Friday, May 1, 2020
Patient Gardening
Wednesday, September 4, 2019
Measuring Training
Most organizations require all their users to undergo some form of cyber security awareness training, and most organizations squander their users' time and attention by trying to boil the ocean.
Rather than share practical skills for avoiding common online threat, the vast majority of security shops use their awareness training to test their colleagues on how well they can regurgitate the company security policy or jargon. Under this model, there is no good way to quantify the effectiveness of the training, or to see which parts worked and which could use some improvement. More important, most of the training I've seen doesn't address real-world security issues that the organization is grappling with. Instead, it deals mainly with policy and HR issues. Not only is it no fun to take, but it's impossible to know whether it does any good.
Instead of using a shotgun approach, what if you had your incident response team work with management to determine the issues behind the three or four most common real security incidents from the past year? Things that can be counted, and are quantifiable in terms of cost, labor, and damage to reputation. Things like phishing, NSFW web surfing, and overly permissive file shares.
Now build a training module around each issue you selected. Explain the risks, what the problem looks like, and how to avoid and report it. Use anonymized, real-world case studies from your organization to illustrate the issue. Rather than bore them with acronyms and policy jargon, engage your students by talking about things they care about - like downtime, loss of privacy data and revenue. This resonates: The reason the holiday bonus was smaller than usual was because we had to purchase Credit Monitoring for 10,000 customers whose data was stolen because of a phishing attack.
At the end of the year, compare the number of incidents between the last two years. If your training module is effective, the numbers around that incident category should have gone down. If so, work with your incident response team to identify a new issue to target. If you see the numbers for a particular incident type start to creep up again, you can rotate the corresponding module back into your training.
If, on the other hand, the numbers for a particular incident category aren't going down, or at least remaining static, that module may not be effective. At this point, you have a couple of options:
Solicit feedback from your users as to how the module could have been more effective.
Try attacking a different issue. It could be that training just doesn't prevent that type of incident.
Over time, you will develop a library of training modules for all of your most painful security issues. You can continue to expand and update them based on emerging threats. And even if you don't like the results, you can still quantify the business value and ROI of cyber security awareness training, enabling your management to make informed business decisions about the program.
Wednesday, April 10, 2019
Limitations
I'm not going to go into the Capability Maturity Model in this post - you can look it up yourself. I don't really like the idea of giving an organization a single score on their capabilities, because I think most organizations are great at some things and pretty terrible at others, and you lose a lot of resolution if you try to pack all of that into one step.
I do think that a lot of organizations are delusional about their capabilities. I recently read a Computer Weekly article by Warwick Ashford saying that 60% of the organizations they surveyed had had an outage due to digital certificates in the past year. Sixty percent of organizations are having trouble managing their certificates.
In case you hadn't heard, certificates are the foundation of the Secure Web. Browsers are starting to break sessions if the certs aren't good. In words of two syllables or less: If you can't do certs, you will fail at the sexy stuff, Stuff like automation, single-sign on, big data, AI, and all the other cutting-edge things your boss wants you to do this year.
Almost any next-gen technology you build is going to rely on your infrastructure, and if you're having trouble with foundational capabilities like certificate management, or DNS, or routing, you may want to seriously rethink your roadmap. Maybe it's time to stop fishing and cut bait for a while.
After all, a man's got to know his limitations.
Wednesday, April 3, 2019
Positions and Interests
Thursday, March 21, 2019
Responsiveness vs. reactivity.
Even though you know a fork isn't the right utensil for eating soup, rather than pause and search for a spoon, you try to compensate by working harder. You scoop up tiny forkfuls of soup as fast as you can so everyone can see you're working as hard as you can to empty the bowl. Tuesday, March 19, 2019
Intelligence Test
If you were a nation-state, how would you test a rival state's intelligence system? What if you fed them fake information, and then sat back and observed how quickly they reacted to it? You could measure your own effectiveness at disinformation at the same time you measured their response time. You'd also begin to understand how they react to different stimuli. Simply by forcing your adversary to react to non-existent issues would throw them off balance and create general malaise.
