SlideShare uma empresa Scribd logo
The Unintended
Consequences of
Beating Users
with Carrot Sticks
Radical
Thoughts on
Security Reform
Quick Definitions &
Background
• Positive
• Encouraging
• Motivating
• Indemnification
• Reduced premiums
• Praise / Celebration
• Bribe vs Reward
• Negative
• Punishing
• (de?)Motivating
• Regulations
• Enforcement activities
• HIPAA and PKI
• Some security programs
Consequences
(Intended / Unintended)
Impact
• Positive
• Negative
• Neutral
Story: Airline Seatbelts
• Seatbelts on taxi...
• Seatbelts in the air...
• Consequences?
• Impact?
Peltzman Effect
Action
Consequence
Decision
!
!
?
Uncertainty Applies!
:)
:|
:(
Impact
Unintended
Consequences
• Fines vs Safe Harbor
• Ubiquitous encryption
• Humiliation vs Enablement
Sidebar: Education,
NCLB, & Enablement
• Enablement culture
• Training vs Education
• How do you measure
teacher performance?
"Careful. We don't want
to learn from this."
-Bill Watterson
Psychology & The
Human Paradox Gap
What’s the Problem?
• Does society as a
whole "get it"?
• What about your
organization?
• How about
everyone in this
room?
Sidebar: FishNet Report
• Decision-makers say top spend
priorities are firewalls, AV, authN, and
anti-malware.
• Same people say top threats are mobile
computing, social networks, and cloud.
W T F ? ! ? ! ?
h/t: http://1raindrop.typepad.com/1_raindrop/2010/10/reconcile-this.html
"If a man is offered a fact which goes against his
instincts, he will scrutinize it closely, and unless the
evidence is overwhelming, he will refuse to believe it.
If, on the other hand, he is offered something which
affords a reason for acting in accordance to his
instincts, he will accept it even on the slightest
evidence. The origin of myths is explained in this
way.” --Bertrand Russell
On... BIAS
"Facts are meaningless. You
could use facts to prove
anything that's even remotely
true!" --Homer Simpson
*The Human Paradox Gap
Image Source: http://www.theninjacamp.com/lifestyle/lifestyle.html
*HPG: Credited to Michael Santarcangelo
www.securitycatalyst.com/learn
Impact
Action
Consequence
Decision
!
!
?
:)
:|
:(Uncertainty Applies!
HPG: Distance
between Action &
Impact.
More on HPG...
• Tew: “The key to success
is massive failure.”
• In engineering, failure
teaches lessons!
• If there’s no connection
between action and
impact, then what’s the
motivation for change?
Recent Research
From IEEE Computer...
• Social pressure
is useful
• Intent to
comply is vital
• Sanctions
better than
rewards
By Mikko Siponen , Seppo Pahnila , M. Adam Mahmood
Issue Date: February 2010, pp. 64-71
Additional Thoughts...
• Ultimately about
narrowing HPG
• Visibility, ease of
compliance key
• Rewards overused,
depreciated?
From Click-It or Ticket...
• Seat belt use
increased over time
• Increased perception
of enforcement
• Favorable attitudes
Source: Lance Spitzner, http://www.securingthehuman.org/blog/ticket-or-click-it/
Some Thoughts...
• HPG was narrowed
• Correlated vs Causal
• What about generational
changes?
• What about other
programs?
On... STATISTICS
"Do not put your faith in what statistics
say until you have carefully considered
what they do not say." --William W. Watt
"There are three kinds of
lies: lies, damned lies and
statistics." --Leonard H.
Courtney (misattributed by
Samuel Clemens to Disraeli)
On... FRAMING
"The greatest
challenge to any
thinker is stating the
problem in a way that
will allow a solution."
--Bertrand Russell
"Living in a vacuum sucks."
--Adrienne E. Gusoff
Some Thoughts...
Policies
• Not all policies are equal!
• “Best” practices?
• What about process?
• What’s the objective?
Awareness Training
• “Best” practices?
• Closing the HPG?
• Just annually?
• Measuring success?
Survivability &
Sustainability
• Engineer for
resilience
• Expect failures
• Optimize for
growth!
• Green -> Blue
Sidebar: Survivability
• Hoff’s 3 Rs:
• Resistance
• Recognition
• Recovery
• Defensibility &
Recoverability
• Civilization: West vs. East
Integrated Security
Practices
• Build security in...
• Add to job descriptions...
• Part of performance...
Do you really need a
dedicated security team?
Risk Management +
Threat Modeling
• Evidence-based & quantitative risk
• Threat modeling w/ scenarios
• Business processes!
On... APPROACHES
"Tradition is what
you resort to when
you don't have the
time or the money to
do it right." --Kurt
Herbert Alder
"An ounce of action
is worth a ton of
theory." --Ralph
Waldo Emerson
Success Strategies
S U M M A R Y
1. Narrow the HPG
2. Model Success
3. Culture Change
4. Sensible & Automatic
5. More Carrots
6. Build Security In
7. Go Blue: Sustainability
Ben Tomhave
@falconsview
btomhave@geminisecurity.com
http://www.secureconsulting.net/
END.

