SlideShare uma empresa Scribd logo
1 de 38
Baixar para ler offline
SESSION ID:
#RSAC
Bikash Barai
Using Behavioral Psychology and
Science of Habit to Change User
Behavior
HUM-F03
Co-founder (Cigital India)
@bikashbarai1
#RSAC
Is Awareness Enough To Change
Human Behavior?
2
#RSAC
3
Credit: Abd Allah Foteih
#RSAC
Awareness vs Change Of Behavior
4
Example: Continued security training beyond the baseline are unlikely to be effective -
“Modifying Smartphone User Locking Behavior” – by Dirk et al (ACM – 2013)
Awareness
ChangeinBehavior
#RSAC
What Else Do We Need?
5
#RSAC
The Mystery of Eugene Pauly’s Brain ..
6
Dr. Lary R. Squire
University of California, San Diego
Image Source: http://whoville.ucsd.edu/about.html
#RSAC
Goal Directed System (Pre-Frontal Cortex)
Responsible for new or infrequent
behaviors
Guided by attitudes, goals, values,
knowledge
Conscious and deliberate
Slow
Habit System (Basal Ganglia)
Very fast. Does not require thought or
attention
Less conscious. More automatic
Goal Directed and Habit System
7
Credit: Neal et al – The Science of Habit…
#RSAC
40% of our daily actions are driven without thinking
Examples of Habits in action
Changing gears
Getting out of elevator in wrong floor
Tying Shoe knots
Bad habits in action
Checking phone/blackberry during the middle of sleep
Clicking phishing links
Writing down passwords in open
Habits in Action..
8
#RSAC
How To Build A New Habit?
9
#RSAC
Story of Pepsodent ..
10
https://upload.wikimedia.org/wikipedia/en/8/88/Pepsodent-0179c.jpg
#RSAC
Trigger – Routine – Reward ( & Craving )
11
Trigger:
Feel Tooth Film with
tongue
Routine:
Brushing Teeth
Reward:
Great Smile
Crave for
Tingling
Image Credit: Seth LemmonsImage Credit: Wikipediahttps://i.ytimg.com/vi/rf1Bs2XpwFI/maxresdefault.jpg
#RSAC
Step 1: Find a Predictable and Recurring Trigger
Step 2: Devise the new Routine/Habit
Step 3: Find the Reward
Practice, Practice, Practice without exceptions
Steps for Building New Habits
12
#RSAC
How To Change A Habit?
13
#RSAC
14
Old Habits
Never Die
#RSAC
Example – Changing A Habit
15
Trigger:
Boredom
Routine:
Have a Whisky
Reward:
Feel Happy
Image Credit: Wiki
#RSAC
Example – Changing A Habit
16
Trigger:
Boredom
New Routine:
Talk to a friend
Reward:
Feel Happy
Image Credit: Wiki
#RSAC
3 Steps for Changing Old Habits
Identify and Deconstruct the Habit
Find the Trigger
Find the “real hidden reward” – Experiment to discover
Find the Trigger-Routine-Reward-Craving model
Find an alternative routine to satisfy the “real hidden reward”
Practice. Practice. Practice.
#RSAC
“Hard Thing” about “Easy Things”..
18
#RSAC
Understanding Buffer Overflow - Easy
19
Finding A vulnerability - Hard
Writing A “Reliable” Exploit- Very Hard
#RSAC
Coke, McDonalds campaigns..
What is hard about it?
Finding a “Reliable” trigger and reward
Creating craving and making it stick
Hard or Easy?
20
#RSAC
Applying The Science Of Habit
21
In Information Security & Life..
#RSAC
Example 1: Create Habit of Locking Computer
Screen..
Goal: Locking system while leaving desk
Trigger – Getting up from chair/Leaving the system
Routine – Lock your computer
Reward – Feeling of security
Rehearse or Repeat at least 20 times
If you forget then go back to seat and repeat the routine
#RSAC
Example 2: Change the Habit of Writing Down
Password in Open Areas
Goal: Stop the habit of writing down password areas
Trigger – New password setting request
Old Routine – write down the password
New Routine – “write down the clue” or “Use a Scheme to generate new
passwords”
Reward – Feeling of security
Rehearse or Repeat
#RSAC
Example 3: Preventing Phishing
Old Habit
Trigger: Legitimate entity asks for personal details
Routine: Share the details
New Desired Habit
Trigger: Legitimate entity asks for personal details
New Routine: Validate the legitimacy of the entity
Practice. Practice. Practice
24
#RSAC
Example 4: Create Secure Coding Behavior
Goal – Ensuring coders use secure coding functions
Trigger – Typing a function
Old Routine – Type insecure function
New Routine – Use intervention method to prompt secure function
Enough practice
Automatic use of secure function
#RSAC
Habits in Day to Day Life..
Playing/Exercise everyday
Controlling anger outbursts..
#RSAC
Driving organizational change
27
#RSAC
7 Learning for Driving Organizational Change
Augment Awareness with a Habit Strategy
Utilize “Keystone Habit”
Certainty of negative incentive and not Severity has high impact
Group sharing has positive impact
Reduce friction or Create friction based on goals
Leverage a disaster
Start with a why
#RSAC
Current State of Research
29
#RSAC
Research on Habits and Beyond..
Research on Habits
Significant studies in the field of psychology, marketing, sports etc
Little or No research in areas related to IT security
30
#RSAC
References and Other Studies ..
Balleine et al – Goal directed instrumental action: contingency and incentive learning and their cortical
substrates
Kahneman – Thinking fast and slow
Duhigg- The power of habit
Neal et al – The pull of the past when do habits persist despite conflict with motives?
Rothman et al- Reflective and automotive processes in the initiation and maintenance of dietary change
Sheeran et al – Implementation intentions and repeated behavior..
Wood et al – A new look at habits and habit- goal interface
Wood et al- The habitual consumer
Wood et al- Habits in everyday life: thought emotion and action
31
#RSAC
Apply What You Learned..
32
#RSAC
Apply What You Learned
Next Week
Choose 1 habit that you want to change or build
Identify a small group for experiment
Experiment
First 3 months
Find the most important habits to change in your organization
Create an organization wide plan for habit change drills
Make people practice at least 20 to 30 times in a short time frame. (Group
activities, Simulation exercise, Wargames etc)
Measure the success of the program
#RSAC
After 6 months
Assess the success of the program based on the metrics defined
Reassess the risky and secure behavior and create a new program
34
#RSAC
Awareness Is Not Enough
35
Invest In Forming Lasting Habits
#RSAC
Practice Does Not Make Perfect
36
“Perfect Practice” Makes Perfect
#RSAC
Want To Engineer A Habit?
37
Let’s Meet At The Bar ..
#RSAC
Questions please..
bbarai@cigital.com
@bikashbarai1
38
Bikash Barai

