The Accidental Security Specialist, with David Shipley
Re-thinking The Human Factor with Bruce Hallas
Release Date: 03/17/2020
Re-thinking The Human Factor with Bruce Hallas
info_outline Key performance metricsRe-thinking The Human Factor with Bruce Hallas
In this episode we re-visit an earlier theme explored in this series. The theme of mesurement and metrics. The question of how to measure awareness, behaviour or culture is something we consistently come across here at Re-thinking the Human Factor when exploring opportunities to work with clients. There's an palpable feeling, across industry chatter, that there's a real lack of maturity when it comes to how we demonstrate the effectiveness of our effrots to influence employee awareness, behaviour and culture. However, there is hope. In this episode I talk with Bernie Smith. Bernie has a focus...
info_outline The security function's culture.Re-thinking The Human Factor with Bruce Hallas
In this episode we take a peek at the role of the security teams’ own culture and its impact on the broader organisational culture. This, is an important perspective, because whilst many commentators focus on influencing organisational culture they haven’t considered the role that the value and behaviours of the security team has in influencing positive security outcomes across the business. To help us explore this perspective, on cultural forces at play, we have a guest who knows a thing or two about how cultures are formed and influenced. Lianne Potter studied in social anthropology,...
info_outline An appointment with the Doctor to discuss culture, behaviour and decision making.Re-thinking The Human Factor with Bruce Hallas
If you’re a regular listener then you will have already met today’s guest Dr. Char Sample. Char is a force at work deep within the information security community. Char is a rarity, combining a deep knowledge of both the technical and human aspects of the challenges security professionals face when managing cyber security risks. Char and I go back a long way, to a horrible conference lunch in London, where her riveting conversation meant I didn’t have to eat what was on the plate in front of me. I have been forever grateful. That riveting conversation was all about our shared...
info_outline Insights from advertising for security awareness professionals.Re-thinking The Human Factor with Bruce Hallas
In this episode we are joined by a guest who has committed their career to the world of advertising agency work. Influencing target audiences awareness of products and stacking the odds in their clients favour, that the target audience will choose their product over their competitors. The challanges our guest has faced, over the years, are in many ways similar to those that education and awareness managers, for information security and data protection, now face.
info_outline A Human Resource view on Information Security Awareness and EducationRe-thinking The Human Factor with Bruce Hallas
The role of the human resources function, in the the overall process of employee awareness, behavioru and culture can't be under stated. In the early days of my research, at Re-thinking the Human Factor, it was very apparent that HR was a major stakeholder. From what I like to call KPI's clash, where stakeholders KPI's sometimes clash against each other, through to employee performance and development, and from HR processes such as starters, movers and leavers, through to organisational change. The HR department can add a lot of value to the process of delivering change in employee security...
info_outline Embracing Diverse Skills When Building an Effective Education and Awareness Team.Re-thinking The Human Factor with Bruce Hallas
When I first got involved in “information security” 20+ years ago, I found myself almost entirely surrounded by industry peers whose training and experience was in technology or technology disciplines. My training in law, marketing and finance, and my experience in business development, marketing, recruitment and even a stint in purchasing and supplies all seemed out of line with the world of IT security as it was called back then. As I came to understand, during my own research in human behaviour and culture, my lack of an education in technology meant I was culturally and even physically...
info_outline The Science Behind MetricsRe-thinking The Human Factor with Bruce Hallas
Finding relevent metrics, for security awareness, behaviour and culture has been a long standing challenge which the information security industry has struggled hard to address. Now, when I reflect on how I personally tackled metrics, around the human factor, before I kicked off my research programme here at Re-thinking the Human Factor, I recognise I had an in-mature approach. That approach focused on what data I knew I could get rather than what was useful. Some industry folks called this "vanity metrics." That's all changed now, and that change started off, with getting back to basics...
info_outline Insights from Educational Psychology for Information Security ProfessionalsRe-thinking The Human Factor with Bruce Hallas
Educating employees on their roles and responsilities when it comes to information security and data protection, is common sense, and, even if you don't think that's the case, it is, without a doubt, a regulatory obligation for many. So, what is "education" and what is going on in the world of learning and development which might help us to re-think the human factor? In this episode our guest, Teisa Marshik, a respected educational psychologist and passionate educator, shares how her's and her colleagues approach to educating learners is changing. We cover everything from how the effectiveness...
info_outline Understand the forces at play.Re-thinking The Human Factor with Bruce Hallas
What can those of us responsible for security awareness, behaviour and culture learn from a member of the Bloodhound Land Speed world record attempt team when it comes to overcoming the seemingly insurmountable challenges we face?
info_outlineThe Accidental Security Specialist, with David Shipley.
Living up to our promise to bring you fantastic guests, David Shipley joins us for Series 3, Episode 6 of the Re-Thinking the Human Factor Podcast. Time to go phishing so grab your rod.
David is a self professed accidental cyber security professional, but has spent time as a soldier, newspaper reporter and marketer. After a cyber hack within his company occurred, David grew increasingly interested in cyber security and was asked to take on this role within his company.
Currently based in Canada, David is an award-winning entrepreneur and head of Beauceron Security. Beauceron's holistic approach to measuring and reducing cyber risk brings together threat intelligence, user education and awareness, simulated attacks and real incident data into an easy-to-use and deploy cloud platform that transforms cybersecurity from an IT-centric issue into a pan-organization management opportunity.
AS YOU LISTEN TO THE EPISODE, IF YOU FIND YOURSELF WANTING TO IMPLEMENT SOME OF THE INSIGHTS YOU’RE GAINING BUT YOU FEEL YOU NEED A LITTLE HELP, PLEASE DO GET IN TOUCH WITH ME AT:
IN THIS EPISODE, DAVID SHIPLEY AND BRUCE HALLAS DISCUSS:
- The sheepdog effect.
- Turning the cyber victims into defenders.
- Empowering the person.
- The importance of driving behavioural reinforcement within a culture to keep positive cyber security behaviour thriving.
- Getting the metrics correct- Repeat clickers and what we can learn.
- Taking the time to make sure people really retain new cyber security-related information and behaviours.
- Phishing fallibility:
- Is someone’s emotional state a factor to be considered?
- The 8 emotional scale.
- Fear response, social hi-jacking and engineering.
- How time affects people’s behaviour during a 24 hour period.
- The power of keeping calm. Speed can often be your enemy.
- The Power Model - what it is and how it can be used to boost cyber-security awareness:
- People, environment, actions and resources.
- Creating an easy to use protocol to gauge involvement.
- Learning from each other. Building a solid support structure.
- Black box culture - going deeper into more effective cyber security training:
- Talking about issues without laying blame.
- The story of the mayor that got phished.
- Learning from mistakes in proactive ways. Rewarding right behaviour.
- Scoring people and then helping them improve their performance within the security culture.
- Compliance:
- Exceeding compliance via relative, contextual, timely informative videos.
- Treat your audience like adults.
- Using Surveying as a tool to generate better metrics around risk and awareness:
- The importance of your baseline and the importance of a good survey.
- How does bias affect survey answers and are there ways around it?
- Using video responses to surveying to offer training in weak spots and offer guidance and support to colleagues.
- Start a positive feedback loop.
- Phishing attacks and data strategy.
- Data gathering from ‘time to click’ data proves to be very fruitful at limiting risk.
- Huge amounts of data are available to be mined to design cyber security awareness and education pieces that change behaviour.
- Having a strategy for data gathering is crucial. Learning when people click leads to a defined process towards a positive security culture.
- Cyber Security Marketing.
- The same tools that marketing applies can be used when trying to form a new culture of awareness within a business.
- The same tools that marketing applies can be used when trying to form a new culture of awareness within a business.
- What is a KPI clash?
- Where is the cyber security industry failing?
- Not enough focus on the human factor.
- Not enough funding for training.
- Real meaningful change comes with data and planning correctly
- Data driven decision making around security awareness.
- The need for sharing resources exists to help strengthen the entire security industry.
RESOURCES AND TOPICS FOR FURTHER STUDY
MORE ABOUT DAVID SHIPLEY:
Please subscribe to the podcast in iTunes, and if you enjoyed this interview, please share with your friends and colleagues and leave a 5 star rating and review.
Thanks for listening and sharing.
Bruce & The Re-thinking the Human Factor Podcast Team