Mais conteúdo relacionado

Mais procurados

vBrownBag Presentation
vBrownBag PresentationvBrownBag Presentation
vBrownBag Presentation
Jon Hildebrand
 
Digitalpresentation
DigitalpresentationDigitalpresentation
Digitalpresentation
zsobes22793
 
"Security on the Brain" Security & Risk Psychology Workshop Nov 2013
"Security on the Brain" Security & Risk Psychology Workshop Nov 2013"Security on the Brain" Security & Risk Psychology Workshop Nov 2013
"Security on the Brain" Security & Risk Psychology Workshop Nov 2013
Adrian Wright
 

Mais procurados (12)

How to Help Managers Counter Unconscious Bias at Work
How to Help Managers Counter Unconscious Bias at WorkHow to Help Managers Counter Unconscious Bias at Work
How to Help Managers Counter Unconscious Bias at Work
 
Nudge
NudgeNudge
Nudge
 
Class Lecture: Knowledge Work, Leadership and Social indentity
Class Lecture: Knowledge Work, Leadership and Social indentityClass Lecture: Knowledge Work, Leadership and Social indentity
Class Lecture: Knowledge Work, Leadership and Social indentity
 
Unconscious bias webinar presentation
Unconscious bias webinar presentationUnconscious bias webinar presentation
Unconscious bias webinar presentation
 
vBrownBag Presentation
vBrownBag PresentationvBrownBag Presentation
vBrownBag Presentation
 
Entrepreneurial Psychology
Entrepreneurial PsychologyEntrepreneurial Psychology
Entrepreneurial Psychology
 
Behavioural economics (and beyond: a presentation to Which? magazine
Behavioural economics (and beyond: a presentation to Which? magazineBehavioural economics (and beyond: a presentation to Which? magazine
Behavioural economics (and beyond: a presentation to Which? magazine
 
Unconscious Bias: A Brief Introduction
Unconscious Bias: A Brief IntroductionUnconscious Bias: A Brief Introduction
Unconscious Bias: A Brief Introduction
 
Big idea: Towards the end of the Unconscious Bias?
Big idea: Towards the end of the Unconscious Bias?Big idea: Towards the end of the Unconscious Bias?
Big idea: Towards the end of the Unconscious Bias?
 
Digitalpresentation
DigitalpresentationDigitalpresentation
Digitalpresentation
 
"Security on the Brain" Security & Risk Psychology Workshop Nov 2013
"Security on the Brain" Security & Risk Psychology Workshop Nov 2013"Security on the Brain" Security & Risk Psychology Workshop Nov 2013
"Security on the Brain" Security & Risk Psychology Workshop Nov 2013
 
The intelligent player realises the team is the real star
The intelligent player realises the team is the real starThe intelligent player realises the team is the real star
The intelligent player realises the team is the real star
 

Semelhante a The Unintended Consequences of Beating Users with Carrot Sticks: Radical Thoughts on Security Reform

Brighttalk reason 114 for learning math - final
Brighttalk   reason 114 for learning math - finalBrighttalk   reason 114 for learning math - final
Brighttalk reason 114 for learning math - final
Andrew White
 
Crowd-programmed initiatives (Dr Adrian Flint, Uni Bristol, and Chris Meyer z...
Crowd-programmed initiatives (Dr Adrian Flint, Uni Bristol, and Chris Meyer z...Crowd-programmed initiatives (Dr Adrian Flint, Uni Bristol, and Chris Meyer z...
Crowd-programmed initiatives (Dr Adrian Flint, Uni Bristol, and Chris Meyer z...
ALNAP
 
Action to empathy
Action to empathyAction to empathy
Action to empathy
lmittler
 
2021 IWC presentation: Risk, SOCs and Mitigations: Cognitive Security is Comi...
2021 IWC presentation: Risk, SOCs and Mitigations: Cognitive Security is Comi...2021 IWC presentation: Risk, SOCs and Mitigations: Cognitive Security is Comi...
2021 IWC presentation: Risk, SOCs and Mitigations: Cognitive Security is Comi...
Sara-Jayne Terp
 
Preventing Bullying and Harassment Through Diversity and Inclusion in the Wor...
Preventing Bullying and Harassment Through Diversity and Inclusion in the Wor...Preventing Bullying and Harassment Through Diversity and Inclusion in the Wor...
Preventing Bullying and Harassment Through Diversity and Inclusion in the Wor...
Case IQ
 