Mais conteúdo relacionado

Destaque

3 Simple Habits of a Highly Effective Team
3 Simple Habits of a Highly Effective Team 3 Simple Habits of a Highly Effective Team
3 Simple Habits of a Highly Effective Team Andy Harjanto
 
Simple Weight Loss Tips - Secrets and Strategies of Losing and Maintaining We...
Simple Weight Loss Tips - Secrets and Strategies of Losing and Maintaining We...Simple Weight Loss Tips - Secrets and Strategies of Losing and Maintaining We...
Simple Weight Loss Tips - Secrets and Strategies of Losing and Maintaining We...Tanveer Padder
 
Seven Habits of Highly Effective Digital Marketers - Tops Tips for 2015!
Seven Habits of Highly Effective Digital Marketers - Tops Tips for 2015!Seven Habits of Highly Effective Digital Marketers - Tops Tips for 2015!
Seven Habits of Highly Effective Digital Marketers - Tops Tips for 2015!Digital Annexe
 
How should we measure habit? (And does it matter?)
How should we measure habit? (And does it matter?)How should we measure habit? (And does it matter?)
How should we measure habit? (And does it matter?)Reflect Project
 
Seven Habits of Highly Effective People
Seven Habits of Highly Effective PeopleSeven Habits of Highly Effective People
Seven Habits of Highly Effective PeopleTania Aslam
 
7 habits of highly effective people by stephen r. covey
7 habits of highly effective people by stephen r. covey7 habits of highly effective people by stephen r. covey
7 habits of highly effective people by stephen r. coveyAnuj Kumar
 
Habits at Work - Merci Victoria Grace, Growth, Slack - 2016 Habit Summit
Habits at Work - Merci Victoria Grace, Growth, Slack - 2016 Habit SummitHabits at Work - Merci Victoria Grace, Growth, Slack - 2016 Habit Summit
Habits at Work - Merci Victoria Grace, Growth, Slack - 2016 Habit SummitHabit Summit
 

Destaque (8)

20 Habits of Happy People
20 Habits of Happy People20 Habits of Happy People
20 Habits of Happy People
 
3 Simple Habits of a Highly Effective Team
3 Simple Habits of a Highly Effective Team 3 Simple Habits of a Highly Effective Team
3 Simple Habits of a Highly Effective Team
 
Simple Weight Loss Tips - Secrets and Strategies of Losing and Maintaining We...
Simple Weight Loss Tips - Secrets and Strategies of Losing and Maintaining We...Simple Weight Loss Tips - Secrets and Strategies of Losing and Maintaining We...
Simple Weight Loss Tips - Secrets and Strategies of Losing and Maintaining We...
 
