Cybersecurity Culture Leadership Talent Development

Improving Cyber Security Awareness and Behavior

Improving Cyber Security Awareness and Behavior

With the rise of data breaches, CIOs and CISOs are quickly learning that internal security breaches as a result of social engineering are occurring more often than they’d like to admit. And while everyone seems to be championing best practices for Cyber Security, awareness is not the same as changing behavior. It’s our human qualities that make us most susceptible to human engineers. If a company were to take the millions they invest in security technology and begin focusing on the people side, how much of a real difference can smarter awareness make?
Contributors

    • Jeffrey Wright, VP & CISO, Allstate
    • Derek Brink, Vice President, Research Fellow, IT Security and IT GRC, The Aberdeen Group

Download Podcast
Apple PodcastGoogle PodcastSpotifyPandoraiHeartRadioSoundCloudTuneIn, and Stitcher. Find other syndication channels here or search CIO Talk Network podcast on any other app.

Explore More

Transcript

Sanjog Aul [00:00:26]:

Hello, and welcome to CIO Talk Radio. To learn more about the show, please visit www.ciotalkradio.com, and as always, we invite you to join the discussion on Twitter, #CTR live, and look for this show as #cybersecurity. Today’s topic is Improving Cybersecurity Awareness And Behavior, and our guests for today’s show are Derek Brink, who’s a Vice President and Chief Information Security Officer with Aberdeen Group. Hi, Derek. How are you?

 

Derek Brink [00:00:53]:

Hi there. Doing well. Thank you, Sanjog .

 

Sanjog Aul [00:00:56]:

Very good. Hey. Life is treating you good?

 

Derek Brink [00:00:59]:

Things are fine here. The weather’s changing into winter in New England where I am, but life is good.

 

Sanjog Aul [00:01:06]:

Alright. Great, and we also have Jeffrey Wright, who’s the Vice President and Chief Information Security Officer with Allstate. How are you, Jeff?

 

Jeffrey Wright [00:01:13]:

Doing well. Thanks.

 

Sanjog Aul [00:01:15]:

Alright. Great, guys. Welcome to the show again. Now there’s a saying that Americans are the most health conscious country in the world, and yet we are also one of the fattest and most unhealthy nations around. Why do I say this? Because the same might be said of cybersecurity where we invest millions in technology to protect our data and our privacy, and yet we are still consistently susceptible to attacks. So October, every year is a national cybersecurity awareness month that we celebrate, and all along the month, we’ve been doing shows focused on security, but today, we wanted to talk specifically about awareness and what it really means to be aware and behaving smartly and properly in regards to the threats that are out there. So, Derek, as a first question I’d like to ask you, we speak about awareness all the time, and we say if there was better awareness, then we could have solved most of these problems, and there may be some best practices people say that exist which could be utilized, but what are we talking about, in terms of awareness? If there was clarity, then there would have been a solution, but is there a lack of clarity?

 

Derek Brink [00:02:24]:

Well, I think this is Derek. So I think the issue is that awareness is on the rise. Awareness is definitely increasing. The headlines are helping us see that. This is unfortunately true that we see so many cases of security breaches. Here’s how I might answer the question. When I think about attending the RSA conference, which is for our industry, it’s one of the 1 of the biggest events of each year. I think it was last year, 2013, that every conference had a sort of theme or a buzz about it. I would say that awareness was one of the buzzes from that time, and it’s increased. If you were to say the level of awareness for information security is at an all time high, I’d have to agree with that, but the thing is that awareness is not the same as doing something about it. You could talk about that on a couple of levels. Greater awareness by management and the business leaders doesn’t necessarily mean that they have greater understanding about risk and what should be done about it, and it doesn’t mean that they’re making more thoughtful and deliberate risk-based decisions and allocation of resources to address those problems. At the same time, and I think what we’re talking mostly about today is greater awareness by the users. So you and I and Jeff, it doesn’t necessarily mean that we’re changing our behavior. Awareness is the first step. Every 12 step program starts with being aware, but we’re sort of consciously incompetent, I guess, and we need to transform ourselves into being conscious of it and then doing something about it.

 

Sanjog Aul [00:04:01]:

So, Jeff, when you look at awareness and, as Derek rightly pointed out, one thing is to get jitters whenever you hear anything like some mishap or there’s a breach happening, and that is not really helping you understand what happened, why it happened, and what can we do to prevent it, prevent it from happening to us. When you look at the overall scenario out there, is the awareness limited to just getting those shocking news or are we really taking it all the way down to the users where they are understanding that if they don’t do their job well, then we could very well be the victims?