Critical Thinking as a Skill for Democracy: A Case of Citizen Engagement with...
Critical Thinking as a Skill for Democracy: A Case of Citizen Engagement with...Critical Thinking as a Skill for Democracy: A Case of Citizen Engagement with...
Critical Thinking as a Skill for Democracy: A Case of Citizen Engagement with...
DIPRC2019
 

Semelhante a The Unintended Consequences of Beating Users with Carrot Sticks: Radical Thoughts on Security Reform (20)

Carrot stick-consequences-app secdc-2010
Carrot stick-consequences-app secdc-2010Carrot stick-consequences-app secdc-2010
Carrot stick-consequences-app secdc-2010
 
Co-Presented: YOU are the Alpha and Omega of a Secure Future (Kottova / Dray)...
Co-Presented: YOU are the Alpha and Omega of a Secure Future (Kottova / Dray)...Co-Presented: YOU are the Alpha and Omega of a Secure Future (Kottova / Dray)...
Co-Presented: YOU are the Alpha and Omega of a Secure Future (Kottova / Dray)...
 
Megatrends and the forward-looking leader
Megatrends and the forward-looking leaderMegatrends and the forward-looking leader
Megatrends and the forward-looking leader
 
Brighttalk reason 114 for learning math - final
Brighttalk   reason 114 for learning math - finalBrighttalk   reason 114 for learning math - final
Brighttalk reason 114 for learning math - final
 
Crowd-programmed initiatives (Dr Adrian Flint, Uni Bristol, and Chris Meyer z...
Crowd-programmed initiatives (Dr Adrian Flint, Uni Bristol, and Chris Meyer z...Crowd-programmed initiatives (Dr Adrian Flint, Uni Bristol, and Chris Meyer z...
Crowd-programmed initiatives (Dr Adrian Flint, Uni Bristol, and Chris Meyer z...
 
Systemic Learning Analytics Symposium, October 10th 2013
Systemic Learning Analytics Symposium, October 10th 2013Systemic Learning Analytics Symposium, October 10th 2013
Systemic Learning Analytics Symposium, October 10th 2013
 
Data and ethics Training
Data and ethics TrainingData and ethics Training
Data and ethics Training
 
Action to empathy
Action to empathyAction to empathy
Action to empathy
 
Effective Cybersecurity Communication Skills
Effective Cybersecurity Communication SkillsEffective Cybersecurity Communication Skills
Effective Cybersecurity Communication Skills
 
Educating Policy Makers and Telling Our Story
Educating Policy Makers and Telling Our StoryEducating Policy Makers and Telling Our Story
Educating Policy Makers and Telling Our Story
 
What's Next for the Future?
What's Next for the Future?What's Next for the Future?
What's Next for the Future?
 
Engineering Economic Security
Engineering Economic SecurityEngineering Economic Security
Engineering Economic Security
 
The BIG ONE 2.0 - HouSecCon
The BIG ONE 2.0 - HouSecConThe BIG ONE 2.0 - HouSecCon
The BIG ONE 2.0 - HouSecCon
 
2015 Think KMGMA
2015 Think KMGMA2015 Think KMGMA
2015 Think KMGMA
 
Risk, SOCs, and mitigations: cognitive security is coming of age
Risk, SOCs, and mitigations: cognitive security is coming of ageRisk, SOCs, and mitigations: cognitive security is coming of age
Risk, SOCs, and mitigations: cognitive security is coming of age
 
2021 IWC presentation: Risk, SOCs and Mitigations: Cognitive Security is Comi...
2021 IWC presentation: Risk, SOCs and Mitigations: Cognitive Security is Comi...2021 IWC presentation: Risk, SOCs and Mitigations: Cognitive Security is Comi...
2021 IWC presentation: Risk, SOCs and Mitigations: Cognitive Security is Comi...
 
Preventing Bullying and Harassment Through Diversity and Inclusion in the Wor...
Preventing Bullying and Harassment Through Diversity and Inclusion in the Wor...Preventing Bullying and Harassment Through Diversity and Inclusion in the Wor...
Preventing Bullying and Harassment Through Diversity and Inclusion in the Wor...
 
How to Not Destroy the World - the Ethics of Web Design
How to Not Destroy the World - the Ethics of Web DesignHow to Not Destroy the World - the Ethics of Web Design
How to Not Destroy the World - the Ethics of Web Design
 
2015 think ida expo
2015 think ida expo2015 think ida expo
2015 think ida expo
 
Critical Thinking as a Skill for Democracy: A Case of Citizen Engagement with...
Critical Thinking as a Skill for Democracy: A Case of Citizen Engagement with...Critical Thinking as a Skill for Democracy: A Case of Citizen Engagement with...
Critical Thinking as a Skill for Democracy: A Case of Citizen Engagement with...
 

