{"id":287,"date":"2017-06-19T13:10:40","date_gmt":"2017-06-19T13:10:40","guid":{"rendered":"http:\/\/securitycurve.com\/?p=287"},"modified":"2017-06-19T13:10:40","modified_gmt":"2017-06-19T13:10:40","slug":"security-bias-and-the-executive-infant","status":"publish","type":"post","link":"https:\/\/securitycurve.com\/?p=287","title":{"rendered":"Security, bias, and the executive infant"},"content":{"rendered":"<p><img decoding=\"async\" class=\"alignright size-medium lazyload\" data-src=\"http:\/\/www.publicdomainpictures.net\/pictures\/30000\/velka\/baby-with-a-laptop.jpg\" width=\"50%\" height=\"50%\" align=\"right\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" \/><\/p>\n<p>HBR has a great article up from a few days ago: &#8220;<a href=\"https:\/\/hbr.org\/2017\/06\/the-behavioral-economics-of-why-executives-underinvest-in-cybersecurity\">The Behavioral Economics of Why Executives Underinvest in Cybersecurity<\/a>.&#8221; It&#8217;s an interesting read. If you&#8217;re too lazy or swamped to go read it, the gist is that natural human biases are such that the default state of behavior when it comes to investing in security is below that which is required to meet real-world risks. \u00a0For example, since we don&#8217;t always get attacked, natural forces lead to a reduction in funding and resource allocation over time. \u00a0It&#8217;s the truth &#8211; anybody who has worked in or around security will recognize the dynamic immediately.<\/p>\n<p>What got me a little fired up are the suggestions that they have about how to deal with the situation:<\/p>\n<ul>\n<li><strong>Appeal to emotionality<\/strong> &#8211; leverage &#8220;effect bias&#8221; to make issues emotionally impactful rather than drawing on dry &#8220;facts and figures&#8221;. \u00a0From the article: &#8220;&#8230;<em>cybersecurity professionals should take into account people\u2019s tendency to overweight information that portrays consequences vividly and tugs at their emotions.<\/em>&#8220;<\/li>\n<li><strong>Reframe mental model<\/strong> &#8211; \u00a0&#8220;<em>Some CEOs may think that security investments are for building an infrastructure, that creating a fortified castle is all that\u2019s needed to keep a company safe<\/em>&#8230;<em>CISOs should work with boards and financial decision makers to reframe metrics for success in terms of the number of vulnerabilities that are found and fixed.<\/em>&#8221; \u00a0So basically, reframe the discussion around positive outcomes, and try your best to curb their native lack of understanding.<\/li>\n<li><strong>Survey peers<\/strong> &#8211; leverage peer pressure and &#8220;social proof&#8221; to curb overconfidence.<\/li>\n<li><strong>Highlight the &#8220;weakest link&#8221;<\/strong> &#8211; Loudly and (semi)publicly highlight issues to help thwart inattention to the problem space.<\/li>\n<\/ul>\n<p>What irritates me about this isn&#8217;t that they&#8217;re wrong. \u00a0In fact, I&#8217;m sure they&#8217;re a) right and b) that these methods work (probably pretty well.) \u00a0And, as such, the savvy practitioner would do well to leverage them accordingly. \u00a0Instead, what irritates me about this is that this is essentially how you&#8217;d treat a child. Like, is it me, or couldn&#8217;t this list basically also serve as a map for how you&#8217;d get your second-grader to do their homework?<\/p>\n<p>Fundamentally, I expect more &#8211; and better &#8211; from senior leaders. \u00a0I expect a degree of maturity where they <strong>can\u00a0<\/strong>make an objective determination about risks and issues without appealing to their emotions (this, by the way, is the reason that FUD works) or without having to draw on what &#8220;the other guy&#8221; is doing to illustrate why they&#8217;re remiss in not doing something similar. \u00a0Rather than leaning into the natural inclination of executives to be &#8220;babies in a suit&#8221;, isn&#8217;t there a way to cultivate maturity, rationality and objectivity? \u00a0Maybe I&#8217;m asking too much&#8230; or maybe these behaviors aren&#8217;t really as infantile as they appear to me on the surface. \u00a0But really, I&#8217;m not a huge fan of &#8220;dumbing it down&#8221; for people unwilling or unable to step up.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>HBR has a great article up from a few days ago: &#8220;The Behavioral Economics of Why Executives Underinvest in Cybersecurity.&#8221; It&#8217;s an interesting read. If you&#8217;re too lazy or swamped to go read it, the gist is that natural human biases are such that the default state of behavior when it comes to investing in [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[4],"tags":[14,106],"class_list":["post-287","post","type-post","status-publish","format-standard","hentry","category-security","tag-baby-in-a-suit","tag-security"],"_links":{"self":[{"href":"https:\/\/securitycurve.com\/index.php?rest_route=\/wp\/v2\/posts\/287","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/securitycurve.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/securitycurve.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/securitycurve.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/securitycurve.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=287"}],"version-history":[{"count":0,"href":"https:\/\/securitycurve.com\/index.php?rest_route=\/wp\/v2\/posts\/287\/revisions"}],"wp:attachment":[{"href":"https:\/\/securitycurve.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=287"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/securitycurve.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=287"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/securitycurve.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=287"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}