What if you made them question their tools? Got them to throw away perfectly good - maybe even best-of-breed - systems just because you were able to convince them they were no good, or had a bug?
Now, instead of moving forward, your rival is tied up replacing resources that work just fine - at a great cost in labor, cost, and time. All for nothing. They're operating at diminished capacity during the replacement, and may replaced something effective with something not-so-effective. And you've figured out what buttons to push to make them react, at virtually no cost.
Am I the only person who thinks this is a pretty efficient way to test an opponent's capabilities?
Wednesday, March 6, 2019
Flywheels and Bullets
There is never a single decision or action that will propel you to excellence. Success is incremental. Jim Collins, author of Good to Great, writes of what he calls the Flywheel Effect. Rather than thinking of work as a series of steps, think of it as a well-placed nudge to a wheel that is already in motion. If you exert the right degree of force at the right inflection point, you will increase the momentum. It will feel inevitable: if you do A, you almost can't avoid doing B, and C just follows naturally, and so on. This builds organic momentum. Slow and steady may win the game, but taking well-timed, calculated risks can provide exponential returns.
Tuesday, February 5, 2019
Tension, Desire, Fear
I just read a blog post by the ever-inspiring Seth Godin, and this part made me think about what's missing from cybersecurity:
Alas, awareness is not action.By now, everyone in your organization has gotten the cybersecurity memo. Everyone from the CEO to the person who maintains the grounds knows security is important, and want to do the right thing. It's condescending, maybe even counter-productive to treat our colleagues as though they've never heard about security. Take it to the next level by building the right combination of tension, desire, and fear to inspire our organizations to execute on security.
Everyone reading this is aware that Peru is a country. But that doesn’t mean you’ve visited recently, or have plans to go soon.
Everyone reading this is aware that turnips are a root vegetable. But knowing they exist doesn’t mean you’re going to have them for dinner.
Awareness is important, but it is insufficient.
Action comes from tension, desire and fear. Action is the hard part.
Most of us security people have the fear part down pat: if you don't do all the security things I tell you to, something really bad is going to happen. The problem is that we've probably been saying that for years, and nothing bad happened. The wolf never came, and even if it did, the bite didn't hurt that badly, so everybody stopped listening to to the Little Security Boy. We need to employ other strategies to inspire our leadership and colleagues to action.
One way to create tension is to make it easier to do the right thing than it is to keep doing the same, wrong thing. Try breaking the problem down into the smallest possible components. Analyze the work you want done. What is the logical first step? What would this process look like if it were easy? Identify the easy parts, the cheap parts, the fast parts. Once we've done a few small things, we can build on our success. Remember that it took years for things get to where they are now, so it's naive to think we can fix them overnight. What we can do is do something. We must do something. Today. Tomorrow. Every day. Start the ball rolling - if we can keep it rolling, pretty soon it will gain its own momentum. First we create the tension by making the work seem easy.
When we think of security, the term desire doesn't exactly jump out. Desire is a positive emotion, and we all have plenty of it. We desire to do a good job, to be recognized, to do the right thing. We desire less stress, less distraction, more wins. Everybody knows things could be better, security-wise - they want them to be better. But they don't know where to start until you create the tension by getting the ball rolling. Making progress - any progress, even if all we've done is stop the bleeding - starts a virtuous cycle in which the team starts to want to do more. Let's celebrate the work that's been done, no matter how tiny, and try not to remind the team about the mountain of work that still needs to be done. By focusing on the success, we create the desire to build on that success.
Let's stop talking to people as though they've never heard about cybersecurity. Let's stop playing the fear card, and build tension to fuel the desire to start moving our organization toward a more secure place.
Patient Gardening
I was pulling weeds in my garden last weekend, and it struck me that there are a lot of parallels between gardening and cybersecurity. I’m...
-
If you were a nation-state, how would you test a rival state's intelligence system? What if you fed them fake information, and then sat...
-
We security boffins love metrics. We measure compliance, performance, response times, and roll them all up into pretty dashboards so we ca...
-
Can people predict the future? The results of tarot or palm readings are often uncannily accurate, even though you know it's random. ...

