Phrases Cyber Security Professionals Need to Think Carefully About Before Using with Non-Cyber People
Link: www.netmums.com

Phrases Cyber Security Professionals Need to Think Carefully About Before Using with Non-Cyber People

As awareness of information security challenges becomes more prevalent, there is an increasing chorus of people involved in the space that seek to promote change. Many of these efforts, from government, advisory bodies, industry bodies, vendors and security providers are genuinely well-intentioned and come from a good place.

The challenge, however, is that despite study after study, report after report, white paper after white paper and breach after breach, all which indicate that cyber security is now a top existential threat to the global economy, privacy and personal safety – the message is simply not cutting through.

Why could this be the case?

Much of the advice that the cybersecurity industry dispenses with is aimed at the non-cybersecurity person to facilitate some level of change – change that we simply are not seeing. In an effort to address this, it could be handy to consider what the non-cybersecurity person is hearing from the industry, and why the message is not getting through – and potentially how to fix this.

The following are phrases that are ripe for deep consideration prior to being used in every day conversation with our non-cyber brethren.

“Cyber Security is Important”

Cyber security is important. To us. To our organisations. To the wider world.

No alt text provided for this image

However, to tell someone who is not in cyber security to consider the issue as important is akin to a dentist telling a patient it’s important to go to the dentist every 6 months; a doctor telling a patient it’s important that they should have a check-up every 12 months; a mechanic telling a driver they should get their car serviced regularly.

Sure – we all know it’s important, but how many of us action that issue because we are told it is important, even in instances where human life is at stake (which is what the doctor is aiming to preserve). The truth is, not many.

Cyber professionals often overlook the fact that there are many people out there who just don’t care about cyber security. This includes the authors partner, who is reminded of this every time he asks her to update her gadgets (more on this later). Many of the people who hold this view have, fortunately, never suffered a tangible cyber-attack, so they simply cannot contextualize the threat in terms that they can grapple with. While they hear stories of large-scale breaches, they live in the belief that “this happens to big organisations with lots of money but not to people like me”. 

Recently, I heard a story of a traveller who never felt vulnerable while travelling, dismissing stories of people who had travelled overseas and were stranded due to theft. That was until he himself had his passport, wallet and money stolen from him while on a trip. This mentality shift due to an adverse event also rings true of cyber security.

A suggestion - rather than telling someone that cyber security is important while righteously nodding your head up and down, illustrate to the person you are speaking with why cyber security is important to them and their circumstances, and what ramifications could ensue should they continue to adopt unsafe practices.

 

“Cyber Security Culture Must Change”

Multiple studies have indicated that over 90% of cyber breaches are caused by human error, be it accidental or deliberate.

It is an undeniable fact that the culture of cyber security needs to change.

But, telling an organisations leadership that it needs to change because it’s what everyone else in cyber security is saying these days will likely fail.

Let me explain.

Culture that is growing from an 8 year olds hand.

Business leaders in almost all industry sectors are today grappling with numerous existential issues. Digitisation is upheaving practically every industry on the planet. Organisations are increasingly expected to be greener, more ethical and more socially responsible. With the advent of social media, organisations also need to market themselves effectively so as to become attractive places to work – so they need to invest in organisational culture change initiatives.

Meanwhile, they still need to meet organisational goals, their obligations to shareholders and after all of this, the financial goals they need to survive and be profitable.

Without addressing why an organisations culture needs to change, how that change will need to take place and who should be responsible for that change, change won’t come from a planned, measured and orderly place. If these parameters are not adequately set by an organisations leadership, change will come, but it will be imposed on the organisation - whether the organisation likes it or not.

A message that “we need to change the culture of cyber” to an organisations management is not enough. Simply put, it will get lost in amongst the other themes of change an organisation needs to grapple with. Worse, it could even be seen as a brake on digitisation strategies many organisations are needing to undertake simply to survive.

Rather, when discussing cyber culture change, again, focus on why the culture of cyber security needs to change in terms of the organisational mission, how that change should be implemented and what organisational goals that change in cyber culture will seek to address. Without understanding a proposed cyber culture shift and ensuring that it aligns with the organisations purpose, any call for change will be difficult to achieve.


“Cyber Security is a Risk Issue”

It is rather fashionable these days to mention to leadership that cyber security is a risk issue. And truth be told, it is. The World Economic Forum lists cyber related issues as two of the top five economic threats around the world today.[1] There is no question that cyber security is a major risk issue.

No alt text provided for this image

The problem with this statement, once again, is that from an organisations leadership perspective, cyber is one of a multitude of diverse risks that it needs to weigh up and decide to apportion the appropriate levels of resourcing in order to mitigate that risk. And, I hate to say it, it probably won’t rank up there with the important risks that get resources unless you can contextualize that risk in terms, constructs and concepts that:

  1. mean something to a largely non-technical audience.
  2. are as accurately quantified as possible in some way.
  3. indicate to management the reputational, regulatory and fiscal repercussions should the organisation not address that risk.

Asking management for a new firewall because “the licences have expired and this presents a business risk” won’t work nearly as well as “we need to upgrade our technology to meet the new cyber risks that our sector are facing, including risk A, B and C which will result in X, Y and Z outcomes should our organisation fail to do so”.  


“It’s important to update your computer / phone / tablet”

Every time a fruit-themed vendor of laptops, smart phones and tablets releases updates to its operating systems, I remind my partner that an update is out and for her to install it.

