[00:01.320 --> 00:04.140] Let's all learn about how we can strengthen security programs. [00:04.560 --> 00:05.500] It's a good idea. [00:05.940 --> 00:06.700] It's novel. [00:07.760 --> 00:09.320] So first, a little bit about me. [00:10.700 --> 00:14.960] My name is Chris, but in every room I go to, there's like 100 Chrises. [00:15.140 --> 00:16.140] It never fails. [00:16.500 --> 00:18.700] So I just tell people to call me Davis. [00:18.880 --> 00:19.280] It's easier. [00:19.440 --> 00:22.920] There's apparently a lot less Davises, even though I feel like that's a more common name. [00:24.160 --> 00:27.240] My experience, I was a veteran of the United States Marine Corps. [00:27.400 --> 00:31.340] I served four and a half years as a satellite telecommunications technician. [00:31.660 --> 00:34.380] I spent three and a half years stationed in Okinawa, Japan. [00:34.640 --> 00:39.080] I got to see the world starting with Southeast Asia? [00:39.260 --> 00:39.800] Southwest Asia? [00:39.860 --> 00:40.960] I can never remember the difference. [00:42.240 --> 00:43.420] But yeah, it's a good time. [00:43.860 --> 00:49.160] I have about 15 years of combined experience in IT, the help desk, and cybersecurity. [00:49.160 --> 00:53.360] I have a bachelor's in computer science, where I learned about how computers work. [00:53.520 --> 00:56.580] And then a master's in cybersecurity, where I learned how people work. [00:57.700 --> 01:02.340] I also hold a CISSP, along with a litany of other certifications. [01:03.120 --> 01:10.160] CompTIA A+, Net+, Sec+, CYSA+, Project+, I don't know. [01:10.260 --> 01:10.780] There's so many. [01:10.860 --> 01:11.340] I forget. [01:12.720 --> 01:21.760] My interests, you can typically find me traveling, taking pictures with my Pixel 8 Pro, or sliding sideways around curves in my 93 Toyota Chaser. [01:22.060 --> 01:25.760] They never made those in America, so I'll forgive you for not knowing what that looks like. [01:26.040 --> 01:29.920] Now, if I was smart, I would have brought a picture, but I'm not smart. [01:30.100 --> 01:31.480] No one's ever called me a smart man. [01:32.380 --> 01:44.960] Also, I really like Tasty Tacos, and I'd love it if after this presentation, if you know of a place that's anywhere close to here that sells Tasty Tacos, you come talk to me, because I need some real good New York Tacos. [01:46.620 --> 01:51.280] Currently, I work as a security compliance engineer for Amazie.io. [01:52.080 --> 01:54.620] We're a small company based out of Zurich, Switzerland. [01:56.520 --> 01:59.500] And, yeah, we host websites for folks all around the world. [01:59.980 --> 02:01.800] I've been here for a little over five years. [02:02.060 --> 02:04.360] I started as a platform engineer and moved my way up. [02:04.360 --> 02:13.540] I was one of the only folks interested in security in our tiny little 50-person team, and I was the guy who started our security team from the ground up. [02:14.020 --> 02:22.960] We started with ISO 27001, then we moved on to SOC 2 Type 2, and now there's like, I don't know, five more on my desk waiting for me when I get back. [02:23.500 --> 02:26.180] But my main focus now is governance, risk, and compliance. [02:26.320 --> 02:29.180] So really control and people-focused. [02:30.660 --> 02:32.760] All right, let's get into the beef of the talk. [02:32.760 --> 02:34.740] So, security. [02:35.180 --> 02:36.700] Security is a people problem. [02:37.020 --> 02:44.760] We can have all the tech we want, but at the end of the day, every security program is only as strong as its weakest link. [02:44.980 --> 02:50.800] And most folks who know security know that people are oftentimes the weakest link. [02:53.200 --> 02:56.240] Security policies and procedures, they're just one facet. [02:56.380 --> 02:58.580] We have to ensure that people actually follow them. [02:58.580 --> 03:02.880] We have to ensure that people actually care and know why they're following them. [03:03.060 --> 03:10.680] Because you can tell people, don't step on my grass, but nobody's going to understand why they can't step on the grass, and they're going to step on the grass because they just don't care. [03:12.400 --> 03:15.940] And simple awareness training and technological monitoring doesn't go far enough. [03:16.060 --> 03:17.560] We have to engage with our communities. [03:17.820 --> 03:23.160] We have to tell these people why they should do this, and help make sure that they're on the right path to doing it. [03:24.420 --> 03:29.320] Time and again, whenever a company's breached, people say something like, they were phished. [03:29.700 --> 03:31.120] Did they do any awareness training? [03:31.540 --> 03:32.620] Oh, they did. [03:33.060 --> 03:36.220] Well, somebody still clicked, so that obviously failed. [03:36.700 --> 03:39.140] When they keep going, humans are awful. [03:39.440 --> 03:40.540] Awareness training is worthless. [03:41.280 --> 03:44.100] We need to double down on technology to protect our users. [03:44.940 --> 03:49.940] Technology is great, but at the end of the day, the technology still exists for the convenience of humans. [03:50.580 --> 03:54.600] Humans make up a significant layer of our security stack, and we need to treat them as such. [03:54.840 --> 03:59.440] We need to leverage them to enhance our security, not detract from it. [03:59.880 --> 04:04.300] But, it's a difficult task, because there are things that stop us. [04:04.680 --> 04:08.580] Fear, bad habits, and shadow IT are all things that we need to worry about. [04:09.900 --> 04:11.140] Oh, let's see. [04:11.860 --> 04:13.820] Let's talk about the human element for a moment. [04:14.000 --> 04:17.140] We spent so much time talking about tools, we can talk about humans. [04:18.000 --> 04:23.860] The reality of things is, every employee that we'll ever have is human. [04:24.100 --> 04:26.740] I mean, until Skynet takes over, but that hasn't happened yet. [04:27.360 --> 04:29.300] And humans are prone to making mistakes. [04:29.580 --> 04:32.900] They can be small mistakes, like clicking on a phishing link. [04:33.240 --> 04:37.900] They can also be pretty big mistakes, like misconfiguring a server and leaking our data. [04:38.360 --> 04:39.520] I mean, nobody wants that. [04:39.940 --> 04:41.080] But I do have a question. [04:41.080 --> 04:49.680] How many of you in here have ever wrote a bad commit, pushed some code, changed a rule, such that production just died? [04:50.420 --> 04:51.140] How many? [04:52.660 --> 04:54.520] Yeah, it's a pretty long list. [04:54.680 --> 05:03.240] And I'd argue the people who didn't raise their hands, you either don't have rights to commit, you're too junior to have those rights, or you're just not technical. [05:04.360 --> 05:12.400] So would it surprise you at all to know that 95% of all successful cyber attacks are caused by human error? [05:12.880 --> 05:17.820] I'm gonna move my laptop a bit here, so I can actually see my slides, because they're too small on my screen. [05:20.320 --> 05:21.780] Yeah, they... [05:23.220 --> 05:24.740] Oh, I threw myself off. [05:24.860 --> 05:25.240] Oh, no. [05:25.960 --> 05:33.840] So, yeah, 95% of all successful cyber attacks, at their root, are caused by human error. [05:35.160 --> 05:37.080] And that's something that we can control. [05:37.320 --> 05:39.020] That's something that we can fix. [05:39.260 --> 05:41.060] That's a problem that we can solve. [05:41.300 --> 05:42.580] We can teach our users. [05:42.860 --> 05:46.040] We can show them better ways to deal with the problems at hand. [05:46.620 --> 05:48.080] That's a thing that we can fix. [05:49.300 --> 05:52.660] It's a very large number, and it's something that we have control over. [05:53.420 --> 05:57.200] One of the other problems we have talking about humans is their perception of security. [05:57.660 --> 05:59.940] They might view it as complex and intimidating. [06:00.540 --> 06:03.760] It's hard to understand giant policies. [06:04.000 --> 06:08.500] I know for a fact, I wrote our policies when we got ISO 27001. [06:08.680 --> 06:11.440] There's 113 pages of policies we wrote. [06:11.680 --> 06:14.540] And it covers all sorts of garbage that I don't even care about. [06:14.540 --> 06:19.040] But we have to