Every organisation I have worked with references a security governance framework. I have yet to see one that matches it. ISO 27001, NIST CSF and COBIT get cited in the policy set. What runs is the organisation’s own management system, built for its own context.

That is how it should work. Context differs, what functions in one company fails in the next, and the standards are input to the design rather than the target state. Reading them as the target is where the trouble starts. Certification shows it plainly. Organisations run an ISO 27001 certification alongside their management system rather than certifying the management system itself with the standard as input. The certification becomes a parallel construct with its own documentation, running beside the thing it was meant to certify.

So the gap worth explaining is not the one between framework and practice. That gap is normal, and closing it would usually make things worse. The gap sits between how governance is documented and how decisions actually get made. It shows up in organisations with engaged boards and in organisations without them, across different companies, industries and countries.

Practitioner literature named the pattern years ago. Schneier called it security theatre in 2003, and Sasse returned to it in 2015. Naming a pattern is not the same as explaining why it survives. Frameworks assume that once the pattern becomes visible, organisations correct it. Mostly they don’t.

This is not a criticism of the people doing the work. Organisations produce what their arrangements pay for. That is what makes this worth studying rather than complaining about.

What follows is the current state of the inquiry. These are questions, not conclusions.

Measurement and decision-making

Why does qualitative assessment persist despite its acknowledged limits?

I have sat in governance committees where everyone receives the same report. Medium risk here, high risk there. No way to compare against last year, no way to see what actually changed. Everyone in the room knows it. When someone proposes a quantitative approach, the initiative stalls or meets resistance.

The interesting question is not why qualitative assessment is weak. It is what the weakness does for the organisation, and what quantification would cost that nobody says out loud.

What incentives shape a security leader’s measurement choices?

Objective metrics should improve decisions. Experienced practitioners with the capability to produce them sometimes decline. There is a rational calculation happening that governance frameworks do not describe.

Authority and risk ownership

How do organisations sustain the gap between accountability and authority?

Security leaders are held accountable for outcomes they cannot compel. They identify vulnerabilities without power to mandate patching, recommend controls without authority to enforce them, and own risk without owning the budget to treat it. The pattern holds across organisations, industries and geographies. Consistency at that scale suggests design, not accident.

How does accountability transfer actually happen?

A board defers a technical decision to the CISO: you’re the expert, you decide. Later the same board asks why the matter was never escalated for a board decision. Neither move is unusual on its own. Together they transfer risk without transferring authority.

Compliance investment and security outcomes

What is the relationship between compliance activity and defensive capability?

Organisations investing heavily in certification, audit and framework programmes are not reliably more secure than those investing in technical and operational capability. Sometimes the inverse holds. If that is a real pattern rather than a selection effect, it changes how resources should be allocated.

How do organisations choose between governance-visible and operationally effective?

ISO 27001 certification reads well in board papers and tender responses. Whether it correlates with better outcomes is a separate question. Organisations trade external validation against approaches that work but carry no recognised label, and they rarely make that trade deliberately.

Organisational dynamics

Why do maturity models become permanent deferral mechanisms?

“We are not mature enough for that yet” starts as a sequencing statement. It becomes a stable position. A framework built to guide improvement ends up justifying the indefinite retention of controls the organisation has already judged insufficient.

Why does nothing change when everyone can already see it?

Boards know qualitative assessments give them little. CISOs know they need better measurement. Operations can predict which findings will still be open next year. Nobody is deceived. That is the part that needs explaining.

Practitioner navigation

How does measurement create attribution problems?

A new security leader introduces objective metrics and exposes accumulated debt. Months later they are answering for why everything is red under their leadership. Measuring the problem makes you the owner of it.

What do the practitioners who succeed at this actually know?

Some security leaders move organisations toward better outcomes while keeping board confidence. Others with equal technical competence do not. The difference is not technical, and it is rarely written down.

Risk acceptance

How does implicit risk acceptance work?

Boards acknowledge limitations and note constraints. Nobody signs anything, no formal acceptance process triggers, and no decision gets recorded. The risk has been accepted regardless.

Why is security investment evaluated differently from other investment?

Business cases for security rarely carry quantified estimates comparable to other capital allocation decisions. When quantification is attempted, the method often differs from the enterprise standard. Something makes security special here. Whether it should be is the open question.

How I’m approaching it

The questions come from practitioner experience across manufacturing and government contexts, read against institutional theory, information economics, behavioural economics and organisational design.

If these patterns persist because they serve organisational needs that the frameworks do not acknowledge, the useful work is naming those needs and finding governance approaches that meet them without the theatre.

Where this leads gets published here.


I advise industry and energy companies on security governance and risk management. More about my work.

Connect: LinkedIn | Mastodon | Bluesky