Último

Search and Society: Reimagining Information Access for Radical Futures
Search and Society: Reimagining Information Access for Radical FuturesSearch and Society: Reimagining Information Access for Radical Futures
Search and Society: Reimagining Information Access for Radical Futures
Bhaskar Mitra
 
Future Visions: Predictions to Guide and Time Tech Innovation, Peter Udo Diehl
Future Visions: Predictions to Guide and Time Tech Innovation, Peter Udo DiehlFuture Visions: Predictions to Guide and Time Tech Innovation, Peter Udo Diehl
Future Visions: Predictions to Guide and Time Tech Innovation, Peter Udo Diehl
Peter Udo Diehl
 

Último (20)

IoT Analytics Company Presentation May 2024
IoT Analytics Company Presentation May 2024IoT Analytics Company Presentation May 2024
IoT Analytics Company Presentation May 2024
 
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
 
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
 
Search and Society: Reimagining Information Access for Radical Futures
Search and Society: Reimagining Information Access for Radical FuturesSearch and Society: Reimagining Information Access for Radical Futures
Search and Society: Reimagining Information Access for Radical Futures
 
Speed Wins: From Kafka to APIs in Minutes
Speed Wins: From Kafka to APIs in MinutesSpeed Wins: From Kafka to APIs in Minutes
Speed Wins: From Kafka to APIs in Minutes
 
IESVE for Early Stage Design and Planning
IESVE for Early Stage Design and PlanningIESVE for Early Stage Design and Planning
IESVE for Early Stage Design and Planning
 
Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...
Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...
Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...
 
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered QualitySoftware Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
 
IOS-PENTESTING-BEGINNERS-PRACTICAL-GUIDE-.pptx
IOS-PENTESTING-BEGINNERS-PRACTICAL-GUIDE-.pptxIOS-PENTESTING-BEGINNERS-PRACTICAL-GUIDE-.pptx
IOS-PENTESTING-BEGINNERS-PRACTICAL-GUIDE-.pptx
 
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
 
SOQL 201 for Admins & Developers: Slice & Dice Your Org’s Data With Aggregate...
SOQL 201 for Admins & Developers: Slice & Dice Your Org’s Data With Aggregate...SOQL 201 for Admins & Developers: Slice & Dice Your Org’s Data With Aggregate...
SOQL 201 for Admins & Developers: Slice & Dice Your Org’s Data With Aggregate...
 
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
 
Salesforce Adoption – Metrics, Methods, and Motivation, Antone Kom
Salesforce Adoption – Metrics, Methods, and Motivation, Antone KomSalesforce Adoption – Metrics, Methods, and Motivation, Antone Kom
Salesforce Adoption – Metrics, Methods, and Motivation, Antone Kom
 
In-Depth Performance Testing Guide for IT Professionals
In-Depth Performance Testing Guide for IT ProfessionalsIn-Depth Performance Testing Guide for IT Professionals
In-Depth Performance Testing Guide for IT Professionals
 
Bits & Pixels using AI for Good.........
Bits & Pixels using AI for Good.........Bits & Pixels using AI for Good.........
Bits & Pixels using AI for Good.........
 
AI revolution and Salesforce, Jiří Karpíšek
AI revolution and Salesforce, Jiří KarpíšekAI revolution and Salesforce, Jiří Karpíšek
AI revolution and Salesforce, Jiří Karpíšek
 
UiPath Test Automation using UiPath Test Suite series, part 1
UiPath Test Automation using UiPath Test Suite series, part 1UiPath Test Automation using UiPath Test Suite series, part 1
UiPath Test Automation using UiPath Test Suite series, part 1
 
How world-class product teams are winning in the AI era by CEO and Founder, P...
How world-class product teams are winning in the AI era by CEO and Founder, P...How world-class product teams are winning in the AI era by CEO and Founder, P...
How world-class product teams are winning in the AI era by CEO and Founder, P...
 
Future Visions: Predictions to Guide and Time Tech Innovation, Peter Udo Diehl
Future Visions: Predictions to Guide and Time Tech Innovation, Peter Udo DiehlFuture Visions: Predictions to Guide and Time Tech Innovation, Peter Udo Diehl
Future Visions: Predictions to Guide and Time Tech Innovation, Peter Udo Diehl
 
Measures in SQL (a talk at SF Distributed Systems meetup, 2024-05-22)
Measures in SQL (a talk at SF Distributed Systems meetup, 2024-05-22)Measures in SQL (a talk at SF Distributed Systems meetup, 2024-05-22)
Measures in SQL (a talk at SF Distributed Systems meetup, 2024-05-22)
 

The Unintended Consequences of Beating Users with Carrot Sticks: Radical Thoughts on Security Reform