Changing the thinking to cyber security

Changing the thinking to cyber security

One of the biggest changes I think we could make as an industry / discipline to really alter how we approach things is to recognise linkage. Realise that everything we do is linked focus upon effectively one junction on a spiders web that’s leads down pathways.

Nothing is isolated. There are always knock on effects, dependencies, people, processes, teams, goals, and of course gaps.

The more we recognise how things bleed into each other the more we’ll design actions with links in mind. It will enable us to affect better change.

Rather than masking a problem, moving it along one or ticking a box.

It will also build a greater cognisance of the things around our little world that impact our effectiveness. Things we don’t directly control, but can influence if we understand them better.

We’ll change by thinking differently. By approaching things differently. It’s why I talk about horizontal thinking, to illustrate how things join in a ‘linear’ fashion against a backdrop of an industry that drives us towards vertical thinking; silo solutions, magic quadrants etc.

And of course aims to make us believe that the problem(s) is/are irreducibly complex. We can’t possibly hope to solve them without faith in vendor/consultancy/MSP/et al.

It is not irreducibly complex, not matter how much you are told about sophistication, or legacy, or whatever.

You can break things down into understandable components from which you can start to build out a ‘spider’s web’ of knowledge of that component and all the things that are joined to it on its linear pathways.

Improve some of those things gradually and you’ll get better.

Always trying to build up to an overall view. It’s bloody hard, but even at a local level you can improve. Whether that is your daily processes, or building relationships with dependent teams, or your overall strategy, or adversarial understanding. None of it happens overnight.

Most of all think differently. Don’t just do what the industry pushes you towards. Building understanding of linkages is key. To do that you need to think in a different way to how most approach the cyber problem(s) today.

Horizontal thinking!!!

Kathryn B.

CEO and Founder, Cybermaniacs

5 年

This is really great. Here The Cybermaniacs?we feel culture needs to move the same way as you describe here, building up positive nodes and reinforcing through a variety of behvaioural approaches- there is no one taxonomy or hierarchy (for instance of biases or choice dynamics) that will help get the wave of security awareness and the necessary behaviour adaptations rolling through your company. It's putting in the thinking, thinking differently, moving horizontally and through the network of people at a company. Sometimes we find that stuff doesn't land and we move on, and we also find things we programmed as a 'nudge' event were powerful resonators and moved the needle more than we could have imagined. If cyber needs to be dynamic, holistic, ready for anything, and has people in the system... then I couldn't agree more- mindset, thinking, adapting, and communication are key. Really love this post, thank you Edward Tucker!!!

回复
Andrew Davies

High-performance cybersecurity consultant that delivers

5 年

In my opinion, attackers think in maps, auditors think in lists, and defenders onions; most of security operations are on the perimeter (outer layer of the onion), and depending on budget and knowledge of the core network, the organisation may have a soft core. But the security architecture is based on layers from outside - in. Graphing is a relatively new way of thinking, incorporating threat intelligence to drive specific threat profiles.

Philip Abraham ~ Strategy

Founder of Brilliancy Deep Tech | World Class Complexity Scientist | Board Member | Quantum | Expert in Artificial Super Intelligence | Cyber Security | Supply Chain | Inventor | Blockchain | Futurist | Keynote Speaker

5 年

Attackers don’t want to mess with systems that stop using traditional off the shelf software! The attacker’s walk right through that software!

Matthew Harris

Driving 5X Email Response Rates for Business Leaders with AI-Powered, Personalised Outreach.

5 年

Its the how? Getting off the railway line and into the air when most reports, feedback etc are all "working on the railroad" .

Dinis Cruz

Founder @ The Cyber Boardroom, Chief Scientist @ Glasswall, vCISO, vCTO and GenAI expert

5 年

great post, and as Phil Huggins mentions above, the key is to think in graphs (and then in maps) Edward Tucker have you seen the presentations I published about thinking in graphs?

要查看或添加评论,请登录

Edward Tucker的更多文章

  • Bridging Conflict with a Culture of Collaboration

    Bridging Conflict with a Culture of Collaboration

    When banging heads against other teams (inc suppliers) it can be easy to fall into a cycle of distrust and conflict. It…

  • Human Firewall feedback request

    Human Firewall feedback request

    LinkedIn InfoSec peeps, I’d like to elicit feedback on a solution we’ve developed please. I think it has got real legs…

    3 条评论
  • Start your DMARC journey

    Start your DMARC journey

    Here’s something that I think every organisation should do and that is to implement DMARC. For those that don’t know…

  • The REAL Cyber Skills Gap

    The REAL Cyber Skills Gap

    1. Executive Summary The internet is an amazing resource providing countless opportunities.

    13 条评论
  • Introducing Human Firewall

    Introducing Human Firewall

    Human Firewall is multi-faceted solution. At the front it is a security awareness solution built on the premise of…

  • How Equifax are you?

    How Equifax are you?

    It is very interesting to see the Equifax report. Most pertinently that they had processes, tools and policies in…

    2 条评论
  • 2019 Predictions

    2019 Predictions

    As we are in the season of predictions, which vary from the factual and realistic to the downright comical. We’ve all…

    22 条评论
  • Building a Cyber Security Academy

    Building a Cyber Security Academy

    Introduction We have skills gap and an aging cyber security workforce. We need new blood, and skilled blood at that.

    13 条评论
  • Cyber Insurance - So you’re insured, well everything’s OK then………..isn’t it?

    Cyber Insurance - So you’re insured, well everything’s OK then………..isn’t it?

    Well let’s start with a fairly fundamental question…..

    6 条评论
  • The Cyber Skills Gap

    The Cyber Skills Gap

    According to several recent studies there are more cyber security jobs going unfilled than there are people on the…

    1 条评论

社区洞察

其他会员也浏览了