Every business we walk into has at least one security control that exists purely to be pointed at. The password rules everybody works around. The annual training video playing to an empty chair. The USB ports disabled on machines whose users upload everything to a personal cloud drive anyway. None of it was installed in bad faith. It was installed because it felt responsible.

The problem with security theater is not that it wastes money, though it does. The problem is that it consumes the limited patience your staff has for security at all. Every pointless rule spends goodwill you will need later for a rule that matters. So here is a practical audit of the controls we most often find doing nothing, and a two-question test you can apply to anything else you are paying for.

The Two-Question Test

Hold any control up against these two questions.

First: what specific attack does this stop? Not “it improves our security posture.” Name the thing. If you cannot describe, in one sentence, the bad outcome this prevents, you have found theater.

Second: would we notice if it stopped working? A control nobody would miss is a control nobody is checking. We have found expired antivirus licenses, backup jobs failing quietly for months, and a firewall rule set that had drifted so far it allowed more than it blocked. In every case the control looked present on paper and was doing nothing.

Anything that fails both questions should be removed, not improved. Removing it is a gain, because it frees the effort for something real.

Forced Password Rotation on a Schedule

This one has the strongest evidence against it and the strongest grip on habit. Making everyone change their password every ninety days feels rigorous. What it produces is Spring1!, then Spring2!, then Summer1!, in a pattern that is trivially predictable and often written on a sticky note.

NIST states the position directly in its Digital Identity Guidelines FAQ: “Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically).” The reasoning NIST gives is exactly what you would guess from watching your own staff. Users pick weaker passwords when they know an expiration is coming, and they apply predictable transformations when forced to change. Rotation should happen when there is evidence of compromise, which is a real trigger, not a calendar date.

What to do instead: longer passwords, unique per account, kept in a password manager, changed when something happens. The FTC’s small business guidance sets a floor of at least twelve characters and notes that “when it comes to passwords, the longer, the stronger.”

Complex Password Rules and Security Questions

The rule requiring an uppercase letter, a number, and a symbol produces the same handful of passwords across every company in America. NIST addresses this too, saying verifiers “SHOULD NOT impose other composition rules (e.g., requiring mixtures of different character types).” Composition rules push people toward predictable workarounds. A capital at the front and an exclamation point at the end is not complexity, it is a convention, and attackers know the convention.

Security questions belong in the same bin. NIST’s FAQ notes that knowledge-based authentication is no longer acceptable as an authenticator. Your mother’s maiden name and the street you grew up on are findable, and worse, they are frequently the exact path used to talk a help desk into resetting an account.

Replace both with length and multi-factor authentication. If you have not decided which form of MFA to standardize on, we have broken down security keys, passkeys, and app-based codes without the marketing.

The Training Video Nobody Watches

We want to be careful here, because security awareness training is not theater. Bad security awareness training is theater, and the difference is measurable.

Apply the first question. What attack does a forty-five minute annual video stop? If the honest answer is that it satisfies an insurance checkbox, you have your answer. NIST’s Small Business Quick-Start Guide, published in 2024, describes the actual objective: communicate to staff “how to recognize common attacks, report attacks or suspicious activity, and perform basic cyber hygiene tasks.” Recognize and report. Those are behaviors, not completions.

NIST also suggests assessing “the timeliness, quality, and frequency” of your training, which quietly indicts the once-a-year format. Short and frequent beats long and annual. Five minutes a month about something that actually happened to a business like yours will change behavior in a way that a compliance video will not. And the single most important thing to teach is not how to spot a fake email. It is that reporting one costs nothing and nobody gets in trouble for a false alarm.

Blocked USB Ports and the Cloud Drive Nobody Blocked

Disabling USB storage is a real control with a real history. It also solves a problem shaped like the year 2008. If the same laptop can sync a folder to a personal cloud account, sign into a personal webmail, or upload a file to a free file transfer site, you have locked one door in a room with three open windows.

This is not an argument for unblocking USB drives. It is an argument for consistency. Decide what you are actually trying to prevent, then close the paths that matter for that outcome. Unapproved cloud services are where company data quietly leaves most small businesses now, which is the whole subject of shadow IT and the risk hiding inside your own organization.

The Firewall Nobody Reviews, and the Oversized Policy

A firewall installed six years ago and never touched since fails the second question badly. Its rules were written for a network that no longer exists, employees who no longer work there, and applications you no longer run. Nobody would notice if it stopped filtering, because nobody looks. The fix is not a bigger firewall. It is a calendar entry twice a year to read the rules and delete what is obsolete.

The same goes for logging. CISA tells small and medium businesses that “early detection of unusual activity is key to preventing data breaches, ransomware, and other costly incidents,” and recommends deciding what to log, including user activity, admin actions, network traffic, and application logins. Logs you collect and never read are storage, not detection.

Then there is the borrowed policy. Forty pages downloaded from a template site, describing a security committee you do not have, a data classification scheme nobody uses, and quarterly access reviews nobody performs. An auditor may accept it. Your staff will not follow it, because it does not describe your company. Two pages your team can recite beats forty nobody has opened.

The Bottom Line

Security theater persists because removing a control feels like lowering your guard. It usually is not. Retiring a rule that produces predictable passwords, a video that teaches nothing, or a policy nobody reads returns time and credibility to your organization. Spend both on the short list that consistently pays:

  • Multi-factor authentication everywhere it is offered. The highest-return control available to a business your size.
  • Backups you have actually restored from. Watching a job report success is not the same as proving you can get your data back.
  • Current patching, including the gear nobody thinks about. Routers, firewalls, and printers count.
  • A short list of people holding administrative rights. Fewer keys, fewer ways in.

Run the two questions across everything you are doing. What attack does this stop, and would we notice if it failed? Most of what survives is worth keeping. Most of what does not was costing you more than you realized.

We are happy to walk your controls with you and say plainly which ones earn their place. For a second opinion on what your business can stop doing, not just what it should buy, Contact us today.


Sources:

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).