 

Jeffrey Wright [00:04:38]:

Yes. I think you’re right. There’s a disconnect between people understanding how the actions they take and the decisions they make at their desks every day and every week can affect the security posture of a large organization. Folks tend to focus on all of the technology that we buy and put in place to protect our company and our assets, and they just don’t appreciate how something as simple as browsing the web or opening an email can in some cases circumvent or bypass a lot of those controls. So it is not good enough simply to create awareness. You need to provide them with the knowledge that they need in order to make smart decisions.

 

Sanjog Aul [00:05:27]:

Now, consciously, this is for you, Jeff again. No one comes to the office or goes to work or wherever they work thinking, “I want to create vulnerability” or to work against the organization as a totally unaware person. So they do the best they can. If there are issues at the user level, should we directly take the blame as leaders or the organization, whoever is working on building the awareness, as a job not being done right?

 

Jeffrey Wright [00:06:00]:

Yes. I think, Derek mentioned the 12 step programs. I think our challenge is to make it simpler than that, fewer steps. It boils down to creating awareness. They need to understand, like I said, how the actions they take can affect the posture, and we have a role to play in that. The threats have gotten so much more sophisticated. The headlines these days are advanced persistent threats, the nation state sponsored attacks and of course all of these breaches, but they tend not to focus too much on the thousands or tens of thousands of attacks that take place every day on our systems, and those are the keep it simple stupid KISS premise. These are the simple attacks that preoccupy our SOCs where we hope that our users will make the right choice. So we’ve boiled it down to far fewer steps. It’s create awareness in order to be able to transfer knowledge to help these well intentioned people to make the right decisions, and then the important step is to visibly transfer accountability. So you’ve created the awareness. You’ve provided them with the knowledge that they need to make the right choices. Now you need to let them know that they’ve got a very important role to play in protecting the company’s assets, and then lastly, the 4th step in my process is to reinforce that not only with penalties, but also with the reward and recognition. So rewarding people for having made a good choice and really helping people stand out as a hero that they’ve been that particular day or that particular minute in protecting the company’s assets.

 

Sanjog Aul [00:07:48]:

Derek, on one hand, you have a regular office going business user who is going about reading their emails or talking about interoffice memos and responding to them and doing whatever they do in their daily lives, and on the other hand, there are very sophisticated people who are planning these attacks, who understand how psyche works, and actually are able to manipulate individuals into clicking on a link or sharing something, etc. So to what degree can you expect just awareness and even brute force training given to these users could ever match up with those super powerful, super intelligent, and highly manipulative, adversaries?

 

Derek Brink [00:08:37]:

Well, I think there is empirical evidence from companies that focus on training. They have the click rates before any training and awareness has been done and they have the click rates after. Those are pretty impressive. They show a reduction of the order of 50% to 70% of click rates by just going through that basic kind of training. So the fact is that the data is actually there, but it’s still what you talked about is social engineers. The malicious intent of these attackers, they’re intelligent and attackers are trying to design these attempts to infect and they’re very clever. They prey on the humanness of all of us and they’re trying to get us to connect or click or call or open or provide information voluntarily. All those things are with their intent to commit fraud or capture the data or sabotage the infrastructure. So the behaviors we’re talking about seem pretty benign, but they just have to do with the networks that we use, the devices that we use, the files that we send and receive, apps that we install and run, the links we click on, the emails we send, all those things. These are just everyday behaviors. So just being aware and sensitive is helping us make better decisions as we were just saying, but the malicious intent is behind it, and they are using these kinds of social engineering techniques.

 

Sanjog Aul [00:10:12]:

So, when you look at, Jeff, the real problem. So if you were to take this whole scenario of awareness not being there or people are still getting attacked or manipulated, what do you think if you were to inventory the top 3 things? What is missing in the way we go about building awareness or handling these things?

 

Jeffrey Wright [00:10:32]:

I think we’ve probably all participated in or provided awareness training. In a lot of cases that training is dated. The workforce has progressed, has moved on. They want to be communicated with in a different way. So one challenge that potentially has been overlooked in some organizations is just the way that you engage your audience. You need to find a way that creates a dialogue. It will lead to questions. Derek had mentioned sort of the empirical evidence that exists. I think it exists not only in some of the phishing tests that you can do and where you can demonstrate how prior to awareness training there was a higher degree of click through than after, but you can also harvest metrics and understand whether you’re on the right path or not by simply counting page views and the number of questions and forums that you’re asked to present in. There’s no shortage of a call to action in the press. Everyone reads about it. I imagine every one of your listeners and probably at this point just about every American has been affected by a data breach this year and had a credit card reissued. So they understand it at a personal level and how it can affect their personal finances and the things they do at home. We need to find out how to bring that level of engagement into the workforce and help them understand how you can help them protect their personal information and at the same time protect the corporate assets.

