Where should real security take over for the appearance of security? How much of security is truly about protecting people, as opposed to making those same people feel safe? By the appearance of security, I mean the use of CCTV cameras that aren’t really monitored or even connected, or the demand to use strong passwords for online transactions when the site isn’t on a secured server. This is an often-used and successful way to increase a general feeling of security. I would even argue that much of the security that has been put in place since 9/11 is really about making people feel more secure. The average person doesn’t want to hear about risk analyses and the low likelihood and difficulty of deterring, say, a terrorist incident. They want to feel that they are safe and secure. If we make everyone at least feel more secure, then aren’t we achieving at least some of what we have set out to accomplish?One of the most obvious examples of this is in building security.Gone are the days when one can just waltz into a high-rise and hop onto an elevator. The screening method du jour involves checking your photo ID at the lobby desk. Most security professionals would agree that checking an ID, when you cannot confirm the validity of that ID, is really quite useless. It is intended to make us feel more secure in our offices and in those we visit. But how about those facilities that, because of their nature, are targets for those who would do us harm? Where should the appearance of security leave off and real security take over?Airports are another example. Since 9/11 the United States has put armed guards into our nation’s airports to prevent another 9/11-style terrorist attack. These actions would almost never prevent a hijacking, but they are intended to make us feel more secure when we travel. Some may argue that they are truly more of a reaction to terrorist attacks of the 1970s, ’80s and ’90s. (And think of the shooting at the El Al Terminal at LAX in 2002.) These moves are certainly a step in the right direction. But what else should we be doing to address airport security? One place to start could be the Transportation Security Administration’s efforts to look for signs of dangerous behavior among airport travelers. (See “Sharp Object Lessons,” www.csoonline.com/030106, for more on that.) At some high-profile buildings in New York—significant targets for all sorts of crime—one would expect to see a high level of real security screening and monitoring. There are cameras and guards and X-ray machines, but almost no one is stopped and subjected to further screening. Are they really screening these visitors or are they just trying to make the tourists feel more secure? Has security been placed on the back burner in order to facilitate the sale of souvenir photos and statues to tourists? Maybe. Is that appropriate? Maybe for them it is.Security professionals practice risk assessments all the time. What is the likelihood of this incident happening? What would the impact of that event be? How much would it cost to mitigate the threat? Is it worth it, or do we just accept that there is always some level of risk inherent in whatever we do? At the end of the day I have to ask that question again: “Where should real security take over for the appearance of security?” It’s a question not easily answered. And in some cases, I suspect, not being asked. Related content news UK government plans 2,500 new tech recruits by 2025 with focus on cybersecurity New apprenticeships and talent programmes will support recruitment for in-demand roles such as cybersecurity technologists and software developers By Michael Hill Sep 29, 2023 4 mins Education Industry Education Industry Education Industry news UK data regulator orders end to spreadsheet FOI requests after serious data breaches The Information Commissioner’s Office says alternative approaches should be used to publish freedom of information data to mitigate risks to personal information By Michael Hill Sep 29, 2023 3 mins Government Cybercrime Data and Information Security feature Cybersecurity startups to watch for in 2023 These startups are jumping in where most established security vendors have yet to go. By CSO Staff Sep 29, 2023 19 mins CSO and CISO Security news analysis Companies are already feeling the pressure from upcoming US SEC cyber rules New Securities and Exchange Commission cyber incident reporting rules don't kick in until December, but experts say they highlight the need for greater collaboration between CISOs and the C-suite By Cynthia Brumfield Sep 28, 2023 6 mins Regulation Data Breach Financial Services Industry Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe