Distributing Security

Distributing Security

You'd think by now we'd all know that security siloes are a bad thing, counterproductive to what we want to achieve. Sadly it doesn't seem to be the case.

Every patronising comment about people being the weakest link, each time supposed professionals blame the user, and most of all the culture of blame and shame that exists for victims of deception shows how far we still have to go.

Knowledge Traps

A mixture between a book and a mousetrap.
A knowledge trap primed and ready to stick

I recently wrote about psychological traps that we fall into, mentioning the narrative trap. There's another one that many of us in security easily fall into without realising (many outside of security do too, it's a common trap).

Knowledge traps are almost the opposite of beliefs in exceptionalism. Instead of falling into thinking that we are unique and special, it's the assumption that everyone else is coming from the same base of knowledge and experience as we are.

Everyone must have the same awareness of the dangers, the same understanding of threats, the same professional paranoia we expect to develop. It's a dangerous trap to fall into because it leads rapidly to victim blaming, and to us failing in our responsibilities to others.

We are there to give others the means to protect themselves at least as much, if not more, than to protect them. Any other approach isn't sustainable.

You Are The Weakest Link, Goodbye

There's a problem narrative that still clings on that people are the weakest link in security. I'm not a fan of that idea.

The Anne Droid from Doctor Who seemed appropriate here

Victim blaming is one of the worst symptoms of poorly distributed security. If people are given insecure tools, not given the training, and their priorities don't incorporate security then the fault doesn't lie with the users.

That's not to say when secure tools, appropriate training, and personal ownership of security are provided that the individual shouldn't be accountable - only to say that I have rarely, if ever, seen that to be the case.

On the tools front there's an argument that the blame might belong on the development side - but even then if development isn't given access to the right security resources to build properly in the first place, are they really at fault? Here I do think education plays a part - security needs to be embedded as a foundational principle in learning development, and that begins at the beginning.

The Point

All of this boils down to security needing to be embedded across organisations. The ideal is not a highly capable, dedicated security function but a skilled and knowledgeable security resource which is not only available to the wider organisation, but actively seeking out opportunities to assist, support, and educate.

I've found, repeatedly, that given the understanding most people are motivated to take ownership of their own security. The biggest issues come when they're trained to believe that it's someone else's problem, which happens when security is siloed away in its own ivory tower.

Alexandre BLANC Cyber Security

Advisor - ISO/IEC 27001 and 27701 Lead Implementer - Named security expert to follow on LinkedIn in 2024 - MCNA - MITRE ATT&CK - LinkedIn Top Voice 2020 in Technology - All my content is sponsored

1 年

very well put !

要查看或添加评论,请登录

James Bore的更多文章

  • Dropping the Ball

    Dropping the Ball

    It happens to everyone from time to time, both in personal and professional life, but it's much more noticeable when…

    3 条评论
  • Making Policy

    Making Policy

    One of the most common challenges we come across working with clients who have mature management systems is that they…

    3 条评论
  • Defining Objectives

    Defining Objectives

    Last week we talked about building the foundation of our management system - defining who we are and what we are as a…

    2 条评论
  • Starting Over

    Starting Over

    This is a bit of an experiment. We've decided to rebuild our BMS (Business Management System) from scratch.

    3 条评论
  • Informational Flak

    Informational Flak

    I did have another topic planned, but given what I'm already seeing out there this one seemed more timely…

    14 条评论
  • Deepfakes: Solving the Wrong Problem

    Deepfakes: Solving the Wrong Problem

    I first wrote about deepfakes back in 2019 in a textbook for Springer, and made a few predictions. Sadly the publishing…

    27 条评论
  • (AI)SO 42001

    (AI)SO 42001

    While this is going to be specific to 42001, there's some useful general notes about the ISO management system…

    2 条评论
  • Out of Touch

    Out of Touch

    I'm always interested in statistics. And, naturally, as the owner of a second-generation family micro-business I'm also…

    11 条评论
  • Writing in Gold

    Writing in Gold

    There's a quote which is deservedly well-known in health and safety circles. I've heard it multiple times over the…

  • Peace of Mind

    Peace of Mind

    A week ago I opened up a couple of polls about what we're actually selling in security (with a special nod towards the…

    6 条评论

社区洞察

其他会员也浏览了