 

Sanjog Aul [00:12:16]:

Social engineering. Now this is the grandma doesn’t understand what social engineering is. So let’s kinda dumb it down a little bit, and, Derek, could you explain what it means to an average person, and what do you want them to learn about it and what they should be doing to prevent getting exploited based on it?

 

Derek Brink [00:12:36]:

Well, sure. I guess the easy definition is the social engineering just takes advantage of our human characteristics to try to get us to do something that the attacker wants us to do. I’ve always found it interesting. There’s a famous line by Arthur C. Clarke. He’s the guy who wrote 2001: A Space Odyssey, if you remember. The line he wrote is, “Any sufficiently advanced technology is indistinguishable from magic.” And so I think for a lot of everyday users that we’re not deeply knowledgeable about the underlying technology. In fact, it’s being designed that way where it’s trying to be designed for ease of use and productivity, not so we know its inner workings. With that in mind, there’s a lot of things that social engineers do that I actually also find similar to what magicians do. There’s a lot of parallels between a magic show and social engineering. So one of them, for example, is confirmation bias. We tend to search or interpret information in a way that confirms the preconceptions that we have about it, and then we tend to avoid information and interpretations that contradict any prior beliefs that we might have. So if we’re looking today and as we approach the holiday season, if we’ve got a package or there’s some problem with our shipment we might be inclined to click on that. Magicians apply the same kind of thing. They let us believe in ourselves. If they let us notice something on our own, the lie that they’re telling us becomes more impenetrable. Nothing fools us better than the lies we tell ourselves. So there’s just a lot of parallels about human nature and what the social engineers do. If it helps anybody to understand it better, then try to think of some of the things that magicians do. I think you’ll find a lot of parallels there.

 

Jeffrey Wright [00:14:33]:

Yes. Derek, this is Jeff here. I agree with your parallel comparison to human nature and magic. I think, in my opinion, social engineering and in particular phishing attacks are probably one of the most rapidly evolving threats or areas of security practice out there. The technology is largely reactive. So it’s looking for a pattern or a signature. The bad guys have figured that out and they figured out ways to rapidly manipulate that so that there really isn’t a pattern or a signature that you can key off as it comes down to the individual behind the keyboard making the right choice. A lot has changed in the last 5 years when you used to get those emails poorly spelled, horrible grammar, asking for $2,000 because you lost your passport and you need to pay a hotel bill. Today’s phishing and spear phishing emails, the social engineering attempts are very well crafted, often very sophisticated, may come in multiple parts. So they’ll ask you for a piece of information that seems fairly innocuous and put that together with a piece of information they got from somewhere else within the organization and they’ll string it together. So it’s just such a dynamic and changing environment. It does truly come down to oftentimes the individual and then fighting the urge to carry forward historical learning.

 

Sanjog Aul [00:16:10]:

Let’s take a quick break. We’ll be right back, and based on the responses we got from both Derek and Jeff, it’s not really very comforting to know that the way the things are being brought on to a regular user, and they’re becoming more and more vulnerable, and they’re more likely to make mistakes because they dealt themselves a lie as per Derek. So what is to be done with them in terms of handling such or preparing them for from such attacks, preventing such attacks? So please stay tuned listeners. We’ll be right back and explore this a little more.

 

Speaker 0 [00:16:51]:

HP is proud to sponsor this program. Find out how the HP as a service solution for SAP HANA can help you gain instant impactful business results without capital investment by logging on to hp.com. Transform information into intelligence and a competitive advantage with a full spectrum of SAP HANA products and services from HP, a global SAP hosting partner.

 

Speaker 0 [00:17:22]:

Bosch Software Innovations is proud to sponsor this program. Visit www.bosch-si.com/connectedmanufacturing to find out how Bosch can help you improve your operational performance and become a manufacturing industry leader in a connected world. Change the way you predict, manage, and produce outcomes. Bosch connected manufacturing.

 

Speaker 0 [00:17:54]:

HP is proud to sponsor this program. Tap into our expertise, innovation, and services to bring your most important workloads to the cloud. You are listening to CIO Talk Radio with Sanjog Aul. To learn more about the show, please visit www.ciotalkradio.com. If you have a question or comment, call toll free at +1 (866) 472-5790. That number again is +1 (866) 472-5790. Now back to the show. Here’s Sanjog Aul.

 

Sanjog Aul [00:18:38]:

Welcome back. So, Jeff, your response as well as Derek’s, both of them suggest that people who are very vulnerable and regular users will keep getting tricked. So what is possible for us to do sitting at the top? And you might have some ways to even share that. Are these problems happening because they just keep tripping on the same problems over and over or is there some growth happening in the user base?