No alt text provided for this image

Our dialogue used to look something like this:

Me: “(insert relationship-based term of affection that precedes all sentences here), please update your laptop, tablet and phone – it’s really important”.

Partner: “Do I have to right now?!”

Me: “Yes – it’s a good idea. There’s a bunch of cyber security patches in this update and I don’t want you to get hacked”.

Partner: “I’m in the middle of something. Can we do this later?!”

Me: “Best not to. Can you save the work you are doing and I’ll do the update for you?”

Partner: “But every time you install updates you screw my computer up and it slows down!!!!!”

Does this dialogue sound familiar to anyone? 

Again – why is it important? Not to me. But to her. What in this proposed security patch is important to her? Explain what of those important issues the updates seek to help minimize the risk for.

Next – make it easy to resolve. In my case, I get her consent to update the devices, wait for her to go to sleep and then update all three devices.

Finally - don't screw up the computer, whatever you do.


“Why did you click on that email for?!?! That was stupid!”

Let’s pretend that you walk into your doctors practice Friday afternoon complaining of a sore thumb that you accidentally struck with a hammer on the weekend prior. X-rays are performed and it’s determined the thumb was broken by the blow. Your doctor then turns around and exclaims “why did you hit your thumb with the hammer for, that was stupid!”.

Ponder the following questions for a moment:

  1. What’s the chance that you won’t strike your thumb with a hammer again? Well, if you throw your hammer away again and refuse to ever use one again, the chances are pretty high. However, will it minimize your risk of getting your thumb caught in a door, a window or any other rather painful situation thumbs can get caught in? Probably not.
  2. What’s the chance you will ever visit that doctor again?
No alt text provided for this image

This is no different for cyber security. Time for cyber professionals to step off the high horse on this one and understand that belittling someone for a mistake will never change their behaviour. 

In addition, doctors are no less immune to broken thumbs than anyone else is. The same is true with cyber security professionals and emails.

 

“What kind of idiot uses ‘Password’ as a password!!!”.

Let's start by cutting out the belittling language. As I illustrated earlier, it’s not going to win you many friends nor will it effect any form of change – except for having yourself taken off this year’s Christmas Card recipient list.

No alt text provided for this image

As cyber security professionals, we know how important passwords are. And yet, even within our own industry, there are dissenting views of what constitutes a good password. Many non-cyber professionals simply do not appreciate the potential repercussions of not using strong passwords until it directly affects them.

 How can you manage a situation where a user opts for an easy-to-guess password:

  1.  Explain in terms that make sense to the person you are speaking with why having a weak password as a password isn’t a great idea.
  2. Explain what some of the repercussions could be of not using a more complex password.
  3. Explain that a password is similar to a house key. If you’re using a key everyone else can easily manufacture, then, just like its easy for a robber to clean out the contents of your home, the same is true for your electronic assets.
  4. Explain the concept of passphrases and how for many, it’s much easier for them to remember a passphrase than a password, with the additional benefit of increasing security.
  5. Explain the privacy implications of having an easily guessed password – including that a potential attacker may gain access to your personal details, photos, and private records that can then have implications on your finances, credit rating, reputation and credibility.

If you want to bring about lasting change, remember to treat the person with dignity, respect and put their interests above any sense of professional ego. 


In Conclusion

At an event I was recently at, a senior cyber security professional reminded me that “we have been talking about cultural change, risk and password for over 10 years now – and we're not seeing any change in results. Far from it, it appears to be getting worse.”

The famous physicist and scientist Albert Einstein reminded us that insanity is doing the same thing over and over again and expecting different results.

While it's often difficult for professionals to look in the mirror and ask “what can we do better” – it is incumbent to understand that any cyber security change starts with the practitioner. How we approach those we seek to protect needs to change.


References

[1] https://www.weforum.org/agenda/2019/01/these-are-the-biggest-risks-facing-our-world-in-2019/ 



Mary Attard

Cyber Security - ANZ Security Lead

5 年

Great article Tony, as someone in the cyber security industry this is a great reminder that not everyone understands these concepts and we need to continue to make them business relevant.

Ari Vennonen

Delivery Lead at Nova Systems

5 年

Not everyone is IT literate yet this article highlights opportunities to educate users of IT with plain English to explain important security concepts and the resulting impacts of taking the wrong approach. Every job role is full of jargon and let’a take the time to explain the detail clearly and succinctly .

Grant McKechnie

Experienced ASX Top 50 CISO | CSO | Cyber Security Expert | 2022 APAC Top 10 CISOs

5 年

Ana Stuparu - it’s like this article listened to our conversation!

Excellent article Tony. Just one thing, the security team needs to know the business backwards to point out to executives exactly where changes need to be made. That includes any backdoors etc. As you point out, executives need a succinct, costed proposal to go with any upgrade of security. This is the only way to get it through their thick heads. Also pointing out the potential costs (documented) to the business of not upgrading security would be another motivator. And you're so right about the language.

Keith Marlow

Cyber Security & Architecture Consultant | PhD, CISSP, Security Risk Management, MACS, MBCS

5 年

I use a lot of storytelling and humour to get the message across; i.e. if they can see themselves within the situation that led to the security issue - they will often change their behaviour. I also use peer pressure a lot as well. Plus some automated tools to take the decision to update or not out of peoples hands.

要查看或添加评论,请登录

Tony Vizza的更多文章

社区洞察

其他会员也浏览了