Seven Habits of Highly Effective Digital Marketers - Tops Tips for 2015!
Seven Habits of Highly Effective Digital Marketers - Tops Tips for 2015!Seven Habits of Highly Effective Digital Marketers - Tops Tips for 2015!
Seven Habits of Highly Effective Digital Marketers - Tops Tips for 2015!
 
How should we measure habit? (And does it matter?)
How should we measure habit? (And does it matter?)How should we measure habit? (And does it matter?)
How should we measure habit? (And does it matter?)
 
Seven Habits of Highly Effective People
Seven Habits of Highly Effective PeopleSeven Habits of Highly Effective People
Seven Habits of Highly Effective People
 
7 habits of highly effective people by stephen r. covey
7 habits of highly effective people by stephen r. covey7 habits of highly effective people by stephen r. covey
7 habits of highly effective people by stephen r. covey
 
Habits at Work - Merci Victoria Grace, Growth, Slack - 2016 Habit Summit
Habits at Work - Merci Victoria Grace, Growth, Slack - 2016 Habit SummitHabits at Work - Merci Victoria Grace, Growth, Slack - 2016 Habit Summit
Habits at Work - Merci Victoria Grace, Growth, Slack - 2016 Habit Summit
 

Semelhante a Using Behavioral Psychology and Science of Habit to Change User Behavior

Keynote Session : Using Behavioral Psychology and Science of Habit to Change ...
Keynote Session : Using Behavioral Psychology and Science of Habit to Change ...Keynote Session : Using Behavioral Psychology and Science of Habit to Change ...
Keynote Session : Using Behavioral Psychology and Science of Habit to Change ...Priyanka Aash
 
From Human Intelligence to Machine Intelligence
From Human Intelligence to Machine IntelligenceFrom Human Intelligence to Machine Intelligence
From Human Intelligence to Machine IntelligenceNUS-ISS
 
Qualitative Research Session with Piyul Mukherjee & Pia Mollback Verbic
Qualitative Research Session with Piyul Mukherjee & Pia Mollback VerbicQualitative Research Session with Piyul Mukherjee & Pia Mollback Verbic
Qualitative Research Session with Piyul Mukherjee & Pia Mollback VerbicNorthpoint Centre of Learning
 
Requirement_and_Discovery_JUNE_2011
Requirement_and_Discovery_JUNE_2011Requirement_and_Discovery_JUNE_2011
Requirement_and_Discovery_JUNE_2011uchitha bandara
 
Add creativity to your decision process
Add creativity to your decision processAdd creativity to your decision process
Add creativity to your decision processSiddharth Kumar Kadamb
 
How to build a superstar self-organizing team?
How to build a superstar self-organizing team?How to build a superstar self-organizing team?
How to build a superstar self-organizing team?Oleksandr Lutsaievskyi
 
People, brain and change in the Manifesto for Agile Software Development
People, brain and change in the Manifesto for Agile Software DevelopmentPeople, brain and change in the Manifesto for Agile Software Development
People, brain and change in the Manifesto for Agile Software DevelopmentIvo Peksens
 
ORGB 300-005Organizational BehaviorLeBow College of Business.docx
ORGB 300-005Organizational BehaviorLeBow College of Business.docxORGB 300-005Organizational BehaviorLeBow College of Business.docx
ORGB 300-005Organizational BehaviorLeBow College of Business.docxgerardkortney
 
APF orlando diy survey workshop 071114 final
APF orlando diy survey workshop 071114 finalAPF orlando diy survey workshop 071114 final
APF orlando diy survey workshop 071114 finalMike Courtney
 
Shaping Tomorrow - Getting Started - Introduction
Shaping Tomorrow - Getting Started - IntroductionShaping Tomorrow - Getting Started - Introduction
Shaping Tomorrow - Getting Started - IntroductionKerry Richardson
 