 

Jeffrey Wright [00:19:06]:

I’m not sure about the growth in the user base, but what I can share, it’s a personal story, because it comes down to human behavior. It’s what we began the show talking about. I was playing the role of a computer support person for my mother-in-law at one point, and her computer was just constantly plagued with viruses and malware, and I couldn’t figure out what was causing that. Troubleshooting it one day, I watched her go through her postal mail. This is a person that has about 12 credit cards, yet every credit card offer that she received she’d open it up and read it and then tear it up. That’s just the way that she had processed mail for probably 30 years or more. When it came to email, those behaviors carry forward. The recognition that that type of action can be harmful just isn’t there. So again, for me it’s about connecting the dots. It’s about providing that level of knowledge about how things have changed in the electronic world, that seemingly harmless actions that one might customarily take in browsing the web for a product they’re searching for or opening a piece of mail electronically can really undermine some of the sophisticated technology that we put in place to protect our user community. So we have a role to play. I desperately think that role is to connect those dots to provide that level of awareness and then provide them with the knowledge: what are the right choices to make here, what should I do, when should I report something, how do I report it, and when should I maybe not open an attachment or something along those lines?

 

Derek Brink [00:21:07]:

If I could add to that, to Jeff’s comment, do you mind, Sanjog ?

 

Sanjog Aul [00:21:11]:

Yes, please go ahead.

 

Derek Brink [00:21:13]:

There’s a short story from years and years ago called The Lady or the Tiger. I don’t know if people are familiar with it, but in the story, if you’re a criminal in a certain kingdom, then you have to make a choice between two doors, and one contains a beautiful woman and the other has a ravenous tiger. The point is that one choice leads to a sentence of innocence and immediate marriage, and the other one leads to immediate death. This is a choice that we face really every day. We’re conditioned to say, look at this, check it out, click on this link. It’s innocent human assumptions to just click through and we’ll get positive results, but there’s another notion of blended threats. We might get a seemingly innocuous email or message, but it contains some kind of malicious URL link or some executable attachment that we open. That’s increasingly common. Spam continues to be a problem in our email. I’m told by the vendors who focus on this that 80% or so of spam contains some kind of malicious link or link to a website. It’s not just those websites that have been infected. In fact, the bad guys are cleverly using the search engine optimization techniques that marketers use to drive people to the websites that they want to drive them to, and just one more example. We’ve all probably seen the what’s referred to as tiny URLs, so we don’t have to see the very long URL, the shortened or tiny URL. It makes it easier for the attackers to disguise the malicious links. It was originally designed to make it easier for us. We don’t have to have the long and cumbersome URLs, but it also makes it harder for us to spot something bad, even when we see it in front of us. So the technologies are being used for both good and bad, and so this awareness just becomes all the more important.

 

Sanjog Aul [00:23:27]:

So we do know that these individuals would be interacting and communicating with the outside world outside of the four walls of the workplace at a personal level, and then they would also do the same at work. So, Jeff, would you be able to exert control or at least some supervision on what they do outside of the workplace? Is that what’s gonna give us a complete overview? What are they talking about? Who are they communicating with? Because as you mentioned, there are people who would get some information from these individuals when they are maybe not at work or innocuous information, and then they will string things together. So what is the scope of influence that you feel the CISO and the security team and the organization should exert now in order for them to prevent these people from becoming vulnerable and cause harm to the organization eventually?

 

Jeffrey Wright [00:24:20]:

Yeah. I don’t think anybody wants me intruding on what their out-of-work practices are, thankfully. I do think that when you position this awareness training and you provide this knowledge, you can do that in one of two ways. You can take the position that this is what I need you to do in order to protect the company’s assets in our email system, or you can extend yourself a little bit and help them understand how these practices will help them not only in the workplace, but also in their personal lives. I think folks are more receptive to that, probably because everyone’s been through one of these events or you can’t read the paper each week without seeing another company that’s incurred one of these breaches. So helping provide them with the tools that will help protect them outside of the workplace is a freebie to them. It’s an added level of control to me inside the workplace.

 

Sanjog Aul [00:25:38]:

So Derek, I love eating good sugary and fatty food, right, like most of us do. So even if somebody tells me, my wife would say don’t eat, but I would still indulge once in a while, maybe not all the time. The same thing then holds true for other people who may be coached with all good intentions by the CISO’s team in their organization or anyone else, but eventually they would give in and that is the opportunity those intruders are looking for. So are you better off training? Yes, but after some time you say, I’m done training these people, then let’s get ready to just be able to respond to those breaches versus trying to expect, spend a whole lot of time and energy and dollars into training people only to understand that they will partially change their behavior, if at all.