have them because that's what the industry says we have to have. [06:19.240 --> 06:21.840] We have to tell you, you can't use removable media. [06:22.040 --> 06:24.540] Please don't pick up USB drives at conferences. [06:25.060 --> 06:28.200] We have to tell you that you should always use the VPN. [06:28.600 --> 06:33.160] I mean, there's a litany of things we have to tell you, and it's information overload all the time. [06:33.160 --> 06:40.920] And that directly leads to errors, especially when you're put under stressful situations or you're under pressure to perform. [06:42.340 --> 06:48.940] And especially if your first day the security team tells you, oh yeah, here's a Google Drive folder. [06:49.240 --> 06:49.740] Read these. [06:49.940 --> 06:50.760] Come back when you're done. [06:51.240 --> 06:52.020] No thanks. [06:52.660 --> 06:53.340] Nobody's gonna. [06:53.720 --> 06:54.600] I mean, I wouldn't. [06:54.740 --> 06:56.440] I'd tell you I did, but I wouldn't. [06:57.420 --> 06:59.780] We also have to deal with diverse skill levels. [06:59.980 --> 07:07.320] We have employees with varying levels of professional and security knowledge, which increases the likelihood for mistakes. [07:07.520 --> 07:10.000] And you would think that those are two different things. [07:10.120 --> 07:13.620] You would think that an experienced engineer would be less of a security problem. [07:13.760 --> 07:15.860] But that is absolutely not the case. [07:16.240 --> 07:18.120] Experienced engineers think they know everything. [07:18.120 --> 07:23.940] And inexperienced engineers are so afraid to press enter that sometimes they make mistakes, too. [07:24.360 --> 07:26.960] They find themselves at both ends of the spectrum. [07:27.240 --> 07:34.100] So just because they're a knowledge, a skilled individual contributor, doesn't always mean that they're security minded. [07:35.300 --> 07:40.440] And the last thing, just because we're aware, doesn't mean we care. [07:41.700 --> 07:47.340] Like I was saying earlier, compliance requires annual cybersecurity training for all of our employees. [07:47.340 --> 07:49.120] Which, come on. [07:49.940 --> 07:52.520] Sure, it teaches people about relevant security topics. [07:52.720 --> 08:03.000] But if anybody who's affiliated with the DOD or has been at any point in their life knows about that weird guy that's like, don't do this, it's terrible. [08:03.560 --> 08:06.860] He says things like, don't click links in the emails. [08:07.260 --> 08:08.940] Don't use removable media. [08:09.320 --> 08:11.060] Don't write your passwords down. [08:11.440 --> 08:17.100] It's just, after you tell people these things hundreds and hundreds and hundreds of times, they don't want to listen. [08:17.240 --> 08:17.800] They don't care. [08:18.300 --> 08:23.480] We could find some way to make it engaging, but at the end of the day, we're still delivering the same old talks the same old way. [08:24.980 --> 08:30.300] So remember, just because employees receive training about risks that they face, doesn't mean they care. [08:32.720 --> 08:33.900] Where's my... there. [08:35.800 --> 08:38.040] So let's talk a little bit about security culture. [08:39.140 --> 08:40.420] First, what is it? [08:40.420 --> 08:53.780] To paraphrase the International Civil Aviation Organization, it's defined as the set of values, shared beliefs, and behaviors that determine how an organization's employees approach and prioritize security in their daily activities. [08:54.130 --> 09:00.840] It encompasses attitudes towards security policies, practices, and the overall commitment to protecting the organization's assets. [09:01.160 --> 09:03.360] I sound like I'm reading Merriam-Webster for a reason. [09:03.520 --> 09:05.760] I just wanted to like... that's the definition. [09:06.320 --> 09:12.180] But to put it more simply, and in my own words, it's where employees' attitudes meet your policies and procedures. [09:12.540 --> 09:14.720] Because, like I said, employees need to care. [09:15.100 --> 09:18.580] So when we're looking at security culture, we should ask some questions. [09:19.540 --> 09:21.560] The first is about awareness and education. [09:22.280 --> 09:27.540] Are we taking steps to inform employees about the latest security threats and best practices? [09:28.140 --> 09:30.180] Are they receiving regular training at all? [09:30.360 --> 09:31.600] Do they get annual training? [09:31.800 --> 09:32.560] Weekly training? [09:32.720 --> 09:33.400] Do they get anything? [09:33.400 --> 09:35.940] Because, in some companies, they don't. [09:36.880 --> 09:39.600] We should ask about our users' behavior and attitude. [09:39.980 --> 09:44.440] Do your employees regularly interact with security team members? [09:44.580 --> 09:46.420] Or do they only see them during audits? [09:46.540 --> 09:51.360] Or when an incident happens and they have to come deal with the crap that these users have caused? [09:52.440 --> 09:56.440] Does the responsibility for security live only with the IT and the security team? [09:56.560 --> 09:59.260] Or are your users actually trying to be secure? [10:00.960 --> 10:02.960] Next, we talk about policies and procedures. [10:03.360 --> 10:04.600] I really wish I could just... [10:04.600 --> 10:05.060] Oh, there we go. [10:05.640 --> 10:07.100] Are your policies clear? [10:07.280 --> 10:08.300] Are they easy to follow? [10:08.560 --> 10:09.280] Are they actionable? [10:09.740 --> 10:12.140] Do they support and reinforce best practices? [10:12.400 --> 10:15.600] Or do they meander and say a bunch of things but actually... [10:15.600 --> 10:17.460] Do they talk a lot and say nothing? [10:19.720 --> 10:20.700] Communication and reporting. [10:20.700 --> 10:25.240] Do your employees feel comfortable talking to members of the security team? [10:25.520 --> 10:31.920] Are your security team members regularly updating employees about things that are going on in the company or in the world? [10:32.120 --> 10:33.720] Because those are big deals. [10:34.460 --> 10:37.240] And the last, leadership and support. [10:37.560 --> 10:41.600] Does leadership make a model for people to follow? [10:41.600 --> 10:43.560] Is leadership following these rules? [10:43.780 --> 10:46.040] Or does leadership say, do as I say, not as I do? [10:47.260 --> 10:50.520] Do they provide resources and support for the security program? [10:50.780 --> 10:53.560] Or is it, ah, security is a cost center. [10:53.640 --> 10:54.300] We don't have money. [10:54.620 --> 10:55.560] Deal with what you got. [10:55.880 --> 10:56.480] Talk to people. [10:57.220 --> 11:00.720] Well, hey, if that's where you find yourself, this talks for you. [11:03.080 --> 11:06.260] So, we kind of discussed what a security culture is. [11:06.540 --> 11:09.260] Let's talk about what a bad security culture looks like. [11:09.400 --> 11:14.080] Because, for me, it's a lot easier to tell you what a bad one looks like than a good one. [11:14.100 --> 11:15.840] Because I've lived the bad ones. [11:16.880 --> 11:19.640] The first big thing, lack of training and awareness. [11:20.140 --> 11:24.220] You just don't provide regular and updated security training to your employees. [11:25.000 --> 11:28.760] Leaving your employees completely unaware of phishing tactics. [11:28.760 --> 11:31.240] They regularly click on malicious links. [11:31.240 --> 11:33.300] They compromise the organization's security. [11:33.520 --> 11:36.760] And they waste the IT team's time trying to deal with this stuff. [11:37.640 --> 11:39.620] Another one, disengage leadership. [11:39.940 --> 11:43.020] Leadership doesn't prioritize or participate in security initiatives. [11:43.240 --> 11:46.240] And they tell the team that security isn't important to them. [11:47.240 --> 11:52.380] Because if the new guy sees the CEO saying, ah, it doesn't apply to me. [11:52.640 --> 11:53.720] Well, what's he going to think? [11:53.880 --> 11:55.460] He's going to think it doesn't apply to him either. [11:58.380 --> 11:59.200] Let's see. [12:00.020 --> 12:02.040] Next is siloed security efforts. [12:02.820 --> 12:06.260] Security is seen as the sole responsibility of the IT or security team. [12:06.540 --> 12:08.380] And nobody else takes ownership. [12:08.640 --> 12:12.080] Nobody else