A programme is drifting into theatre when it relies on broad ambition but lacks concrete requirements, data-driven measurement, and lessons learned from incidents. Another warning sign is inconsistent outcomes across organisations that should be governed by the same baseline. Effective programmes produce clearer enforcement, better coordination, and visible changes in resilience, not just more policy language.
What signals that a national cybersecurity programme has become performative?
When a national programme is performative, the centre of gravity shifts from measurable security outcomes to visible activity. The warning signs are usually structural: plans that are broad but not testable, reporting that describes effort rather than effect, and coordination that looks good on paper but does not change how organisations prevent, detect, or recover from incidents.
The most useful way to spot theatre is to ask whether the programme changes baseline behaviour across the country. If it does not drive consistent obligations, evidence, and feedback from incidents, it may still be politically useful, but it is not yet operationally effective.
What does performative cybersecurity policy look like in practice?
Performative programmes tend to overproduce strategy language and underproduce implementation detail. Common symptoms include high-level commitments without minimum requirements, guidance that is voluntary by default, and success being measured by publications, workshops, or announcements rather than adoption, control coverage, and incident trends.
Another sign is that the programme can be cited easily but cannot be defended operationally. If organisations subject to the same baseline show widely inconsistent outcomes, the programme may have created awareness without enforcement. That gap matters because national cybersecurity only becomes real when requirements are specific enough to change behaviour and auditable enough to prove that they did.
A third signal is weak learning loops. Effective programmes treat incidents, exercises, and sector reporting as inputs to policy revision. Performative ones repeat the same talking points after repeated failures, which usually means the framework for improvement is missing or disconnected from actual incidents and sector data.
Which signs separate visible activity from real improvement?
The clearest separator is evidence. A real programme can show where controls improved, where compliance rose, where incident handling got faster, or where known weaknesses dropped over time. A performative programme can often show attendance, consultation, and publication volume, but not whether those activities changed risk.
Another separator is consistency. National programmes should narrow the gap between organisations facing the same baseline requirements. If some sectors or operators materially improve while others are left to interpret the programme differently, the issue is often not ambition but enforceability and accountability.
Finally, look at whether the programme creates operational clarity for practitioners. When policy is effective, it reduces ambiguity about ownership, reporting, control expectations, and escalation. When it is performative, practitioners are left with broad intent and no dependable way to translate it into controls, budgets, or assurance activity.
Risk and Threat Considerations
Performative national programmes create a false sense of assurance. That is risky because policy visibility can mask control gaps, leaving critical sectors, suppliers, and public bodies exposed even while the programme appears mature on paper.
Failure mechanism: Weak requirements, loose enforcement, and poor feedback from incidents allow organisations to comply cosmetically while leaving the underlying control environment unchanged.
Impact: The programme may normalise inconsistent resilience, delay remediation, and let recurring weaknesses persist until a major incident exposes the gap between stated policy and actual capability.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OC-01 — Organizational Context | National programmes must define measurable outcomes and scope for the country or sector. |
| GV.RM-01 — Risk Management Strategy | The question is about whether the programme meaningfully reduces national cyber risk. | |
| GV.RR-01 — Roles, Responsibilities, and Authorities | Performative programmes often fail when accountability is unclear across agencies and sectors. | |
| Recommendation — Define the programme’s operating context and expected outcomes before expanding policy language. Set risk-based priorities and review whether actions are reducing material exposure. Assign clear ownership for baseline enforcement, reporting, and escalation. | ||
| ISO/IEC 27001:2022 | A.5.35 — Independent review of information security | Independent review helps distinguish genuine control improvement from policy theatre. |
| A.5.36 — Compliance with policies, rules and standards for information security | A performative programme often lacks evidence that organisations actually comply. | |
| Recommendation — Use independent review to verify that programme claims match observed control performance. Check whether compliance expectations are auditable and consistently enforced. | ||
| CIS Controls v8 | CIS-17 — Incident Response Management | Incident learning is a key indicator of whether national programmes improve outcomes. |
| Recommendation — Use incident trends and lessons learned to validate programme effectiveness. | ||
Practitioner Guidance
What to verify: Treat the programme as effective only if you can point to specific requirements, measurable adoption, and incident-driven updates. If reporting cannot show change in control coverage, response performance, or sector consistency, the programme is still in theatre mode.
Decision rule: If the national baseline is broad but not enforceable, prioritise clarifying minimum obligations, evidence requirements, and escalation paths before adding more strategy language. The absence of those mechanics usually explains why delivery stalls.
Practitioner takeaway: The right test is not whether the programme sounds serious, but whether it measurably changes what organisations must do and what they actually do.
Related resources from NHI Mgmt Group
- What are the signs that a trust programme is becoming performative rather than operational?
- What are the signs that a data governance programme is becoming operational rather than staying theoretical?
- What are the signs that a NIS2 readiness programme is not protecting critical services effectively?
- Where does cross-environment agent discovery fit in an IAM programme?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 25, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org