 

Derek Brink [00:26:29]:

Well, that’s a great question and there’s so many dimensions to it. We might have to break up our responses a bit, but let me start by saying that there are a couple of approaches to the problem. One is that there are prevention-oriented strategies. I would characterize what we’re talking about right now as the last mile in the prevention side of the equation: the user behavior. So there are other controls in place. More and more companies acknowledge that they can’t possibly, even though those controls are effective, be effective 100% of the time. So what we’re trying to do is to talk about that last mile, which is the user behavior side. There’s also the case, perhaps for another show, that more companies are investing in technologies to monitor and detect things more quickly and tend to respond and remediate and restore to normal more quickly because that minimizes the impact of infection. In other words, there’s two sides to the risk equation. There’s the side that addresses the likelihood of something bad happening, and what we’re talking about here addresses that likelihood side. There’s also the side of how do we minimize the impact when something does happen in spite of all our investments. Both sides are important and we’re really focused here on awareness, which is on the reduce-the-likelihood side.

 

Jeffrey Wright [00:28:02]:

Yes. Sanjog, it’s Jeff. If I could, you mentioned cost and I think folks will be pleasantly surprised to learn that providing just this basic level of awareness and knowledge transfer that’s so critically important to any program really isn’t an expensive proposition. It takes time. It means introducing yourself maybe to some parts of the organization that you haven’t interacted with frequently, like your communications team, your enterprise communications folks who can help get that message out. Simply communicating with the user community is not a very burdensome or expensive proposition. I think some of the cost that we associate with awareness training comes in when we talk about some of the testing or the remediation actions that we can take. So phishing exercises, mandatory training portals, that sort of thing, that’s expensive. There’s a lot of machinery behind that, but simply getting the message out, I think, is a very powerful thing that you can do without really incurring a lot of cost, and you also mentioned response. That’s another very important element of any security program, not just as it relates to social engineering and phishing attacks. With the frequency of attacks taking place today, I think folks would be very wise to spend a lot of time understanding how they’re going to respond and what capabilities they can bring to bear quickly to identify the scope of an incident, isolate it and remediate it. It’s a separate track outside of the social engineering or awareness training, but equally important.

 

Derek Brink [00:29:57]:

If we could, Sanjog, again, I’d like to keep the conversation with Jeff going a bit. It’s all right. We’re a couple of guys who both agree that the investment in awareness and training is a good thing, but I have to say, as a researcher, that I’ve looked across what Aberdeen does in terms of research and it is a benchmarking style of research. So that means that organizations like yours, Jeff, would respond to a survey and tell us about their practices and so on. I just looked over a particular 5-year period and over that time, there were 29 benchmark studies and they involved over 3,500 organizations worldwide. It turns out that the companies who, relative to the others, had the top performance, we call them leaders or we also use the term best in class, they were, in fact, 70% more likely on average than the bottom performers to have invested in user awareness and education, but that said, that’s still only about half of the leaders who made that investment and a much smaller percentage of the laggards. In other words, it’s a relatively low amount. I’ve always been astounded by why the majority of companies out there don’t make this investment. I have a couple of quick comments about that. One is because there are some underlying attitudes perhaps towards users — again, not your company, but there might be the, “I’ve heard it so many times that users aren’t capable of always doing the right thing, so we need to dumb things down.” Or, “I believe that users aren’t trustworthy to do the right thing, so we have to have tighter controls and fewer freedoms.” Another is a belief that users shouldn’t be making decisions about security and compliance and then the policy should be strictly enforced. I think the reason though is that security leaders frankly don’t know how. Their awareness is high, but we’re not talking about risk in the proper way and security leaders don’t know how to make that discussion of risk in terms that the business leaders understand, which is there’s a likelihood that something bad will happen and there’s an impact when it does. By making this investment, we can reduce that risk, which is a function of likelihood and impact. I don’t know if you agree with that or whether that’s a direction you want to go.

 

Sanjog Aul [00:32:25]:

Antonio? Yes. So yeah. This actually is a great time for us to take a quick break. When we come back, we’d love to get Jeff’s comments on this, and, of course, then I’d like to ask a follow-up question that as a business, we don’t get paid to try. We get paid to get results, and if social engineering or any kind of user level vulnerability is causing us the big bucks or causing us goodwill loss or other types of issues, then there has to be some significant investment made of what type. Let’s discuss that more when we come back from the break. Please stay tuned.

 

Speaker 0 [00:33:03]:

HP is proud to sponsor this program. Tap into our expertise, innovation, and services to bring your most important workloads to the cloud.

 

Speaker 0 [00:33:15]:

Bosch Software Innovations is proud to sponsor this program. Visit www.bosch-si.com/connectedmanufacturing to find out how Bosch can help you improve your operational performance and become a manufacturing industry leader in a connected world. Change the way you predict, manage, and produce outcomes. Bosch connected manufacturing.