says, well, I could have chosen not to click that link. [12:12.080 --> 12:13.280] Or I could have thought a little bit. [12:13.320 --> 12:14.800] Or I could have checked the email address. [12:15.080 --> 12:16.280] Nobody says things like that. [12:16.720 --> 12:21.720] And the last one, my least favorite, is a fear-based reporting environment. [12:21.720 --> 12:28.680] This is where employees are straight up afraid to report security incidents or issues around the company. [12:28.920 --> 12:31.900] Because they're afraid they'll get punished or reprimanded. [12:32.200 --> 12:36.040] And a good example of this is an employee falling for a phishing scam. [12:36.040 --> 12:37.400] They know they got phished. [12:37.560 --> 12:38.680] They just don't want to tell you. [12:38.980 --> 12:40.800] Because if they tell you, they might get fired. [12:41.760 --> 12:43.480] Because they are a super admin. [12:43.760 --> 12:47.440] And those credentials that just got phished, they're good. [12:47.680 --> 12:49.740] They're pretty good for people who shouldn't have them. [12:51.360 --> 12:54.200] And if they would have just talked to you, you could have avoided all of this. [12:54.200 --> 12:55.920] You could have just rotated their password. [12:56.200 --> 12:58.000] Told them to change things. [12:58.680 --> 12:59.680] Been right on your way. [13:00.100 --> 13:01.080] But that didn't happen. [13:01.980 --> 13:06.280] It took me like two hours to get ChatGPT to generate this image, by the way. [13:06.460 --> 13:11.800] It is really difficult to make ChatGPT generate an image of a guy sweeping a mistake under a rug. [13:12.040 --> 13:13.340] I dare you to try it. [13:13.460 --> 13:14.140] It's difficult. [13:15.660 --> 13:18.380] Also, it started out as a lady, but then I thought that was too... [13:20.220 --> 13:27.860] Anyway, so we've talked about bad security cultures, and I really want to talk about fear. [13:28.160 --> 13:32.220] How can a bad security culture really instill fear in employees? [13:32.540 --> 13:34.260] What are the different ways that can happen? [13:34.620 --> 13:36.740] So the first is fear of punishment. [13:37.180 --> 13:41.900] Concerns about disciplinary actions, losing your job, a negative performance review. [13:42.340 --> 13:45.160] Any of that for a mistake that you make with security. [13:45.160 --> 13:48.480] It just leads to under-reporting and hiding mistakes. [13:48.720 --> 13:52.240] And when employees have to hide things, security fails. [13:53.300 --> 13:55.980] Because the whole point is for us not to hide things. [13:56.540 --> 13:58.200] The next is fear of blame. [13:58.900 --> 14:03.760] Anxiety about being singled out or blamed for security breaches or vulnerabilities. [14:04.400 --> 14:08.360] It reduces people's willingness to take responsibility and participate. [14:09.380 --> 14:10.660] A fear of judgment. [14:10.660 --> 14:16.840] Worry about being judged or ridiculed by your peers and your supervisors for lack of your knowledge in a domain. [14:17.020 --> 14:20.140] It just discourages people from asking questions or seeking help. [14:20.540 --> 14:25.840] One of the important things that I look for when I interview folks are three words. [14:26.080 --> 14:27.240] I don't know. [14:27.900 --> 14:30.400] I ask incredibly difficult questions. [14:31.020 --> 14:32.480] And I don't expect... [14:32.480 --> 14:34.120] I don't expect the right answer. [14:34.320 --> 14:37.580] I expect at some point this person will say, I don't know. [14:37.960 --> 14:40.680] Because if you're afraid to say, I don't know. [14:40.980 --> 14:45.940] If you think you know everything, there will come a time where you will find you are wrong. [14:48.660 --> 14:49.620] Let's see. [14:49.880 --> 14:53.080] Next is fear of complexity. [14:53.420 --> 14:55.000] Like we were talking about earlier. [14:55.500 --> 15:01.720] Intimidation by the complexion of your security policies, procedures, and technologies can lead to avoidance of them altogether. [15:02.200 --> 15:04.180] And that avoidance will cause gaps. [15:04.480 --> 15:07.720] And those gaps, they cost money and time. [15:08.460 --> 15:09.600] Time's the big one. [15:10.380 --> 15:11.700] Fear of uncertainty. [15:12.580 --> 15:15.000] Uncertainty of an organization... [15:20.420 --> 15:20.980] Oops. [15:21.240 --> 15:22.140] Sorry about that. [15:26.000 --> 15:27.840] So I skipped retribution, huh? [15:28.700 --> 15:29.300] Okay. [15:29.580 --> 15:30.340] Thanks for keeping track. [15:30.960 --> 15:32.340] So, retribution. [15:32.740 --> 15:37.280] Concerns about facing retaliation or negative consequences creates a culture of silence. [15:37.380 --> 15:41.820] And if people aren't willing to speak up, you lose those people's opinions and ideas. [15:42.340 --> 15:45.620] People need to be free to share whatever crazy ideas they have. [15:45.780 --> 15:47.140] Because if they're not... [15:47.860 --> 15:49.900] Well, then you're just stagnating. [15:50.080 --> 15:51.700] And you're missing out on good ideas. [15:53.380 --> 15:54.020] Let's see. [15:54.100 --> 15:54.980] We talked about complexity. [15:55.200 --> 15:56.140] So last is uncertainty. [15:56.640 --> 15:57.460] Thanks for the catch. [15:59.260 --> 16:00.260] Oh, come on. [16:02.520 --> 16:03.500] Damn it, Google. [16:04.700 --> 16:05.800] Fear of uncertainty. [16:06.400 --> 16:15.540] Uncertainty about the organization's response to security incidents and lack of clear guidelines causes confusion and inconsistency in how employees handle those security issues. [16:16.180 --> 16:24.640] It's really important that you write down your process for interacting with incidents before you have an incident. [16:25.220 --> 16:38.880] Because the absolute dead last thing you want to do is try to figure out who you need to call, who needs to be there, what you need to do, and how you need to plug that leak when that leak is happening right in front of you, and it's just you, and it's 11 o'clock at night. [16:40.760 --> 16:42.880] Been there, done that, got the t-shirt. [16:44.340 --> 16:47.660] Actually, I don't have that particular t-shirt, but if there was one, I'd buy it. [16:49.400 --> 16:52.720] So, we talked a lot about how fear can crop up in a security culture. [16:52.720 --> 16:56.320] What is the actual human cost of fear in a security culture? [16:58.620 --> 17:04.800] And, like I've said before, I previously worked in a couple of different countries, companies, with bad security cultures. [17:05.300 --> 17:08.520] I'd even go so far as to label one of them as straight-up toxic. [17:08.780 --> 17:12.300] I won't name names, but you've got my LinkedIn at the end of this. [17:12.400 --> 17:13.280] Feel free to look them up. [17:13.500 --> 17:14.440] There aren't that many. [17:15.020 --> 17:16.520] I'm pretty sure you'll figure it out quick. [17:17.200 --> 17:18.400] Well, maybe not, actually. [17:18.600 --> 17:19.140] We'll see. [17:19.860 --> 17:27.400] But all that is to say, I know exactly, firsthand, how fear and anxiety diminish the effectiveness of security programs and controls. [17:27.940 --> 17:35.760] Put simply, employees' fear of being reprimanded or terminated greatly affects the success or failure of a security program. [17:36.240 --> 17:39.000] So, let's talk about some of these negative costs. [17:39.300 --> 17:41.880] The first, reduced incident reporting. [17:42.260 --> 17:48.080] Like we've said, employees that are afraid of punishment, they hide their mistakes and they avoid reporting security incidents. [17:48.080 --> 17:52.960] Those incidents escalate and they lead to larger security breaches over time. [17:53.280 --> 17:56.080] Like the example of the lady who knew she got phished. [17:56.600 --> 17:57.940] She didn't tell us. [17:58.180 --> 17:58.980] Bad things happen. [17:59.260 --> 18:03.580] But, if we had just said, hey, something bad happened, can you look at it? [18:03.740 --> 18:05.200] It would have been totally different. [18:06.080 --> 18:08.240] And that's what we try to instill. [18:09.380 --> 18:12.000] So, next is lower morale and productivity. [18:12.820 --> 18:20.680] A fear-based culture creates stress and anxiety, leading to decreased job satisfaction, productivity, and ultimately higher turnover rates. [18:21.100 --> 18:23.600] In this day and age, we can't afford to lose good workers. [18:23.860 --> 18:31.220] Even if they make mistakes, we should probably give them some training or something, because, like, there's a huge cyber security shortage out there, so they say. [18:32.560 --> 18:33.840] Nobody's beating down my door. [18:35.160 --> 18:35.880] Let's see. [18:36.140 --> 18:37.860] Next up, lack of transparency. [18:38.160 --> 18:44.000] Fear prevents open communication and transparency, as employees are afraid to acknowledge and own up to their own mistakes. [18:44.600 --> 18:55.700] Being able to say, I made a mistake, it's my fault, I know what I did wrong, and I learned from it, is one of the most important things that I think you can do as a professional. [18:56.060 --> 18:57.600] Because mistakes are how we get better. [18:57.860 --> 18:59.120] And we'll talk more about that later. [18:59.200 --> 19:00.380] I don't want to go too deep into that. [19:02.400 --> 19:08.660] But the important thing about lack of transparency is, if nobody's owning their issues, nobody's writing down what happened. [19:08.800 --> 19:09.940] And we're never learning. [19:09.940 --> 19:13.640] We as a company, we as an organization, are never learning from those issues. [19:13.900 --> 19:19.480] So we never realize, hey, there were seven websites on this one server, and it fell over. [19:19.700 --> 19:24.340] We never noticed that one of those websites has a huge database load, and that's why it happened. [19:24.540 --> 19:25.540] We never write that down. [19:25.640 --> 19:29.120] So it keeps escalating and going around different nodes, and they keep dying. [19:29.940 --> 19:30.620] Same thing. [19:31.580 --> 19:33.320] Next up, poor decision making. [19:34.360 --> 19:40.740] Fear of repercussions lead employees to make poor security decisions, such as circumventing our security policies. [19:41.320 --> 19:43.420] Like we talked about removable media. [19:44.060 --> 19:45.380] Maybe they went to a conference. [19:45.660 --> 19:48.660] Maybe this guy said, hey, check out my PDF on this thumb drive. [19:49.860 --> 19:51.860] I really... please don't fall for that. [19:52.180 --> 19:54.960] If anyone at this conference gives you a thumb drive, burn it. [19:55.320 --> 19:56.220] I'm not kidding. [19:57.040 --> 19:59.060] It's not worth the risk. [19:59.320 --> 19:59.840] Not at all. [20:00.780 --> 20:04.360] And the last one is erosion of trust. [20:05.000 --> 20:08.880] A punitive security culture erodes trust between employees and the security team. [20:09.120 --> 20:14.200] And what happens here is employees start to view security as adversaries, not companions. [20:14.640 --> 20:21.940] And if you're working against the security team, if you're trying to say, how can I get around their controls? [20:21.940 --> 20:25.720] How can I figure out how to make this the way I want it to be? [20:26.900 --> 20:29.480] You're not going to be very good at following them. [20:32.420 --> 20:33.340] There you go. [20:34.300 --> 20:35.820] So now let's talk about compassion. [20:36.020 --> 20:37.300] I've talked a lot about fear. [20:37.640 --> 20:41.000] But the crux of this talk is supposed to be compassion, I think, right? [20:42.700 --> 20:46.860] So Merriam-Webster gives us a nice little definition we can start with. [20:47.220 --> 20:49.200] But I kind of edited it. [20:49.200 --> 20:56.000] Being interested in and understanding the difficulties of other people and having a genuine desire to help them. [20:56.240 --> 20:57.820] That's how I view compassion. [20:58.140 --> 21:01.300] And there are some bits of compassion that matter. [21:01.900 --> 21:03.480] The first is empathy. [21:03.840 --> 21:13.960] Empathy is simply putting yourself in another person's shoes, understanding their feelings and challenges, and using that knowledge to guide your interactions with them. [21:13.960 --> 21:20.060] Really sit down and think, how does that person feel, and why do they feel that way? [21:20.320 --> 21:24.920] Because nine times out of ten when you find a disgruntled employee, they're disgruntled for a reason. [21:25.140 --> 21:27.360] They're not mad at you, probably. [21:27.520 --> 21:28.980] They're mad at some process. [21:28.980 --> 21:32.980] Or they're mad at their boss making them work Sunday and file TPS reports. [21:33.200 --> 21:33.660] I don't know. [21:33.940 --> 21:35.740] But there's usually some issue. [21:36.120 --> 21:37.200] You just have to look. [21:37.200 --> 21:41.520] And show them that you value their experiences and perspectives. [21:42.060 --> 21:44.160] Give them time to explain what's going on. [21:44.480 --> 21:48.120] The key about empathy is, it's not about what you know. [21:48.420 --> 21:50.320] It's about what you don't know. [21:50.520 --> 21:51.700] Because you're not them. [21:51.900 --> 21:52.920] You're not in their shoes. [21:53.340 --> 21:54.760] Take a moment to ask. [21:55.140 --> 22:02.680] And if this is a foreign concept to you, you might say something like, I don't know how you feel, but I'm here to listen. [22:03.220 --> 22:06.560] Because something like that shows them that they're valued and that they care. [22:07.100 --> 22:11.320] And even if maybe you don't really care what they have to say, you can lie. [22:13.200 --> 22:14.560] I mean, we're in cyber, right? [22:14.660 --> 22:15.720] We're convincing liars. [22:17.640 --> 22:24.460] I will say, from my own experience, don't be quick to provide solutions if they give you problems on a silver platter. [22:24.880 --> 22:30.380] Wait until you understand the scope of the issues at hand, and then maybe you can come up with some solutions. [22:30.380 --> 22:32.440] But focus on the listening part. [22:32.740 --> 22:33.600] That's the best. [22:34.540 --> 22:36.740] Next up, genuine concern. [22:37.260 --> 22:44.800] And this is showing authentic care for your employees' personal and professional challenges, and making efforts to support them whenever you can. [22:45.200 --> 22:47.420] You should be a friend to your employees. [22:47.620 --> 22:48.820] Don't be an adversary. [22:49.620 --> 22:50.600] Remember the golden rule. [22:50.800 --> 22:52.660] Treat others as you would like to be treated. [22:53.180 --> 23:00.280] Like I said before, no one wants a boss who breathes down their neck, demands them to work overtime to put in TPS reports on Monday morning. [23:00.640 --> 23:01.880] Man, that's a tired cliche. [23:02.060 --> 23:03.060] I shouldn't use that too early. [23:03.480 --> 23:03.680] Oops. [23:05.060 --> 23:05.720] So yeah. [23:06.940 --> 23:07.840] Genuine concern. [23:08.160 --> 23:09.960] Next up, a desire to help. [23:10.480 --> 23:13.960] This is taking a proactive approach to offering assistance and solutions. [23:13.960 --> 23:18.980] You want to be the one who reaches out and says, hey, I saw you were having issues with this. [23:19.100 --> 23:20.660] You didn't deliver this goal on time. [23:20.880 --> 23:21.980] Is there anything I can help you with? [23:22.300 --> 23:23.140] It's not hard. [23:23.660 --> 23:31.980] And as a leader, providing resources, guidance, and encouragement to help those employees overcome difficulties, whether they be personal or professional. [23:32.300 --> 23:36.000] Because as you'll find out a lot of times, the line's pretty blurry. [23:36.920 --> 23:41.120] Like, if your mom gets cancer, you're probably not going to deliver your fucking work on time. [23:41.900 --> 23:43.420] Oh, can I say fuck here? [23:43.540 --> 23:44.440] I did it twice. [23:44.540 --> 23:44.700] Sorry. [23:46.780 --> 23:48.080] Yeah, it's the Marine in me. [23:48.200 --> 23:48.360] Sorry. [23:48.800 --> 23:49.580] That's me. [23:50.500 --> 23:51.520] Next, patience. [23:51.520 --> 23:56.040] You have to understand that resolving issues and overcoming challenges takes time. [23:56.300 --> 23:58.080] It's not a fast process. [23:58.080 --> 24:02.460] And it's really not a process that you can influence to make it faster. [24:03.060 --> 24:11.360] All you can do sometimes is offer ongoing support and avoid the quick rush to judgment or expecting immediate results. [24:11.780 --> 24:13.100] Rome wasn't built in a day. [24:13.300 --> 24:17.620] It was built