Using Problem Solving Skills To Get A Job
Using Problem Solving Skills To Get A JobUsing Problem Solving Skills To Get A Job
Using Problem Solving Skills To Get A JobGary Clement
 
DTI-Module 4.pptx
DTI-Module 4.pptxDTI-Module 4.pptx
DTI-Module 4.pptxSHANKARRCse
 
Instructional Design Today: What We Really Need to Know as Practitioners, Res...
Instructional Design Today: What We Really Need to Know as Practitioners, Res...Instructional Design Today: What We Really Need to Know as Practitioners, Res...
Instructional Design Today: What We Really Need to Know as Practitioners, Res...Karl Kapp
 
Unit_-_3_Org._Dcn._making_in_changing_env_.pdf
Unit_-_3_Org._Dcn._making_in_changing_env_.pdfUnit_-_3_Org._Dcn._making_in_changing_env_.pdf
Unit_-_3_Org._Dcn._making_in_changing_env_.pdfsandhyashakya13
 
Seven Habits For Highly Successful Use Of Organization
Seven Habits For Highly Successful Use Of OrganizationSeven Habits For Highly Successful Use Of Organization
Seven Habits For Highly Successful Use Of OrganizationSherryanne Meyer, SHRM-SCP
 
Kanban India 2022 | Badre Srinivasan | Culture Hack# - Decision Filters
Kanban India 2022 | Badre Srinivasan | Culture Hack# - Decision FiltersKanban India 2022 | Badre Srinivasan | Culture Hack# - Decision Filters
Kanban India 2022 | Badre Srinivasan | Culture Hack# - Decision FiltersLeanKanbanIndia
 

Semelhante a Using Behavioral Psychology and Science of Habit to Change User Behavior (20)

Keynote Session : Using Behavioral Psychology and Science of Habit to Change ...
Keynote Session : Using Behavioral Psychology and Science of Habit to Change ...Keynote Session : Using Behavioral Psychology and Science of Habit to Change ...
Keynote Session : Using Behavioral Psychology and Science of Habit to Change ...
 
From Human Intelligence to Machine Intelligence
From Human Intelligence to Machine IntelligenceFrom Human Intelligence to Machine Intelligence
From Human Intelligence to Machine Intelligence
 
Qualitative Research Session with Piyul Mukherjee & Pia Mollback Verbic
Qualitative Research Session with Piyul Mukherjee & Pia Mollback VerbicQualitative Research Session with Piyul Mukherjee & Pia Mollback Verbic
Qualitative Research Session with Piyul Mukherjee & Pia Mollback Verbic
 
Requirement_and_Discovery_JUNE_2011
Requirement_and_Discovery_JUNE_2011Requirement_and_Discovery_JUNE_2011
Requirement_and_Discovery_JUNE_2011
 
Add creativity to your decision process
Add creativity to your decision processAdd creativity to your decision process
Add creativity to your decision process
 
How to build a superstar self-organizing team?
How to build a superstar self-organizing team?How to build a superstar self-organizing team?
How to build a superstar self-organizing team?
 
Unit 1.pptx
Unit 1.pptxUnit 1.pptx
Unit 1.pptx
 
People, brain and change in the Manifesto for Agile Software Development
People, brain and change in the Manifesto for Agile Software DevelopmentPeople, brain and change in the Manifesto for Agile Software Development
People, brain and change in the Manifesto for Agile Software Development
 
ORGB 300-005Organizational BehaviorLeBow College of Business.docx
ORGB 300-005Organizational BehaviorLeBow College of Business.docxORGB 300-005Organizational BehaviorLeBow College of Business.docx
ORGB 300-005Organizational BehaviorLeBow College of Business.docx
 
3 classification
3  classification3  classification
3 classification
 
APF orlando diy survey workshop 071114 final
APF orlando diy survey workshop 071114 finalAPF orlando diy survey workshop 071114 final
APF orlando diy survey workshop 071114 final
 
Shaping Tomorrow - Getting Started - Introduction
Shaping Tomorrow - Getting Started - IntroductionShaping Tomorrow - Getting Started - Introduction
Shaping Tomorrow - Getting Started - Introduction
 
Using Problem Solving Skills To Get A Job
Using Problem Solving Skills To Get A JobUsing Problem Solving Skills To Get A Job
Using Problem Solving Skills To Get A Job
 
DTI-Module 4.pptx
DTI-Module 4.pptxDTI-Module 4.pptx
DTI-Module 4.pptx
 
Ch14
Ch14Ch14
Ch14
 
Instructional Design Today: What We Really Need to Know as Practitioners, Res...
Instructional Design Today: What We Really Need to Know as Practitioners, Res...Instructional Design Today: What We Really Need to Know as Practitioners, Res...
Instructional Design Today: What We Really Need to Know as Practitioners, Res...
 