 

Speaker 0 [00:33:46]:

HP is proud to sponsor this program. Find out how the HP as a service solution for SAP HANA can help you gain instant impactful business results without capital investment by logging on to hp.com. Transform information into intelligence and a competitive advantage with a full spectrum of SAP HANA products and services from HP, a global SAP hosting partner. You are listening to CIO Talk Radio with Sanjog Aul. To learn more about the show, please visit www.ciotalkradio.com. If you have a question or comment, call toll free at +1 (866) 472-5790. That number again is +1 (866) 472-5790. Now back to the show. Here’s Sanjog Aul.

 

Sanjog Aul [00:34:49]:

Welcome back. So, Jeff, you, of course, are going to be able to respond to what Derek just mentioned and, of course, the issue that I raised in terms of we have to get results and we have to get appropriate investments given the stakes.

 

Jeffrey Wright [00:35:05]:

Yes, hopefully it will be an eloquent response. When I heard Derek and the points you’re making, it comes back in my mind to an outcomes-driven program. So what is it that we’re trying to prevent or deter or minimize? In this case, it’s risk to a phishing attack or a social engineering attack that could lead to data loss or brand or reputation damage. So you need to create some way of proving that you’re making a dent, that you’re plugging a hole in the dam here. That’s the outcome. I said it was a relatively low investment to start one of these awareness programs. There’s cost that folks can incur as they mature that capability. Primarily, in my opinion, that comes into play when you begin to enact some of these remediation or mandatory training obligations, but you can clearly demonstrate through a couple of key metrics. One is your folks in the Security Operations Center or just in the industry, the number of attacks that are occurring in this space on a daily basis. That number is a staggeringly large number. Please don’t ask me to quote it, but it’s many zeroes after it. It’s such an easy and low cost way for criminals and less-than-well-intended individuals to try to launch an attack. On the one hand, you’ve got the number of attempts that are being made every day and every hour to compromise your environment. On the other side of that equation are simple things like the number of times that your internal web pages are viewed when you begin to put this communication out. So you begin to get a sense or an appreciation for whether or not the community is participating in this dialogue, if they’re taking this information up. Hopefully, you’re instructing them to do something, to make a choice and that choice might be to contact the email team or contact your Security Operations Center. So another metric that you can use to demonstrate that the awareness and the knowledge that you’ve just provided this community with are having a positive impact on your program is the number of people following the dialogue and taking action and that action being captured in your Security Operations Center. So I mentioned maybe 3 or 4 metrics there that demonstrate for you the size of the challenge, what’s potentially at risk as well as how as a CISO you can begin to quantify the effect that your awareness program is having and hopefully continue to fund it or fight for space when it comes to all of corporate communications or all of the other initiatives that are lingering around out there in the ether.

 

Sanjog Aul [00:38:22]:

So, Derek, would you think based on all the discussions you’ve had, are people looking for investment? I would like to especially go to CISOs. Are they going and looking at a line-item-based investment that this is how much I’m going to spend on training, etc.? Or are there different ways by which the budget could include these items and then to a varying degree you can adjust it based on what kind of results you’re getting?

 

Derek Brink [00:38:47]:

Well, I think a couple of points I’ll just try to circle back and clarify. One point I was trying to make is that present company accepted. I mean, Allstate would be considered a leader or best in class, right? I used to, before I had this role as an analyst, report to the CEO of a pretty well known security company, and he used to like to go visit customers, of course. He would come back and say, well, these customers are doing this or that. I used to say, you’re talking to the cream of the crop. When you ask to go on sales calls, you don’t go to the mom and pop stores. There’s a pyramid of organizations out there. I’m trying to make a point to the middle and even the bottom of the pyramid instead of the very tip top here. Companies are investing millions of dollars in security controls and, for the most part, they’re not investing anything in their people. I think that’s one of the points that I would make. Again, present company accepted. The second point I was trying to make is that the language we use when we try to make the business case or get the resources allocated is off base. We love, as security and technology people and IT people, to talk about advanced persistent threats and phishing and vulnerabilities and exploits and the headlines of the day, but the leaders that we’re trying to serve understand the language of risk. So here’s a simple way to hopefully get my point across for your listeners. Just take this little pop quiz here. True or false, phishing is a serious security risk to our organization. The answer is false because it’s a trick question, but it makes my point about language. Phishing is not a risk. Phishing is an exploit. Specifically, phishing is an exploit of a vulnerability that everybody has, which is human beings. So if you’re going to use the language of risk, what we need to do is say, there’s, for example, an 80% likelihood that phishing attacks will result in a business impact of greater than y million dollars over the next 12 months. If we invest in such and such, we can reduce that to an acceptable amount. Communicating in the language of risk and making decisions based on management’s appetite for risk is the point I was trying to make.