brick by painstaking brick, mostly by slaves. [24:17.780 --> 24:20.920] And neither was your security program or company culture. [24:21.600 --> 24:22.740] It'll take time. [24:23.020 --> 24:24.120] Be mindful of that. [24:25.380 --> 24:27.960] Next, is a non-judgmental attitude. [24:28.460 --> 24:30.800] You have to avoid criticism and blame. [24:31.040 --> 24:33.300] And instead focus on understanding and support. [24:33.660 --> 24:38.560] Understand where these employees are coming from and why they want to do these things. [24:38.740 --> 24:39.820] And support them. [24:40.060 --> 24:43.760] Give them options that get away from what they don't want to do. [24:43.760 --> 24:48.340] Make this a safe space for employees to share concerns and mistakes. [24:48.720 --> 24:51.340] It's okay to own that you made a mistake. [24:51.620 --> 24:52.820] It's okay... [24:55.760 --> 25:02.800] You just need to understand that you can say these things without worrying about getting fired or getting put on a project improvement plan. [25:03.320 --> 25:07.760] At the end of the day, it doesn't matter who's at fault when an incident happens. [25:08.060 --> 25:09.920] The singular focus is about fixing. [25:10.500 --> 25:11.280] Assigning fault. [25:11.420 --> 25:12.080] Blaming people. [25:12.380 --> 25:14.380] You can do that after the fact if you really want to. [25:14.580 --> 25:15.680] You can just leave it at the door. [25:15.860 --> 25:16.380] Who cares? [25:16.880 --> 25:19.020] As long as we're not bleeding data, it doesn't matter. [25:20.400 --> 25:23.640] I believe the last one is encouragement. [25:24.980 --> 25:29.800] So, you want to motivate and uplift employees through positive reinforcement. [25:30.120 --> 25:33.060] You want to recognize and celebrate their efforts and their successes. [25:33.380 --> 25:35.340] Making them feel supported. [25:36.280 --> 25:38.640] This can take many, many forms. [25:39.440 --> 25:41.580] The least of which is just saying thank you. [25:42.500 --> 25:51.720] At our company, whenever someone reports an incident or a phishing email, we always start with the first two words as, thank you. [25:52.020 --> 25:56.760] Because that employee took time out of their day to tell us something that we needed to do. [25:56.880 --> 25:58.080] And we appreciate it. [25:58.660 --> 26:01.060] Most teams would say, thanks for giving me more work. [26:01.180 --> 26:02.820] But no, I genuinely mean it. [26:03.120 --> 26:04.320] Like, thank you. [26:04.620 --> 26:06.760] Because without you, I wouldn't know that it was happening. [26:09.500 --> 26:12.360] You also want to encourage employees to share big ideas. [26:12.740 --> 26:16.140] Even, and perhaps especially, unconventional ones. [26:16.140 --> 26:23.700] This is one place in particular where having varying levels of experience in your team can be an asset, not a distraction. [26:24.060 --> 26:30.160] Because those with less experience sometimes approach problems with a different lens than those with a lot of experience. [26:30.600 --> 26:40.700] People who know intimately how a system works are going to design their responses for designs or whatever around, well, I know this works this way and that works that way. [26:40.820 --> 26:44.840] But a person who doesn't exactly understand things might say, well, why does it work that way? [26:44.900 --> 26:46.040] Why couldn't it work this way? [26:46.760 --> 26:48.660] That's how big progress is made sometimes. [26:48.660 --> 26:50.400] I've seen it first-hand. [26:53.180 --> 26:54.000] Okay, cool. [26:54.160 --> 26:55.780] I just covered like three paragraphs. [26:56.040 --> 26:56.300] Love it. [26:57.160 --> 26:58.120] So the next one. [26:58.740 --> 27:02.440] How do we introduce compassion into our security culture? [27:02.740 --> 27:05.200] Talked a lot about what compassion is and how to be compassionate. [27:05.380 --> 27:07.440] But what does that look like in practice? [27:08.180 --> 27:12.240] So first, we want to assume positive intent, but verify. [27:12.580 --> 27:13.480] Trust, but verify. [27:14.240 --> 27:22.320] So anytime you have an employee that does something negative, just assume out of the gate that it was an accident. [27:22.560 --> 27:23.820] It was an innocent mistake. [27:24.780 --> 27:26.440] And this is twofold. [27:27.040 --> 27:29.480] If it was a mistake, you're not going to look like a jackass. [27:29.760 --> 27:37.480] If it wasn't a mistake, the user's going to realize that you're watching, and it's going to encourage them to make better choices moving forward. [27:38.860 --> 27:41.580] Next up, non-punitive reporting. [27:42.680 --> 27:50.240] So you need to establish policies that let employees know that there aren't negative consequences for reporting security issues. [27:50.400 --> 27:51.640] Even if they're at fault. [27:51.860 --> 27:57.180] Even if it's their problem, their fault, and they're the only person involved, it doesn't matter. [27:57.400 --> 28:00.020] At the end of the day, it's a security issue and we need to fix it. [28:00.160 --> 28:01.560] We'll deal with anything else later. [28:02.200 --> 28:10.400] But when employees aren't afraid to report an issue they may have been a part of, they're substantially more likely to actually report anything. [28:10.400 --> 28:16.340] I'd much rather have a thousand false positives and one real positive than nothing. [28:16.860 --> 28:19.660] Because silence makes me wonder if the program works at all. [28:21.460 --> 28:27.800] And like we've said, encouraging employees to report issues early and often stops big issues before they become big. [28:29.860 --> 28:32.360] Next up, supportive feedback. [28:32.960 --> 28:39.320] Provide constructive feedback and resources to help employees understand their mistakes and how to avoid them in the future. [28:39.720 --> 28:43.000] Because mistakes are how we as humans grow and improve. [28:44.160 --> 28:52.780] At Amazee, our founder and my grand boss, Michael Schmid, said something to me when I was a very young developer there. [28:53.560 --> 28:57.180] He said, make any mistake you want, but only make it once. [28:57.700 --> 28:59.480] That was groundbreaking for me. [28:59.640 --> 29:02.040] I've never been told to make mistakes in my life. [29:02.040 --> 29:04.640] Like in the Marine Corps, you make a mistake, somebody dies. [29:04.980 --> 29:09.140] And at my job before Amazee IO, you make a mistake, you're going to get fired. [29:10.680 --> 29:12.080] But here it's different. [29:12.560 --> 29:14.840] Here it's, we want you to make mistakes. [29:15.080 --> 29:16.540] We want you to try new things. [29:16.740 --> 29:17.840] Think outside the box. [29:18.320 --> 29:19.700] Try different avenues. [29:20.120 --> 29:22.540] Because when you fail, you learn. [29:22.540 --> 29:26.360] And when you fail, you want to fail forward. [29:27.320 --> 29:30.480] Think about people who were successful at creating companies. [29:30.880 --> 29:31.620] Nikolai Tesla. [29:31.840 --> 29:33.700] He tried 10 times. [29:34.160 --> 29:36.160] Alexander Graham Bell, 20 times. [29:36.480 --> 29:37.780] They were all failures. [29:38.060 --> 29:40.920] And every failure taught them something along the way. [29:41.220 --> 29:45.900] And they needed those failures in their background to get to where they are, where they were. [29:46.140 --> 29:48.780] They're both dead, but that's the idea. [29:50.040 --> 29:53.620] And that single sentence embodies the core of compassion in our company culture. [29:53.860 --> 29:55.640] And time's proven that it works. [29:56.120 --> 29:58.620] If you make a mistake, we don't judge you. [29:58.900 --> 30:00.600] We don't get mad at you. [30:00.700 --> 30:02.080] We just help you fix it. [30:02.940 --> 30:04.240] And that's how it's been. [30:04.340 --> 30:05.560] We've had some pretty big mistakes. [30:05.820 --> 30:06.820] I made one myself. [30:07.040 --> 30:09.320] I deleted some project's database. [30:09.780 --> 30:11.840] It cost us like a quarter million dollars. [30:12.180 --> 30:13.300] They almost sued us. [30:14.200 --> 30:15.800] Oh well, I still work there. [30:17.800 --> 30:20.600] That doesn't mean you should get hired and delete people's databases. [30:20.620 --> 30:21.340] Don't do