AR7 All articles
Enterprise Technology

Security Theater in the SOC: When Incident Drills Rehearse Compliance Rather Than Resilience

AR7
Security Theater in the SOC: When Incident Drills Rehearse Compliance Rather Than Resilience

Photo: U.S. Army USAG-RP by Linda Lambiotte, Public domain, via Wikimedia Commons

There is a particular kind of confidence that security leaders should be most wary of: the confidence that follows a successful tabletop exercise. The scenario was realistic, the stakeholders participated, the runbooks were consulted, and the debrief identified three action items that were dutifully entered into a project tracker. The compliance checkbox is satisfied. The actual threat surface, in most cases, is unchanged.

This is the operational definition of security theater—not the absence of security activity, but the presence of security activity that is optimized for appearance rather than outcome. It is more prevalent than the industry acknowledges, and its consequences are measurable in breach frequency, dwell time, and incident recovery cost.

The Compliance Driver and Its Distortions

To understand why incident response programs drift toward theater, it is necessary to understand the incentive structures that shape them. For most US enterprises subject to frameworks such as SOC 2, HIPAA, PCI-DSS, or NIST 800-53, incident response capability is a documented audit requirement. Auditors need evidence. Evidence, in this context, typically means documentation: a written incident response plan, records of at least one annual tabletop exercise, and a post-incident review process.

These requirements are not unreasonable in principle. The problem emerges in execution. When the primary driver of an incident response program is audit readiness rather than operational effectiveness, the program's design optimizes for the production of documentation rather than the development of capability. Scenarios are selected because they are easy to facilitate and simple to document, not because they reflect the threat vectors most likely to affect the organization. Participants are chosen for their availability and seniority rather than their operational role during an actual incident. Outcomes are measured by completion rather than by the quality of decision-making under pressure.

The result is a program that passes audits reliably and prepares teams inadequately.

The Anatomy of a Theater Exercise

Several structural characteristics distinguish a compliance-oriented exercise from one designed to build genuine resilience. Recognizing them is the first step toward remediation.

Predetermined outcomes. In theater exercises, the scenario is constructed so that the correct responses are apparent and the team reaches a successful resolution within the allotted time. Real incidents are characterized by ambiguity, incomplete information, and decision points where no option is clearly correct. An exercise that does not introduce these conditions is not training for the actual experience.

Absent operational stakeholders. Tabletops frequently populate the room with CISOs, VPs of Engineering, and General Counsel—the stakeholders most relevant to a post-incident board briefing, and least relevant to the first four hours of an active breach. The engineers who will actually execute containment procedures, the on-call SREs who will be paged at 2:00 a.m., and the IT administrators who manage identity and access systems are often not in the room. Rehearsing leadership communication without rehearsing operational response is practicing the wrong skill.

Static runbooks treated as gospel. Incident response runbooks are useful artifacts. They become liabilities when they are treated as authoritative scripts rather than starting frameworks. Real incidents deviate from documented scenarios immediately and persistently. Teams that have only practiced following a runbook rather than adapting one will lose critical time when the actual incident does not match the documented template.

No measurement of decision quality. Most tabletop exercises conclude with a facilitator summary and a list of identified gaps. Rarely does the debrief include a rigorous analysis of where decision-making degraded under pressure, which assumptions proved incorrect, or how long it took the team to reach key decisions. Without that measurement, the exercise produces documentation but not learning.

What Substantive Testing Actually Looks Like

Organizations that develop genuine incident response capability approach testing differently across several dimensions.

First, they introduce adversarial realism. Red team engagements and purple team exercises—where offensive and defensive teams collaborate to stress-test detection and response—provide qualitatively different signal than facilitator-led tabletops. They surface gaps in tooling, detection coverage, and human decision-making that structured scenarios do not reach. Organizations that conduct red team exercises only to satisfy a vendor questionnaire are missing the point of the exercise entirely.

Second, they test the actual response chain. This means involving the engineers, analysts, and administrators who will be operationally responsible during a real incident—not just the executives who will communicate about it afterward. It also means running exercises at uncomfortable times, under conditions that introduce cognitive load, and without advance notice of the specific scenario. The goal is not to embarrass participants; it is to expose the gaps that only appear under realistic conditions.

Third, they measure mean time to detect and mean time to respond as operational metrics, not just as compliance data points. When these metrics are tracked continuously against real incidents and exercise outcomes, they create accountability for improvement that documentation-based programs cannot replicate.

Fourth, they treat the post-exercise debrief as a structured learning process rather than a formality. Blameless post-mortems—a practice borrowed from site reliability engineering—provide a framework for extracting genuine insight from both real incidents and simulated ones. The question is not what went wrong, but why it went wrong, and what systemic changes would prevent recurrence.

A Framework for Honest Assessment

Security leaders who want to evaluate whether their incident response program is substantive or theatrical can apply a straightforward diagnostic. Ask four questions.

One: When was the last exercise that produced an outcome the team did not anticipate? If every exercise resolves as planned, the scenarios are not realistic enough.

Two: Are the people who will execute containment procedures the same people practicing them? If not, the program is rehearsing communication rather than response.

Three: Has the organization measured how its mean time to detect and respond has changed over the past two years? If those metrics are not tracked, improvement cannot be demonstrated.

Four: Would the current incident response program satisfy an auditor but embarrass a red team? If the honest answer is yes, the program is oriented toward the wrong objective.

The Cost of Rehearsing the Wrong Thing

Incident response programs that prioritize compliance over capability carry a concrete cost. According to IBM's Cost of a Data Breach Report, the average breach in the United States costs organizations $9.48 million as of 2023—a figure that reflects not just remediation expense but business interruption, regulatory penalties, and reputational impact. Organizations with mature incident response capabilities consistently demonstrate lower breach costs and shorter recovery timelines than those without.

The investment required to build a genuinely capable incident response program is not trivial. It demands more sophisticated exercise design, broader stakeholder participation, and a willingness to surface uncomfortable gaps rather than paper over them. But it is a defensible investment, because its return is measured in reduced breach impact rather than in audit findings.

The alternative—rehearsing the appearance of readiness while leaving the actual threat surface unexamined—is a cost that organizations pay not in preparation, but in recovery.

All Articles

Related Articles

Complexity as a Cost Center: What Ovengineered Systems Are Really Doing to Your Engineering Workforce

Complexity as a Cost Center: What Ovengineered Systems Are Really Doing to Your Engineering Workforce

Proving Platform Engineering's Worth: A Finance-Ready Framework for Infrastructure ROI

Proving Platform Engineering's Worth: A Finance-Ready Framework for Infrastructure ROI

The Modularity Mirage: When Best-of-Breed Architecture Becomes a Financial Liability