 

Sanjog Aul [00:41:09]:

So, Derek, I will just come back right to you because you’re making a claim that organizations are not investing enough in awareness, etc. If I gave you all the funds that you ever needed and you were a CISO or anyone in the business who wants to take care of this, what would you have done new or different or more?

 

Derek Brink [00:41:26]:

More? Well, now you’re getting into the real role that Jeff and other CISOs have. They have to recommend as subject matter experts and strategic advisors to the businesses that they serve. They have to recommend a mix. There’s a range of risks that the organization faces. Every organization, security is always in context, so every organization is going to have different priorities and needs for risk to float to the top. Organizations may choose to prioritize this. You don’t have infinite resources, right? So you have to do that kind of triage on the investments that you make. It’s impossible to answer that question. I am saying though that the analysis is that investments in awareness and training do significantly reduce the risk. It’s that last mile on the prevention side that I was telling you about. The investments in training and awareness are actually not that big either. The impact that you can have is to reduce the risk in models that I have by about 60%. So, again, it’s a mix of controls and that’s going to be unique for everybody, but if you approach it in the proper way, which is a risk-based discussion, then I think you’ll get more traction with and probably more budget in total from the business leaders.

 

Jeffrey Wright [00:42:58]:

Sanjog Aul, if I could. For me, it’s about sustainability of a particular control. Technology these days is critical. It serves a very important role. All of the various technologies that we as security professionals put in place inside of our organizations are important capabilities to have.

 

Derek Brink [00:43:45]:

In the face of threats that change on a daily or monthly basis, you can’t keep up in a technology race with that type of change.

 

Jeffrey Wright [00:43:45]:

But the culture can, the people can. If they’ve been provided with the right tools and knowledge, they can keep pace with that and they’ll make decisions, probably on pace with the technology, hopefully in some cases. That outpaces your ability to keep up with putting the next generation firewall or the next anti-phishing control. For me, it’s about sustainability. It’s about overcoming the cultural barriers, shifting the culture and attention of an organization and creating almost a self-sustaining environment where the people become a layer of defense in your portfolio.

 

Derek Brink [00:44:39]:

I think that’s really well said. I wish I’d said that.

 

Sanjog Aul [00:44:43]:

So, Jeff, when you look at your organization and the kind of initiatives that are underway in terms of building awareness and then doing other things related to helping the organization become more secure with respect to this area, the awareness side and the behavior change, would you say any kind of constraint exists today which prevents you from doing the best you could?

 

Jeffrey Wright [00:45:12]:

It’s a difficult question. I think one of the things that occurs to me is we’re constrained by the limits of our imagination. It’s so important that you identify the right way or ways to engage with your community. Any large organization has pockets of people. One organization is remarkably different than another in the way they work and the constitution of their workforce, maybe what their responsibilities are. So it may not be a one size fits all. In some ways, time is a constraint. I wish I had enough time to put toward shaping and driving awareness and training across the organization. I’ve had to make some decisions around the level and content at an enterprise level and then how much we can customize or tailor that and push it out to other, maybe more specialized or diverse parts of our business. So it’s, I guess in my mind, less about the dollars and more about time and imagination.

 

Sanjog Aul [00:46:28]:

Let’s take a quick break, listeners. We’ll be right back, and Derek, when we come back, let’s look at the different areas in which we are going to be investing with respect to building awareness and behavior change, keeping in mind that what we are dealing with today is going to further morph and it is going to most probably become more complex, more demanding, in terms of what we need to do in terms of educating our business users and others. So what is in store? What are we doing? Are we only going to react towards saying this is what we learned based on 20 breaches that happened, and now our training will be oriented to take care of those breaches because thieves are always going to be ahead, and we’ll keep playing catch up. Is that what is going to be the case, or are we doing anything proactively? Please stay tuned, listeners. We’ll be right back.

 

Speaker 0 [00:47:26]:

Bosch Software Innovations is proud to sponsor this program. Visit www.bosch-si.com/connectedmanufacturing to find out how Bosch can help you improve your operational performance and become a manufacturing industry leader in a connected world. Change the way you predict, manage, and produce outcomes. Bosch connected manufacturing.

 

Speaker 0 [00:47:58]:

HP is proud to sponsor this program. Tap into our expertise, innovation, and services to bring your most important workloads to the cloud. HP is proud to sponsor this program. Find out how the HP as a service solution for SAP HANA can help you gain instant impactful business results without capital investment by logging on to hp.com. Transform information into intelligence and a competitive advantage with a full spectrum of SAP HANA products and services from HP, a global SAP hosting partner. You are listening to CIO Talk Radio with Sanjog Aul. To learn more about the show, please visit www.ciotalkradio.com. If you have a question or comment, call toll free at +1 (866) 472-5790. That number again is +1 (866) 472-5790. Now back to the show. Here’s Sanjog Aul.