that. [30:21.660 --> 30:22.780] Don't take that away from this. [30:22.880 --> 30:24.120] Don't take that away from this call. [30:24.240 --> 30:24.760] I'm just telling you. [30:24.880 --> 30:25.800] I've made plenty of mistakes. [30:28.600 --> 30:29.880] Next, build trust. [30:30.220 --> 30:34.160] So you need to ensure that your employees feel safe to report security issues. [30:34.160 --> 30:38.500] By creating an environment where security teams are seen as helpers. [30:38.820 --> 30:41.200] Not as the judge, the jury, or the executioner. [30:41.380 --> 30:42.620] And certainly not all three. [30:43.720 --> 30:46.040] It's not security versus the users. [30:46.080 --> 30:47.800] Or the users versus security. [30:48.580 --> 30:50.220] It's all of us. [30:50.380 --> 30:52.880] The entire organization versus the world. [30:53.500 --> 30:55.040] And that's the way we need to see it. [30:57.680 --> 31:00.100] Next up, recognize good practices. [31:00.680 --> 31:07.160] Recognize and reward employees who demonstrate good security practices and proactively contribute to the organization's security efforts. [31:07.620 --> 31:13.960] Like I said, when we have a report of a potential incident or a phishing email, we always start off with thank you. [31:13.960 --> 31:21.220] Because even something as simple as thanking employees for reporting a phishing email can go a long way toward fostering a positive work culture. [31:21.500 --> 31:22.840] You want people to like you. [31:23.060 --> 31:25.020] You don't want people to think you're a dick. [31:27.040 --> 31:29.240] Next up, empower your employees. [31:29.660 --> 31:33.020] Employees are often the first or last line of defense against attacks. [31:33.340 --> 31:36.040] So empower them to take security into their own hands. [31:36.480 --> 31:40.480] In the Marine Corps, we had a saying, leadership at the lowest level. [31:40.740 --> 31:43.620] And when I was promoted to an NCO, it was me. [31:43.620 --> 31:44.560] I didn't ask people. [31:44.880 --> 31:46.140] I didn't ask for permission. [31:46.280 --> 31:47.200] I begged for forgiveness. [31:47.500 --> 31:49.460] And trust me, I begged a lot. [31:49.860 --> 31:50.860] Because I was an idiot. [31:52.860 --> 31:57.980] But help your users understand the importance of safeguarding the data they're entrusted with access to. [31:58.500 --> 32:00.980] Help them understand why these policies exist. [32:01.100 --> 32:02.000] Why they're in place. [32:02.300 --> 32:04.300] And the reason that you care so much. [32:05.160 --> 32:07.660] Make them feel like they're a part of your security team. [32:07.760 --> 32:09.500] Because at the end of the day, they really are. [32:09.500 --> 32:14.720] The people holding those admin credentials are every bit as much a security team member as I am. [32:15.320 --> 32:16.220] A hundred percent. [32:16.540 --> 32:21.140] Because if they decide to sell those, man, it's going to be a bad fucking day for everybody. [32:23.460 --> 32:26.980] At our company, we cover this a few different times during our onboarding training. [32:27.960 --> 32:29.600] Trust takes years to lose. [32:31.460 --> 32:34.780] Trust takes years to earn, but only seconds to lose. [32:34.780 --> 32:37.660] And once lost, it's not easily regained. [32:38.060 --> 32:40.860] We have big companies that trust us with their data. [32:41.580 --> 32:44.440] A few pharmaceutical companies and some others. [32:44.660 --> 32:45.700] But they're pretty big. [32:46.780 --> 32:52.640] And if their data gets leaked, they're going to find another provider who's not going to leak their data. [32:53.420 --> 32:55.620] They're not going to say, ah, you made a mistake. [32:55.900 --> 32:57.220] We might be compassionate. [32:57.220 --> 32:58.200] I doubt they will be. [32:59.220 --> 33:06.480] So, yeah, without the users and the employees, the security team doesn't need to exist because there's no product or company to protect. [33:07.000 --> 33:10.900] So, remember, they're the reason we're here and they're part of our team, too. [33:13.180 --> 33:15.520] So, we talked about a bad security culture. [33:15.780 --> 33:17.020] We talked a lot about compassion. [33:17.280 --> 33:18.940] And we talked about how to apply that. [33:19.220 --> 33:21.740] So, let's go back to those bad examples and look at them again. [33:21.740 --> 33:26.460] So, let's revisit it and see what good topics look like. [33:26.940 --> 33:30.300] So, a proactive reporting environment. [33:30.740 --> 33:32.980] Employees feel safe to report their issues. [33:33.220 --> 33:34.800] They don't feel like they're going to be judged. [33:35.000 --> 33:36.860] They don't feel like they're going to be reprised. [33:37.120 --> 33:40.740] And you get increased reporting rates all across your organization. [33:41.020 --> 33:45.400] You detect threats earlier just because people are telling you about them. [33:47.240 --> 33:49.880] You have regular training and awareness programs. [33:49.880 --> 33:55.720] You keep employees updated on the latest threats and best practices without overwhelming them. [33:56.200 --> 33:59.340] At Amazie.io, in addition to our required annual training... [33:59.340 --> 34:00.180] It's so boring. [34:00.280 --> 34:00.760] I hate it. [34:01.700 --> 34:05.320] We prepare a single slide every month in the regular all-hands meeting. [34:05.360 --> 34:07.820] And we talk about some new hot-button topic. [34:08.220 --> 34:13.360] Last month's was password complexity requirements. [34:13.520 --> 34:17.860] Why do we require your passwords to be 14 characters long and made up of all this garbage? [34:18.660 --> 34:20.120] Because some people don't know. [34:20.220 --> 34:21.820] They think it's just an arbitrary number. [34:22.080 --> 34:31.340] But when you show somebody a graph that says, well, if your password is 10 characters long and made of only lowercase letters, my 3090 could crack it in less than a second. [34:32.140 --> 34:37.300] When you really tell people why they have to follow this, it really makes them follow it. [34:37.480 --> 34:39.380] Because they don't want to get hacked either. [34:42.320 --> 34:49.940] The continuous and bite-sized education program we put in place helps users stay informed and engaged without information overload. [34:51.060 --> 34:53.480] Another big thing is leadership engagement. [34:53.740 --> 34:57.320] Leaders actively participate in and promote security initiatives. [34:57.660 --> 35:00.000] It's not do as I say, not as I do. [35:00.260 --> 35:02.800] It's a saying I have from the Marine Corps. [35:03.060 --> 35:05.320] Lead from the trenches, not the benches. [35:06.200 --> 35:10.240] You can't be an effective leader without first being an effective follower. [35:10.540 --> 35:14.380] You have to understand how to follow before you can understand how to lead. [35:14.580 --> 35:19.340] And you can't possibly expect anyone to follow a rule that you don't follow yourself. [35:19.920 --> 35:25.760] In the Marine Corps, I likened it to, I'm not going to go pick up trash because you wouldn't go pick up trash. [35:28.740 --> 35:31.600] I'll push the Earth until I change the orbit of the Earth. [35:31.720 --> 35:32.760] That's all I'll do. [35:33.220 --> 35:35.000] But that's the idea. [35:36.160 --> 35:42.960] So what you would want to see for an example of that, you'd want to see your CEO attending security training sessions with the whole company. [35:43.080 --> 35:47.300] And you'd want to see them communicating the importance of security to all of your employees. [35:47.480 --> 35:50.960] Setting that tone of seriousness and commitment from the top down. [35:52.500 --> 35:54.820] The next is collaborative security efforts. [35:55.440 --> 35:58.700] Security is seen as a shared responsibility across all the departments. [35:59.000 --> 36:01.480] Not just a silo in the IT or the security team. [36:02.240 --> 36:12.820] So an example of that would be during a software development project, developers and security experts would work together to identify and mitigate potential vulnerabilities earlier in the process than when they were in production. [36:13.120 --> 36:14.500] You'll hear more about that one later. [36:14.600 --> 36:15.760] I got a good example for you. [36:17.220 --> 36:22.060] So let's talk about some real life examples of using compassion and understanding in security. [36:22.360 --> 36:22.960] Big ones. [36:22.960 --> 36:25.780] So in 2016... [36:27.620 --> 36:28.360] There we go. [36:28.600 --> 36:35.300] In 2016, Google was having a difficult time with its employees' logins being compromised due to repeated phishing attacks. [36:35.640 --> 36:41.180] The typical knee-jerk response would be to assign the phished users more training on how to avoid phishing emails. [36:41.480 --> 36:42.820] I mean, that works, right? [36:42.980 --> 36:46.540] You'll just go to training six times and you'll never click a phishing email again, right? [36:47.440 --> 36:48.740] But Google didn't do that. [36:48.740 --> 37:01.800] They took a step back, they looked at the problem at hand, and they put themselves in the user's shoes and said, how can we fix this technologically while not getting in the way of doing the work that needs to be done? [37:01.800 --> 37:03.740] And the answer was simple. [37:04.500 --> 37:06.100] A tightened security key. [37:07.240 --> 37:10.760] Because it doesn't matter if you phish my account and my password. [37:11.320 --> 37:16.940] If you need to click that button before you can log in, you don't get nowhere without that button. [37:16.940 --> 37:21.840] And a phishing attack is never going to take your hardware two-factor token. [37:22.040 --> 37:23.940] At least, not any one that I know of. [37:26.400 --> 37:31.880] In the time period after that, Google saw no additional accounts compromised due to phishing attempts. [37:32.120 --> 37:35.720] The article I specifically quoted here only went up to 2020. [37:36.060 --> 37:44.160] But that's four years of no more phishing attempts just because they implemented hardware security keys. [37:45.280 --> 37:54.400] So instead of blaming the employees for falling for the phishing scams, they just found an easy-to-use solution that didn't even require the users to alter their behavior very much. [37:56.320 --> 37:58.280] Next up, you're going to love this one. [37:58.560 --> 38:01.160] Let's go back to a time when I was seven years old. [38:02.400 --> 38:03.220] I know, right? [38:03.220 --> 38:11.320] So, one of the things about compassion and empathy you should know, they don't just apply to your employees. [38:11.320 --> 38:13.540] They don't just apply within your organization. [38:13.680 --> 38:17.040] They can also apply outside your organization. [38:17.360 --> 38:20.420] And Netscape is a brilliant example of this. [38:20.700 --> 38:24.320] And has anyone in here actually used Netscape Navigator? [38:25.040 --> 38:26.260] Holy shit! [38:26.520 --> 38:26.880] Really? [38:27.660 --> 38:28.340] Wow! [38:28.640 --> 38:30.200] I'm blown away! [38:30.200 --> 38:30.580] Okay. [38:31.320 --> 38:31.900] Anyway. [38:32.340 --> 38:34.740] So, that's... [38:34.740 --> 38:37.160] Wow, that's mind-blowing. [38:37.520 --> 38:41.180] So, these principles don't just apply inside your organization. [38:41.360 --> 38:42.840] They apply outside your organization too. [38:43.420 --> 38:51.980] And Netscape, they were releasing the version 2 beta of their Navigator product, which was the web browser in 1995. [38:52.020 --> 38:53.920] It's the one you wanted to have. [38:54.100 --> 38:56.740] Because Windows didn't ship with Internet Explorer yet. [38:56.740 --> 39:00.020] So, if you wanted the Internet, it was Navigator or nothing. [39:00.320 --> 39:02.780] I think maybe AOL had something back then. [39:02.820 --> 39:03.340] I don't remember. [39:04.000 --> 39:04.480] But... [39:10.480 --> 39:20.180] By putting yourselves in the shoes of your adversaries, and understanding their motivations and desires, you can sometimes find an alternative answer to a rather serious problem. [39:20.440 --> 39:21.640] And Netscape did that. [39:21.640 --> 39:28.880] So, in an effort to get bugs out of their code, they thought about, who's going to find these bugs? [39:29.540 --> 39:30.900] Security researchers, of course. [39:31.120 --> 39:32.220] What are they going to do with them? [39:32.560 --> 39:34.420] Well, they're going to sell them to the highest bidder. [39:34.580 --> 39:36.420] Or they're going to exploit them to try to make money. [39:37.320 --> 39:42.240] Well, it's a lot easier to just have the company buy your bug and fix it. [39:42.240 --> 39:52.700] Because it's a lot easier to sign an NDA and get a check than it is to worry about the statute of limitations expiring on that computer crime you just committed. [39:53.140 --> 39:53.640] Right? [39:53.980 --> 39:55.160] I mean, am I wrong there? [39:55.160 --> 39:57.680] But that's what they did. [39:57.800 --> 40:00.660] And they created what we know as the bug bounty program. [40:00.960 --> 40:09.900] And by offering financial incentives to those security researchers, Netscape made it worth their while to not just find, but eradicate bugs. [40:10.420 --> 40:20.940] And it changed the way security, software security vulnerability testing was handled and resulted in significantly less bugs for their product to boot. [40:21.280 --> 40:22.520] Couldn't have been done any better. [40:23.000 --> 40:23.500] Masterful. [40:28.190 --> 40:29.710] Next up, Microsoft. [40:30.550 --> 40:41.850] So, in the early 2000s, PCs were becoming more and more ubiquitous, leading to a rise in threat actors writing malicious software looking to take advantage of those users, connecting these new PCs to the Internet. [40:42.270 --> 40:46.990] In 2002, Microsoft launched the Trustworthy Computing Initiative. [40:47.270 --> 40:52.030] And it was aimed at helping them offer highly secure and reliable software to their customers. [40:52.410 --> 40:55.810] You have to remember, Microsoft doesn't just serve home users. [40:55.810 --> 40:59.730] They also serve millions of business and government users as well. [41:00.250 --> 41:08.090] In 2004, that proved fruitful as they implemented what we now know as the software development lifecycle. [41:10.070 --> 41:15.190] And that integrated security throughout all phases of the software development process. [41:15.850 --> 41:30.630] So, rather than blaming their developers for writing flawed code, they provided training, tools, and support to integrate security-minded individuals, like all of us in here, into that development lifecycle, to prevent bugs before they even happened. [41:31.790 --> 41:37.870] It resulted in much more secure software products for them, reduced the number of security vulnerabilities in their products. [41:38.090 --> 41:44.050] It's been updated many times since, and it's still used in most DevSecOps workflows around the world. [41:44.370 --> 41:47.690] Sure, there are other ways to do it, but this is the one that started it. [41:50.210 --> 41:51.030] Home stretch. [41:52.090 --> 41:57.250] So, in conclusion, technological measures only take your security programs so far. [41:57.430 --> 42:03.890] It's inevitable that employees will be involved in the process at some point, and a bad security culture will only make things worse. [42:04.250 --> 42:08.850] Issues will go unreported, mistakes will be hidden, and lessons will go unlearned. [42:10.090 --> 42:14.050] Compassion and understanding are key to fostering a positive security culture. [42:14.650 --> 42:21.390] By understanding the motivation of others' feelings, you can find new ways to better leverage their talents and help them grow. [42:22.130 --> 42:25.530] Putting yourself in someone else's shoes can help you to understand. [42:25.870 --> 42:27.670] I think I got those two backwards, dammit. [42:29.330 --> 42:41.770] When employees feel safe to report issues and own their mistakes without fear of reprisal, they perform better, they feel better about their jobs and themselves, and they're more likely to report issues early and often. [42:44.070 --> 42:47.750] Moving security away from the security team and into the hands of your employees. [42:48.110 --> 42:58.410] Making it the responsibility of every employee in an organization has tangible benefits, as those employees are the first and or last line of defense against malicious actors. [43:00.170 --> 43:10.350] Encouraging them to own security processes through positive reinforcement