Unit_-_3_Org._Dcn._making_in_changing_env_.pdf
Unit_-_3_Org._Dcn._making_in_changing_env_.pdfUnit_-_3_Org._Dcn._making_in_changing_env_.pdf
Unit_-_3_Org._Dcn._making_in_changing_env_.pdf
 
Baworld adapting to whats happening
Baworld adapting to whats happeningBaworld adapting to whats happening
Baworld adapting to whats happening
 
Seven Habits For Highly Successful Use Of Organization
Seven Habits For Highly Successful Use Of OrganizationSeven Habits For Highly Successful Use Of Organization
Seven Habits For Highly Successful Use Of Organization
 
Kanban India 2022 | Badre Srinivasan | Culture Hack# - Decision Filters
Kanban India 2022 | Badre Srinivasan | Culture Hack# - Decision FiltersKanban India 2022 | Badre Srinivasan | Culture Hack# - Decision Filters
Kanban India 2022 | Badre Srinivasan | Culture Hack# - Decision Filters
 

Mais de Priyanka Aash

Digital Personal Data Protection (DPDP) Practical Approach For CISOs
Digital Personal Data Protection (DPDP) Practical Approach For CISOsDigital Personal Data Protection (DPDP) Practical Approach For CISOs
Digital Personal Data Protection (DPDP) Practical Approach For CISOsPriyanka Aash
 
Verizon Breach Investigation Report (VBIR).pdf
Verizon Breach Investigation Report (VBIR).pdfVerizon Breach Investigation Report (VBIR).pdf
Verizon Breach Investigation Report (VBIR).pdfPriyanka Aash
 
Top 10 Security Risks .pptx.pdf
Top 10 Security Risks .pptx.pdfTop 10 Security Risks .pptx.pdf
Top 10 Security Risks .pptx.pdfPriyanka Aash
 
Simplifying data privacy and protection.pdf
Simplifying data privacy and protection.pdfSimplifying data privacy and protection.pdf
Simplifying data privacy and protection.pdfPriyanka Aash
 
Generative AI and Security (1).pptx.pdf
Generative AI and Security (1).pptx.pdfGenerative AI and Security (1).pptx.pdf
Generative AI and Security (1).pptx.pdfPriyanka Aash
 
EVERY ATTACK INVOLVES EXPLOITATION OF A WEAKNESS.pdf
EVERY ATTACK INVOLVES EXPLOITATION OF A WEAKNESS.pdfEVERY ATTACK INVOLVES EXPLOITATION OF A WEAKNESS.pdf
EVERY ATTACK INVOLVES EXPLOITATION OF A WEAKNESS.pdfPriyanka Aash
 
Cyber Truths_Are you Prepared version 1.1.pptx.pdf
Cyber Truths_Are you Prepared version 1.1.pptx.pdfCyber Truths_Are you Prepared version 1.1.pptx.pdf
Cyber Truths_Are you Prepared version 1.1.pptx.pdfPriyanka Aash
 
Cyber Crisis Management.pdf
Cyber Crisis Management.pdfCyber Crisis Management.pdf
Cyber Crisis Management.pdfPriyanka Aash
 
CISOPlatform journey.pptx.pdf
CISOPlatform journey.pptx.pdfCISOPlatform journey.pptx.pdf
CISOPlatform journey.pptx.pdfPriyanka Aash
 
Chennai Chapter.pptx.pdf
Chennai Chapter.pptx.pdfChennai Chapter.pptx.pdf
Chennai Chapter.pptx.pdfPriyanka Aash
 
Cloud attack vectors_Moshe.pdf
Cloud attack vectors_Moshe.pdfCloud attack vectors_Moshe.pdf
Cloud attack vectors_Moshe.pdfPriyanka Aash
 
Stories From The Web 3 Battlefield
Stories From The Web 3 BattlefieldStories From The Web 3 Battlefield
Stories From The Web 3 BattlefieldPriyanka Aash
 
Lessons Learned From Ransomware Attacks
Lessons Learned From Ransomware AttacksLessons Learned From Ransomware Attacks
Lessons Learned From Ransomware AttacksPriyanka Aash
 
