trying. There are real engineers, real red teams, real people fighting for budget to fix the thing that’s actually broken instead of the thing that’s easy to photograph for the annual report. But they’re fighting an org chart that rewards the show, not the substance. Org charts, unlike attackers, don’t get bored and move on to easier targets.

The hackers, meanwhile, are not impressed by your slide deck. They do not care about your SOC 2 letter. They’re looking for the gap, and the gap is usually sitting exactly where the audience isn’t looking because that’s where the show never had to shine a light.

-IH