can help reap significant benefits in reducing the number of successful attacks against the company. [43:11.230 --> 43:13.630] My favorite, the carrot. [43:14.930 --> 43:17.530] We've tried the stick for far too long. [43:17.730 --> 43:19.350] Why not try the carrot instead? [43:19.890 --> 43:25.090] Research proves that punitive and judgmental reactions in security programs do more harm than good. [43:25.090 --> 43:28.670] So let's throw the baby out with the bathwater on that one and try something different. [43:29.210 --> 43:32.210] Compassion, understanding and empathy toward our employees. [43:32.650 --> 43:37.370] The best part about trying the carrot is that it doesn't cost money. [43:37.710 --> 43:39.330] You just don't have to be a dick. [43:39.770 --> 43:40.670] Pretty easy. [43:42.090 --> 43:42.910] All right. [43:43.410 --> 43:44.230] That's it. [43:45.110 --> 43:45.850] Any questions? [43:45.970 --> 43:47.370] I'm a private pilot and... [43:47.790 --> 43:48.250] Me too. [43:48.610 --> 43:52.290] Okay, and NASA has a aviation stage reporting system. [43:52.290 --> 43:52.970] They do. [43:53.090 --> 43:55.630] Which is non-putative. [43:55.850 --> 43:56.250] That's right. [43:56.350 --> 44:05.930] So if you get involved in some little incident, some little problem, you fill out this form, you send it to NASA, it's basically a get-out-of-jail-free card against enforcement actions overall. [44:07.030 --> 44:09.330] And just what you were talking about is reminding me so much of that. [44:09.770 --> 44:15.130] Even a more formal report your security issue and we promise we won't do anything to you. [44:15.430 --> 44:16.330] That's exactly it. [44:16.430 --> 44:16.970] That's what we do. [44:18.630 --> 44:21.770] You know, it's funny you mention reporting private pilot incidents. [44:22.510 --> 44:22.990] I... [44:23.630 --> 44:26.990] Near the end of my private pilots training, I collided with another plane. [44:27.170 --> 44:28.050] They were in the wrong. [44:28.290 --> 44:31.770] They were taxiing without their taxi light on and they went over. [44:32.350 --> 44:37.330] My wing went under their wing because by the time I saw them, we were too close to avoid it. [44:37.630 --> 44:41.510] I did a post-trip inspection on the... or a post-flight inspection. [44:41.770 --> 44:43.810] Didn't see any damage, so I didn't report anything. [44:43.810 --> 44:46.870] That was the end of my flying career at the University of North Dakota. [44:47.210 --> 44:49.950] They still passed that piece of the wing around in aviation safety. [44:50.190 --> 44:51.370] Saying, don't be that dude. [44:53.170 --> 44:54.050] Stories for days. [44:54.230 --> 44:55.510] And that's just not just private pilots. [44:55.610 --> 44:56.330] Airline pilots. [44:56.670 --> 44:57.110] Everybody. [44:57.590 --> 44:58.590] Air traffic controllers. [44:58.950 --> 45:02.590] They all use the 3-4 and try to get immunity for air. [45:03.310 --> 45:03.650] True. [45:03.950 --> 45:04.030] Yeah. [45:04.930 --> 45:05.430] Anybody else? [45:05.490 --> 45:06.030] Any other questions? [45:06.270 --> 45:06.870] Happy to answer. [45:07.430 --> 45:07.750] Hey. [45:08.150 --> 45:12.310] So this is more a comment than a question, which I know is everyone's favorite. [45:12.310 --> 45:12.910] It's fine. [45:14.150 --> 45:22.770] But just to go a little bit deeper into a couple of things that you brought up and areas where I've had a lot of success. [45:23.430 --> 45:36.390] So I really loved the whole awareness not equaling caring because I think we have all encountered developers who so deeply know better with their own personal security practices. [45:36.390 --> 45:49.730] But like a lot of the way that I've kind of dealt with that is instead of taking more of an informational approach, looking at like motivational interviewing and coaching techniques. [45:50.010 --> 45:56.350] Because at that point, it's less about how do you get someone to know to do better? [45:56.350 --> 46:02.870] And how do you actually get someone to basically be able to like do their own behavior modification? [46:04.070 --> 46:25.350] And I think that's an area I've had a lot of success in terms of like once I recognize that someone knows and doesn't care is like how do I figure out how to actively engage with whatever their intrinsic motivations are that might actually overlap. [46:25.930 --> 46:35.730] And sometimes people really don't care, but like often people have like some sense of pride in doing their job well or like not letting their coworkers down or something like that. [46:36.550 --> 46:40.530] And then in terms of... [46:40.530 --> 46:42.410] You took a lot of notes, I'm impressed. [46:43.850 --> 46:45.330] Is it because I have to flip back? [46:45.810 --> 46:45.990] Yep. [46:48.030 --> 47:08.330] In terms of just like compassion and displaying it towards the people you're working with and trying to change the behavior of, one thing that I've had a certain amount of success with that I think I would like to see people thinking of as like sort [47:08.330 --> 47:23.530] of a best practices thing in a workplace is when I have the ability to, taking a moment to talk about how the workplace security practices that I'm asking people to participate in translate into their personal lives. [47:23.750 --> 47:36.230] Because if I can get them to shift to their behavior every time they interact with a given system, I think that's actually a lot easier for most people in terms of making a behavior change. [47:36.390 --> 47:39.170] If it's like, hey, this is what I want you to do at work. [47:39.330 --> 47:43.110] Oh, also, you know, in your personal life, this works the same way. [47:43.390 --> 47:48.750] And like maybe you care about your personal email more than you care about your work email. [47:48.950 --> 47:59.330] So just FYI, here's what you need to know in order to like take as good care of your own self as you are of like your office email. [48:00.030 --> 48:19.270] And in terms of working with developers specifically, like anytime I have been able to like get people to recognize that like the security settings under a GitHub account is crucial to their professional future, I get so much more buy-in because I'm like, yo, this is not about our business or company. [48:23.490 --> 48:29.170] Like you're stuck with your GitHub for like the legacy of however one you want to use your GitHub. [48:29.570 --> 48:29.790] Right. [48:30.090 --> 48:39.290] So just like those are the two like very hands-on actionable ways I've drawn out the concepts you were talking about. [48:39.490 --> 48:39.710] Sure. [48:40.010 --> 48:40.530] Thanks for sharing. [48:41.350 --> 48:42.650] I'll take more questions. [48:42.770 --> 48:44.310] But before I do, I want to put up one more slide. [48:44.430 --> 48:47.290] If you want to know where to find me, these are all the places I am. [48:48.650 --> 48:49.530] Photos are all there. [48:49.750 --> 48:50.890] And that's my website. [48:51.090 --> 48:56.870] You can view my master's thesis on the Fourth Amendment in the digital age. [48:57.490 --> 49:00.910] Also, I think I'm being cut off, but I'll take your question until he makes me stop talking. [49:01.750 --> 49:02.430] Are we good? [49:02.650 --> 49:03.530] Oh, yeah. [49:03.650 --> 49:10.070] Just kind of to kind of piggyback off what you were saying, ma'am, and also something that kind of got in my head about what you were talking about. [49:11.630 --> 49:14.250] I was wondering if anybody has... just kind of pulled the room. [49:14.930 --> 49:17.610] You were talking about transitioning from stick to carrot. [49:18.410 --> 49:22.050] And carrot can come in the form of compassion, but it can also come in the form of fun. [49:22.510 --> 49:33.590] I don't know if anybody has any bright ideas about how to make cybersecurity or physical security practices, or at least learning about how to do that more fun and interesting. [49:34.170 --> 49:37.490] That sounds like a conversation to have right after this. [49:37.490 --> 49:37.750] Sure. [49:37.930 --> 49:41.190] And everyone, please thank Davis for his wonderful presentation. [49:41.670 --> 49:42.090] Thank you. [49:42.950 --> 49:45.610] There's always gamification, just so that's on the recording.