Emerging New Threats And Top CISO Priorities In 2022 (Chennai)
Emerging New Threats And Top CISO Priorities In 2022 (Chennai)Emerging New Threats And Top CISO Priorities In 2022 (Chennai)
Emerging New Threats And Top CISO Priorities In 2022 (Chennai)Priyanka Aash
 
Emerging New Threats And Top CISO Priorities In 2022 (Mumbai)
Emerging New Threats And Top CISO Priorities In 2022 (Mumbai)Emerging New Threats And Top CISO Priorities In 2022 (Mumbai)
Emerging New Threats And Top CISO Priorities In 2022 (Mumbai)Priyanka Aash
 
Emerging New Threats And Top CISO Priorities in 2022 (Bangalore)
Emerging New Threats And Top CISO Priorities in 2022 (Bangalore)Emerging New Threats And Top CISO Priorities in 2022 (Bangalore)
Emerging New Threats And Top CISO Priorities in 2022 (Bangalore)Priyanka Aash
 
Cloud Security: Limitations of Cloud Security Groups and Flow Logs
Cloud Security: Limitations of Cloud Security Groups and Flow LogsCloud Security: Limitations of Cloud Security Groups and Flow Logs
Cloud Security: Limitations of Cloud Security Groups and Flow LogsPriyanka Aash
 
Cyber Security Governance
Cyber Security GovernanceCyber Security Governance
Cyber Security GovernancePriyanka Aash
 

Mais de Priyanka Aash (20)

Digital Personal Data Protection (DPDP) Practical Approach For CISOs
Digital Personal Data Protection (DPDP) Practical Approach For CISOsDigital Personal Data Protection (DPDP) Practical Approach For CISOs
Digital Personal Data Protection (DPDP) Practical Approach For CISOs
 
Verizon Breach Investigation Report (VBIR).pdf
Verizon Breach Investigation Report (VBIR).pdfVerizon Breach Investigation Report (VBIR).pdf
Verizon Breach Investigation Report (VBIR).pdf
 
Top 10 Security Risks .pptx.pdf
Top 10 Security Risks .pptx.pdfTop 10 Security Risks .pptx.pdf
Top 10 Security Risks .pptx.pdf
 
Simplifying data privacy and protection.pdf
Simplifying data privacy and protection.pdfSimplifying data privacy and protection.pdf
Simplifying data privacy and protection.pdf
 
Generative AI and Security (1).pptx.pdf
Generative AI and Security (1).pptx.pdfGenerative AI and Security (1).pptx.pdf
Generative AI and Security (1).pptx.pdf
 
EVERY ATTACK INVOLVES EXPLOITATION OF A WEAKNESS.pdf
EVERY ATTACK INVOLVES EXPLOITATION OF A WEAKNESS.pdfEVERY ATTACK INVOLVES EXPLOITATION OF A WEAKNESS.pdf
EVERY ATTACK INVOLVES EXPLOITATION OF A WEAKNESS.pdf
 
DPDP Act 2023.pdf
DPDP Act 2023.pdfDPDP Act 2023.pdf
DPDP Act 2023.pdf
 
Cyber Truths_Are you Prepared version 1.1.pptx.pdf
Cyber Truths_Are you Prepared version 1.1.pptx.pdfCyber Truths_Are you Prepared version 1.1.pptx.pdf
Cyber Truths_Are you Prepared version 1.1.pptx.pdf
 
Cyber Crisis Management.pdf
Cyber Crisis Management.pdfCyber Crisis Management.pdf
Cyber Crisis Management.pdf
 
CISOPlatform journey.pptx.pdf
CISOPlatform journey.pptx.pdfCISOPlatform journey.pptx.pdf
CISOPlatform journey.pptx.pdf
 
Chennai Chapter.pptx.pdf
Chennai Chapter.pptx.pdfChennai Chapter.pptx.pdf
Chennai Chapter.pptx.pdf
 
Cloud attack vectors_Moshe.pdf
Cloud attack vectors_Moshe.pdfCloud attack vectors_Moshe.pdf
Cloud attack vectors_Moshe.pdf
 
Stories From The Web 3 Battlefield
Stories From The Web 3 BattlefieldStories From The Web 3 Battlefield
Stories From The Web 3 Battlefield
 
Lessons Learned From Ransomware Attacks
Lessons Learned From Ransomware AttacksLessons Learned From Ransomware Attacks
Lessons Learned From Ransomware Attacks
 
