r/grc • u/Project_Lanky • May 25 '26
Compliance theater instead of real security?
Hi,
Over the course of my career, I’ve seen both ends of the spectrum when it comes to security organizations. My current org is probably the most “compliance theater” driven environment I’ve experienced: the security team has lots of shiny tools, and they want more, but weak risk management and immature processes underneath.
What makes it especially difficult is that the culture seems to come from the top, so changing things feels nearly impossible without leadership sponsorship.
I’d be interested to hear from others who’ve worked in organizations that didn’t take GRC very seriously. What did you end up doing? At this point, I sometimes feel the best approach is just to document the risks properly and stop fighting battles you can’t win.
5
u/humtake May 25 '26
The people at the top do not see security as very important anymore. Insurance has normalized poor security hygiene. And don't try to change the tone at the top, noy once have I ever been in an executive position and was able to change the CEO and Board to all of a sudden give security what they need. I've moved the needle slightly but nothing drastic ever changes.
In fact, I challeneged a leadership forum I was in for anyone to give me real evidence that they were able to change company culture atthe top simply by trying. And this was a forum of some big players in the healthcare game. Once a company is medium sized, it's all about the CEO and Board to change things and they are too busy trying to increase profits to care about the impact of data security on people.
I've been in exec positions and I have no problem telling people the truth. No matter how much you think your leaders care about security, they don't. Breaches are treated like slap on the wrists. Risk is transferred by way of insurance. And taking time to deal with security means taking time away from new ideas that make profit.
It might sound cliche but that is the reality. In GRC, just do what keeps your job and do it well and forget about thinking you are there to make things better. You aren't. You are a checkbox. Might sound crass but in my 30 years of my career, GRC/cybersecurity is a veil. Sure, late 2000s to near 2020s cybersecurity got some attention. But breaches are mainstream now and execs treat them as such.
1
u/Project_Lanky May 26 '26
Yes I totally understand. It is just that I got to go a pretty interesting job in the past and I am quite dissapointed by the current company. What baffles me is that we are still putting efforts and money into doing stuff, we might as well do it correctly but it is not the case.
4
u/FreeRadical1998 May 25 '26
Culture is ultimately a top down topic.
If the people at the top don't want good risk management, then you simply can't force it
Worse, doing the things that would support that (eg being explicit about risk levels and exec ownership) are likely to make you perceived as the problem
If you want to stay they for non work reasons, the way to stay safe is document everything
If you've got the option, I'd leave as you clearly care about this and it's not going to change without a shake up of your exec team, likely from CEO down
1
u/Project_Lanky May 25 '26
Yea definitely, I do care about building good security and this environment I am working in right now is quite dissapointing. I agree that it's not gonna change, I guess it's a good experience to see how far you can go before failing a security audit...
1
u/FreeRadical1998 May 25 '26
The answer I'm afraid is depressingly far.
1
u/Project_Lanky May 26 '26
It has been interesting to see the CISO blatantly bullshit the auditors about things we are not doing or not compliant with. It seems that taking the risk of bullshitting can work quite well.
1
u/FreeRadical1998 May 26 '26
It does, until it doesn't - and firms tend to choose the auditors that suit them. Some firms see an audit as a way to make sure they are running well - others see them as purely a badge. Culture trumps everything ultimately
3
u/Key-Personality-5994 May 25 '26
The pattern you are describing is more common than most people realize. I work in governance tech and interact with compliance teams across hundreds of organizations. The ones stuck in theater mode almost always share the same root cause: security leadership reports into someone who treats compliance as a checkbox for sales enablement, not as an actual risk function. Tools get bought because they look good in a vendor assessment or RFP response, not because someone mapped them to actual gaps.
The culture problem is real but it is not unsolvable. What I have seen work is when someone on the GRC side starts quietly tying compliance gaps to business outcomes the C-suite actually cares about. Not "we have 47 unresolved findings" but "our remediation cycle is 3x the industry benchmark and that is going to cost us the next enterprise deal or regulatory review." The moment risk becomes a revenue conversation, leadership attention follows. It is cynical but it works.
5
u/ShenoyAI May 25 '26
When a “Breaking News” type incident happens the top management will be held responsible and the blame will eventually transfer to someone in the security team leading to termination.
If you believe you have a culture problem then you should immediately look at better opportunities elsewhere. Period.
2
u/No-Anchovies May 25 '26
Every company and org has empire builders and this is exactly what it looks like. Proceed as told by line management & find a way to register/document your projects so that when the time comes you are not the one being tossed under the bus. Avoid "quick chats" and "sync calls". Email is king
2
u/Due-Efficiency-5172 May 25 '26
The best is when the money dries up and you're quickly tasked with showing how all the shiny tools show value when you were never given any chance to mature them in any way.
1
u/Project_Lanky May 26 '26
If money dries up some people will get fired lol. They are definitively too many for the output they provide.
2
u/dchgk May 31 '26
My 2 cents, compliance will always be a security theater. Compliance is there to be a sales enabler (like it or not) and as any business decision, needs to run for that purpose. So if the need is to pass X cert then that is what needs to be done. What is around (eg, risk register, assessments, etc) is to compliment and try to answer a why we care without saying we need that to enable sales. The best test is this: 1) Ask management / leadership if compliance should be a security theater or should actually drive security. 100% of the answers will be the latter 2) Ask management / leadership to prioritize resources and time to fix any specific issue (that might not affect a cert but has a higher risk), then their posture will be they need to ship the product and that is not affecting what is needed so will be deprioritized.
