Imagine that you are the head of security awareness at an organization (not a stretch for some) and have been charged with getting people to report issues to the help desk. You decide, in your infinite wisdom, to encourage them to report issues to the help desk by giving them $1 each time they report a valid problem. The week after implementing the new reward program the number of issues reported to the help desk has increased 100 fold. You …

Read more »

Many of the products out there would lead you to believe that anyone with Word can write a newsletter but this is not the case. Think about it, you are asking someone to voluntarily take time out of his or her day, or even potential free/personal time, to read a document about security. If done right, you can have a captive audience that happily takes the time to read your content. If done wrong, then all your hard work turns …

Read more »

Now that we know how to effectively pair a problem behavior with a solution, what happens when the problem behavior is the product of more than one reason? For example, several organizations identify ‘falling for phishing attacks’ as one of the biggest problems they have with users in their organization. A cultural assessment reveals that not only do several users have a hard time identifying the ever changing phishing emails, but they also don’t see them as very dangerous, and …

Read more »

After reading through my last 3 blogs I realized that something needs to be clarified. Even though surveying and interviewing humans is required in order to create successful security architecture it’s HARD! There are so many things that influence answers, cause people to tense up and shut down, or just not understand what your questions are asking. In fact making a survey is so involved that I had to take a 4-month graduate level course on it before they would …

Read more »

The process of evaluating and changing an organizations user behavior can be a large and daunting task –similar to looking at a picture of the milk-way galaxy with the task of counting the rings around all the planets- but rest assured it can be broken down into a very simple process to follow. Over the next few weeks I will talk about how to identify key behaviors through assessment of an organizations culture, how to identify what about that culture …

Read more »