Emerging New Threats And Top CISO Priorities In 2022 (Chennai)
Emerging New Threats And Top CISO Priorities In 2022 (Chennai)Emerging New Threats And Top CISO Priorities In 2022 (Chennai)
Emerging New Threats And Top CISO Priorities In 2022 (Chennai)
 
Emerging New Threats And Top CISO Priorities In 2022 (Mumbai)
Emerging New Threats And Top CISO Priorities In 2022 (Mumbai)Emerging New Threats And Top CISO Priorities In 2022 (Mumbai)
Emerging New Threats And Top CISO Priorities In 2022 (Mumbai)
 
Emerging New Threats And Top CISO Priorities in 2022 (Bangalore)
Emerging New Threats And Top CISO Priorities in 2022 (Bangalore)Emerging New Threats And Top CISO Priorities in 2022 (Bangalore)
Emerging New Threats And Top CISO Priorities in 2022 (Bangalore)
 
Cloud Security: Limitations of Cloud Security Groups and Flow Logs
Cloud Security: Limitations of Cloud Security Groups and Flow LogsCloud Security: Limitations of Cloud Security Groups and Flow Logs
Cloud Security: Limitations of Cloud Security Groups and Flow Logs
 
Cyber Security Governance
Cyber Security GovernanceCyber Security Governance
Cyber Security Governance
 
Ethical Hacking
Ethical HackingEthical Hacking
Ethical Hacking
 

Último

SALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICESSALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICESmohitsingh558521
 
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptxPasskey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptxLoriGlavin3
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024BookNet Canada
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationSlibray Presentation
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupFlorian Wilhelm
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Mattias Andersson
 
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxLoriGlavin3
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024Lorenzo Miniero
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfAlex Barbosa Coqueiro
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .Alan Dix
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek SchlawackFwdays
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity PlanDatabarracks
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
DSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine TuningDSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine TuningLars Bell
 
Moving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfMoving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfLoriGlavin3
 
The State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxThe State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxLoriGlavin3
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubKalema Edgar
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024Stephanie Beckett
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfAddepto
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr BaganFwdays
 

Último (20)

SALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICESSALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICES
 
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptxPasskey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptx
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck Presentation
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project Setup
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?
 
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdf
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity Plan
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
DSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine TuningDSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine Tuning
 
Moving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfMoving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdf
 
The State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxThe State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptx
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding Club
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdf
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan
 