 

Sanjog Aul [00:49:13]:

Welcome back. So, Derek, while we are dealing with existing threats, they are evolving, and people will get deceived in new ways. Do you think that education or awareness building and behavioral change related exercises that we are executing today are going to really prepare us for the future or is this again going to be that we live day by day?

 

Derek Brink [00:49:35]:

Well, I think they can. What Jeff was saying before about creating a sustainable culture and relying on the people as part of the mix of security controls is very well said. The kind of awareness that many companies might think of — the posters or the annual compliance-oriented, “you must take this course and check the box” — I don’t think is what we’re talking about here, at least not what I’m talking about. I think we’re talking about an ongoing capability of making users aware and making it part of the way that they approach their work for the company. Those things do need to be flexible and evolve over time. They’re not just static posters or kind of once a year and done. The kind of leadership that Jeff is talking about is excellent. Not everyone has it. I think you would be kind of the tip of the pyramid on that, but when you talk about the ability of a CSO or other security leader to strategize, to have awareness and be able to do forward thinking and conceptualization like that, those are very important skills. The builders of community and people that he was talking about are also part of that. Communication is critical. It’s so important to be able to listen and understand the needs of the business, persuade and build consensus. Those are maybe not the skills that a lot of people in security and technology leadership roles had. They might have gotten into those roles because they were good at security and technology. These are skills that are so important going forward. Maybe as we get to the final segments here, I’ll try to make those points because I think they’re extremely important.

 

Sanjog Aul [00:51:36]:

So, Jeff, when you look at your role and most CISOs at the top who are grappling with all of these different challenges, I’m sure they must be feeling lonely up there because the businesses, other business leaders, executive management may not understand the intricacies of the technology, but they definitely see the risks and even get more paranoid as they hear more breaches. So what is the support system that is needed at your level for you to be able to go out and build the right type of awareness and the behavioral change along with making the changes in technology and processes to eventually get to a point where you can say, yes, I can sleep at night? Perhaps I’m not sure if that’s going to happen, but

 

Jeffrey Wright [00:52:18]:

I don’t know that that day will come. Sanjog, your point is spot on, especially in security. The challenges are so multifaceted. The threat is oftentimes unpredictable; attackers don’t have to follow a release calendar or a QA review process. They can adapt on the fly and target organizations on a whim. Predicting who’s going to hit you next and how is often very difficult to do. Equally, your point around the complexity of the technology and the technical solution that you bring to bear against it is very valid. It’s difficult to explain; put it a different way, I find myself saying there is no silver bullet to this. There’s no piece of technology or portfolio of technology or combination of things that we can put in place that would really give anybody in my role the ability to look at another senior executive and say, “We’re good. We’ve got it covered.” It comes back to balancing your portfolio of capabilities, understanding the risk — not the threat, but as Derek said, what is the risk that we’re attempting to mitigate or control — and how much control do we want to exert over it. Then the CSOs have to step up and help advise on the right fuel mixture, the right selection of capabilities: people, process, and technology that can provide a measurable way of demonstrating that particular risk is being managed. It’s an ongoing and active dialogue. Awareness at an executive level may not necessarily take on the form of what email to open or what website not to browse. Awareness in that audience may be around the complexity of the challenge that we face and helping give them the tools and the forum to have these types of discussions, understand the threat, the risks and the capabilities that we can bring to bear to manage it. This awareness takes a different form depending on the audience. That’s what I would say.

 

Sanjog Aul [00:55:05]:

On behalf of the show and our listeners, I’d really like to thank you both Derek and Jeff for sharing your thoughts on how we could go about improving cybersecurity awareness and behavior.

 

Sanjog Aul [00:55:16]:

Very good. Happy to do it, and, listeners, please like us on Facebook, search for CIO Talk Radio, and be sure to follow us on Twitter. Thank you again for listening to CIO Talk Radio. This is Sanjog Aul, your talk show host. Till next

 

 

Contributors

Jeffrey Wright

Jeffrey Wright, VP & CISO, Allstate

Jeff Wright is Vice President and Chief Information Security Officer for Allstate Insurance Company. In this role he is responsible for the enterprise information security strategy to ensure the protection of Allstate information from all e... More   View all posts
Derek Brink

Derek Brink, Vice President, Research Fellow, IT Security and IT GRC, The Aberdeen Group

Derek Brink helps organizations to improve their security and compliance initiatives by researching, writing about and speaking about the people, processes and technologies that correspond most strongly with leading performance. He also hel... More   View all posts
Add Comment
Click here to post a comment

Advertisement

FWS - AWSMarketplaceFreshservice MPU 300X224
Jeffrey Wright