Zero Security Theatre

Patterns and anti-patterns

Patterns are practices that help when tested. Anti-patterns are common, usually well-intentioned practices that create paperwork without improving the result.

Patterns

  • Score unknown as red

    Remove the not assessed category. A control whose effect has not been demonstrated is reported as failing until it is tested, which makes the verification backlog visible to the people who fund it.

    Under The dangers of security theatre, Attack-and-recovery engineering

  • Store the query, not the screenshot

    Keep the source, collection time, and query with the result so a reader can reproduce it. The same record is ready when an audit begins.

    Under Compliant Insecurity, GRC engineering

  • Machine prepares, human decides

    Automate correlation, reconstruction, testing, and evidence assembly. Keep isolation, disclosure, notification, and risk acceptance with named people, and let authority move only as measured performance supports it.

    Under AI-native defensive security

Anti-patterns

  • Writing a narrative where no data source exists

    Requirements with no operational evidence source produce prose, and prose always passes. The absence never appears as a failure in any report.

    Under Compliant Insecurity, GRC engineering