Using Behavioral Psychology and Science of Habit to Change User Behavior

  • 1. SESSION ID: #RSAC Bikash Barai Using Behavioral Psychology and Science of Habit to Change User Behavior HUM-F03 Co-founder (Cigital India) @bikashbarai1
  • 2. #RSAC Is Awareness Enough To Change Human Behavior? 2
  • 4. #RSAC Awareness vs Change Of Behavior 4 Example: Continued security training beyond the baseline are unlikely to be effective - “Modifying Smartphone User Locking Behavior” – by Dirk et al (ACM – 2013) Awareness ChangeinBehavior
  • 5. #RSAC What Else Do We Need? 5
  • 6. #RSAC The Mystery of Eugene Pauly’s Brain .. 6 Dr. Lary R. Squire University of California, San Diego Image Source: http://whoville.ucsd.edu/about.html
  • 7. #RSAC Goal Directed System (Pre-Frontal Cortex) Responsible for new or infrequent behaviors Guided by attitudes, goals, values, knowledge Conscious and deliberate Slow Habit System (Basal Ganglia) Very fast. Does not require thought or attention Less conscious. More automatic Goal Directed and Habit System 7 Credit: Neal et al – The Science of Habit…
  • 8. #RSAC 40% of our daily actions are driven without thinking Examples of Habits in action Changing gears Getting out of elevator in wrong floor Tying Shoe knots Bad habits in action Checking phone/blackberry during the middle of sleep Clicking phishing links Writing down passwords in open Habits in Action.. 8
  • 9. #RSAC How To Build A New Habit? 9
  • 10. #RSAC Story of Pepsodent .. 10 https://upload.wikimedia.org/wikipedia/en/8/88/Pepsodent-0179c.jpg
  • 11. #RSAC Trigger – Routine – Reward ( & Craving ) 11 Trigger: Feel Tooth Film with tongue Routine: Brushing Teeth Reward: Great Smile Crave for Tingling Image Credit: Seth LemmonsImage Credit: Wikipediahttps://i.ytimg.com/vi/rf1Bs2XpwFI/maxresdefault.jpg
  • 12. #RSAC Step 1: Find a Predictable and Recurring Trigger Step 2: Devise the new Routine/Habit Step 3: Find the Reward Practice, Practice, Practice without exceptions Steps for Building New Habits 12
  • 13. #RSAC How To Change A Habit? 13
  • 15. #RSAC Example – Changing A Habit 15 Trigger: Boredom Routine: Have a Whisky Reward: Feel Happy Image Credit: Wiki
  • 16. #RSAC Example – Changing A Habit 16 Trigger: Boredom New Routine: Talk to a friend Reward: Feel Happy Image Credit: Wiki
  • 17. #RSAC 3 Steps for Changing Old Habits Identify and Deconstruct the Habit Find the Trigger Find the “real hidden reward” – Experiment to discover Find the Trigger-Routine-Reward-Craving model Find an alternative routine to satisfy the “real hidden reward” Practice. Practice. Practice.
  • 18. #RSAC “Hard Thing” about “Easy Things”.. 18
  • 19. #RSAC Understanding Buffer Overflow - Easy 19 Finding A vulnerability - Hard Writing A “Reliable” Exploit- Very Hard
  • 20. #RSAC Coke, McDonalds campaigns.. What is hard about it? Finding a “Reliable” trigger and reward Creating craving and making it stick Hard or Easy? 20
  • 21. #RSAC Applying The Science Of Habit 21 In Information Security & Life..
  • 22. #RSAC Example 1: Create Habit of Locking Computer Screen.. Goal: Locking system while leaving desk Trigger – Getting up from chair/Leaving the system Routine – Lock your computer Reward – Feeling of security Rehearse or Repeat at least 20 times If you forget then go back to seat and repeat the routine
  • 23. #RSAC Example 2: Change the Habit of Writing Down Password in Open Areas Goal: Stop the habit of writing down password areas Trigger – New password setting request Old Routine – write down the password New Routine – “write down the clue” or “Use a Scheme to generate new passwords” Reward – Feeling of security Rehearse or Repeat
  • 24. #RSAC Example 3: Preventing Phishing Old Habit Trigger: Legitimate entity asks for personal details Routine: Share the details New Desired Habit Trigger: Legitimate entity asks for personal details New Routine: Validate the legitimacy of the entity Practice. Practice. Practice 24
  • 25. #RSAC Example 4: Create Secure Coding Behavior Goal – Ensuring coders use secure coding functions Trigger – Typing a function Old Routine – Type insecure function New Routine – Use intervention method to prompt secure function Enough practice Automatic use of secure function
  • 26. #RSAC Habits in Day to Day Life.. Playing/Exercise everyday Controlling anger outbursts..
  • 28. #RSAC 7 Learning for Driving Organizational Change Augment Awareness with a Habit Strategy Utilize “Keystone Habit” Certainty of negative incentive and not Severity has high impact Group sharing has positive impact Reduce friction or Create friction based on goals Leverage a disaster Start with a why
  • 29. #RSAC Current State of Research 29
  • 30. #RSAC Research on Habits and Beyond.. Research on Habits Significant studies in the field of psychology, marketing, sports etc Little or No research in areas related to IT security 30
  • 31. #RSAC References and Other Studies .. Balleine et al – Goal directed instrumental action: contingency and incentive learning and their cortical substrates Kahneman – Thinking fast and slow Duhigg- The power of habit Neal et al – The pull of the past when do habits persist despite conflict with motives? Rothman et al- Reflective and automotive processes in the initiation and maintenance of dietary change Sheeran et al – Implementation intentions and repeated behavior.. Wood et al – A new look at habits and habit- goal interface Wood et al- The habitual consumer Wood et al- Habits in everyday life: thought emotion and action 31
  • 32. #RSAC Apply What You Learned.. 32
  • 33. #RSAC Apply What You Learned Next Week Choose 1 habit that you want to change or build Identify a small group for experiment Experiment First 3 months Find the most important habits to change in your organization Create an organization wide plan for habit change drills Make people practice at least 20 to 30 times in a short time frame. (Group activities, Simulation exercise, Wargames etc) Measure the success of the program
  • 34. #RSAC After 6 months Assess the success of the program based on the metrics defined Reassess the risky and secure behavior and create a new program 34
  • 35. #RSAC Awareness Is Not Enough 35 Invest In Forming Lasting Habits
  • 36. #RSAC Practice Does Not Make Perfect 36 “Perfect Practice” Makes Perfect
  • 37. #RSAC Want To Engineer A Habit? 37 Let’s Meet At The Bar ..