False sense of 'security' due to corruption, why CISO's can't be trusted ;)
CSO
As Chief Security Officer for high-risk organisations for the past 30 odd years, i've been put under a lot of pressure by various high ranking officials to create official reports stating that "all is fully compliant with laws and regulations and ISO27001/VIRBI/ABDO/NIS/GDPR/NATO rules/etc.. When it is too clearly not at all compliant due to the fact that management refuses to allow decent security rules enforcement.
I've always refused to write reports which are not true. But most of the thousands of CISO's and lower ranking 'security' officers do play along, and get paid to keep quiet about why there are so many security incidents which should never have been able to happen if the security structure is actually compliant with regulations.