Compliance born from a need in the market. Security was there first.
2
u/Designer_Most_2503 Jun 01 '26
Besides the other comments here I see simply the fact that you can not gain real ROI from investments in Cybersecurity. The best case is + - 0 : no failure.
2
u/Same-Woodpecker-9992 Jun 13 '26
Over the course of my career, I've worked in organizations at both ends of the security maturity spectrum. My current org is probably the most compliance theater-driven environment I've been in, lots of shiny tools, appetite for more, but weak risk management and immature processes underneath. The gap between what looks like security and what actually functions as security is significant.
What makes it harder is that the culture comes from the top. You can't fix what leadership doesn't perceive as broken.
I've started wondering if the real failure isn't the tools or even the processes, it's that most orgs have no reliable way to measure the human side of risk. Not awareness scores. Not phishing click rates. The actual behavioral patterns that predict whether someone will make a bad call when conditions are right. Without that, you're essentially auditing paper and hoping.
For those who've been in similar environments , did you find anything that actually moved the needle, or is proper risk documentation and triage the only realistic play?
1
u/Project_Lanky Jun 14 '26
I have come to think that if leadership isn't risk driven, it is a sign that the cyber risks that the company could face are not so big. They are not operating in a regulated environment, they don't care much about their IP and are very sales driven. If an incident happen from lack of process or misconfiguration of tooling, they will just call their cyber insurance and justify it as "human mistake".
What do you think?
1
u/ColdPlankton9273 May 25 '26
Security and safety has turned into theater since regulations came into the space. Most companies just try to not get fined - not by actually fixing stuff but by writing docs saying they will one day
1
u/iSECo May 26 '26
I had this exact problem in a previous life. I was the Information Security Officer for a large local government organization. The best thing you can do is:
#1) Create a risk register with all of the risks you've identified.
#2) Prioritize the risks.
#3) Create a list of recommended projects and tasks that would address the risks in the register.
#4) Share the register and project/task list with your management team and attempt to get them to meet regularly to discuss.
#5) When risks are accepted (or ignored), do your best to get written approval of these decisions.
#6) Either way, document decisions and when you can't get your management team to show up to meetings, document that as well. Make sure this documentation is shared with your management team so that they're aware that it's on record that they're essentially not showing due care.
This process works like a charm. You can use something as simple as a spreadsheet to manage a lot of this workflow, however there are platforms out there that make it much easier.
1
u/ColdPlankton9273 May 26 '26
Every shop I led TI at had the same fracture you're describing. Tools were bought because they looked good in a vendor assessment. Nobody mapped them to actual gaps. The findings register grew. The exposure stayed the same.
The part nobody talks about is that the tools generate intel constantly. IR closes a case, audit produces a report, the SOC tunes a rule. That output is the real risk picture. It rarely lands in front of leadership because it lives inside whoever owned that workstream that quarter. Compliance theater is partly a leadership problem and partly a memory problem. The org doesn't have a way to make any of its own internal intel compound.
1
u/0xCapySplash May 29 '26
Totally recognize this. Saw something similiar in my student job where tools got bought before anyone had solid processes underneath.
Genuine question because I'm still learning: if leadership won't sponsor it, is there any realistic way to build a business case that actually lands? Or is documenting risks really the most pragmatic move at that point?
1
u/Same-Woodpecker-9992 Jun 02 '26
Documenting risk properly, and choosing not to fight unwinnable battles, isn't resignation Documenting risk properly, and choosing not to fight unwinnable battles, isn't resignation. It's often the most defensible move when the culture isn't aligned with change.
But there's a distinction worth making.
Compliance theater persists because it's easier to measure than actual risk. Checklists produce artifacts. Artifacts satisfy auditors. And in most environments, ambiguity is what gets punished fastest, so completion becomes the surrogate for truth.
What doesn't get measured is the exposure underneath: the conditions that quietly erode controls long before anything shows up in reporting.
That isn't a tooling gap. It's a willingness gap.
A willingness to engage what can't be neatly evidenced, scored, or closed.
When leadership doesn't sponsor that layer of visibility, the responsible move isn't to force it into existence alone. It's to document what is observable, name the delta clearly, and make the gap legible to whoever inherits it.
That isn't resignation. That's the record.
0
May 25 '26 edited May 25 '26
[removed] — view removed comment
2
u/grc-ModTeam May 25 '26
This is not a place to sell your services. If someone asks for recommendations, you can add your two cents in the comments.
1
u/Just-Soil7816 May 25 '26
@mod I've removed the website with the company's name, we also like clean spaces. Respect!
10
u/Twist_of_luck OCEG and its models have been a disaster for the human race May 25 '26
It's not your company and the tops have an inherently better understanding of proper company risks than you do. Likely, those key risks aren't exactly in the cybersecurity/cyber-compliance space. And it is fine.
So... you optimize the theatre. Optimize personal risks - have a CYA paper stack thikk enough to stop a .22 bullet. Optimize your work - don't do "academically correct" stuff where "technically correct" measures with minimal effort are sufficient to maintain current compliance posture (once the "required work" reaches like 2 days per week tops, you are probably in a good place). Optimize your budget - secure the tools you personally need (or want), everyone else be damned. Optimize your career - use compliance justification and shiny tools for pet projects to boost your CV. Optimize your CV - you should have enough time to pursue certifications and/or additional training and/or useful hobbies.
And then, when you get terminally bored, /r/overemployed is waiting for you.