the difference between the reality and feeling of security

30
The difference between the “Reality” and “Feeling” of Security Anup Narayanan, Founder & CEO, Information Security Quotient (ISQ) She looks trustworthy I’m gonna steal your toys

Upload: anup-narayanan

Post on 22-Nov-2014

11.132 views

Category:

Business


0 download

DESCRIPTION

A presentation that I took recently for a top management group that focuses on the human factor in information security. The presentation focuses on why people make security mistakes by analyzing various factors involving perception, how people make security decisions and how people are influenced by their feeling of security. Do drop me a note if you wish to discuss this further at "anup at isqworld dot com"

TRANSCRIPT

Page 1: The difference between the Reality and Feeling of Security

The difference between the “Reality” and “Feeling” of Security

Anup Narayanan, Founder & CEO, Information Security Quotient (ISQ)

She looks trustworthy

I’m gonna steal your toys

Page 2: The difference between the Reality and Feeling of Security

2

Focus of the talk

• The Human Factor in Information Security

• From “Security Awareness” to “Security Awareness and

Competence”

• Solution model

• What others are doing?

Page 3: The difference between the Reality and Feeling of Security

3

Awareness

I know the traffic rules….

Page 4: The difference between the Reality and Feeling of Security

4

Competence?

Does it guarantee that I am a good driver?

Page 5: The difference between the Reality and Feeling of Security

5

Awareness >> Behaviour >> Culture

Awareness

• I know

Behaviour (Competence)

• I do

Culture

• We know and do

An organization must aim for a responsible security culture

Page 6: The difference between the Reality and Feeling of Security

6

What organizations need?

A system that periodically shows the current Security Awareness and Competence Levels

LOW AWARENESSLOW AWARENESS MEDIUM AWARENESSMEDIUM AWARENESS HIGH AWARENESSHIGH AWARENESS

Awareness score is 87%

Competence score is 65%

LOW COMPETENCELOW COMPETENCE

MEDIUM COMPETENCE

MEDIUM COMPETENCE HIGH

COMPETENCEHIGH

COMPETENCE

Page 7: The difference between the Reality and Feeling of Security

The power of perception

Why do people make security mistakes?

Page 8: The difference between the Reality and Feeling of Security

8

Imagine…

Will you accept it?

Nelson Mandela walks into this room right now and offers you this glass of water….

Page 9: The difference between the Reality and Feeling of Security

9

Now, imagine this…

Will you accept it?

This man walks into this room right now and offers you this glass of water….

Page 10: The difference between the Reality and Feeling of Security

10

Question

Which water did

you accept?

Why?

Page 11: The difference between the Reality and Feeling of Security

11

Analysis

People decide what is good and what is bad based on “trust”

Perception is influenced by Trust

Were you checking the water or the person serving the water?

Page 12: The difference between the Reality and Feeling of Security

Why must we address the human factor?

(or)

Is the human factor worth addressing?

Page 13: The difference between the Reality and Feeling of Security

13

Case Study 1

LinkedIn Password leak

Page 14: The difference between the Reality and Feeling of Security

14

The most popular passwords in LinkedIn

link

1234

work

god

job

12345

angel

the

ilove

sex

jesus

connect

monkey

123456

michael

jordan

dragon

soccer

killer

pepper

Page 15: The difference between the Reality and Feeling of Security

Analysis

You may think you are safe when you are actually not

15

People get more terrified thinking of getting eaten by a shark then dying of heart

attack…..but more people die of heart attacks

Page 16: The difference between the Reality and Feeling of Security

Analysis

People exaggerate risks that are abnormal

16

More kids die choking on french fries than due to Adrenoleukodistrophy

Adrenoleukodistrophy

Page 17: The difference between the Reality and Feeling of Security

Reason 1: Security is both a “Reality” and “Feeling”

17

For security practitioners security is a “Reality” based on the mathematical probability of risks

For the end user security is a “feeling”

Success lies in influencing the “feeling” of security

Page 18: The difference between the Reality and Feeling of Security

18

Reason 2: Not every attack(er) is that smart

People exaggerate risks that are spectacular or uncommon:So what? RSA was hacked

Control efficiency

Risk severity/ Attacker

Smartness/ Attack

Efficiency

Technology & Processes

Awareness & Competence

Automatic security controls – AV, Updates

Technology + Human – Firewall configuration, Choosing a secure Wifi

Human – Recognizing a zero day attack, Phishing mails, Not posting business

information in social media

The very smart attacker

1

2

3

4

Page 19: The difference between the Reality and Feeling of Security

Reason 3: Technology…yes, but humans…of course!

19

Aircrafts have become more advanced, but does it mean that pilot training requirements have reduced?

Medical technology has become more advanced, but will you choose a hospital for it’s machines or

the doctors?

Page 20: The difference between the Reality and Feeling of Security

The Solution Model

Security Awareness and Competence Management

Page 21: The difference between the Reality and Feeling of Security

21

The solution is based on HIMIS

• HIMIS – Human Impact

Management for Information

Security

• Released under Creative

Commons License

• Free for Non-Commercial Use

http://www.isqworld.com/himis

Page 22: The difference between the Reality and Feeling of Security

22

Security Risk analysis

Identify the human factor

Awareness

Behaviour (Competence)

Assess, Improve, Re-

assess

ESP – Expected Security Practice

1. Awareness Vs. Competence

Consider both “Awareness” and “Competence” independently

Page 23: The difference between the Reality and Feeling of Security

23

2. Visualize, engage ….and influence perception

Page 24: The difference between the Reality and Feeling of Security

24

Page 25: The difference between the Reality and Feeling of Security

25

3. Remember drip irrigation

Small doses, more frequent

Which is more effective – Drip irrigation or spraying a lot of water once a day?

Page 26: The difference between the Reality and Feeling of Security

26

4. Re-measure frequently

LOW AWARENESSLOW AWARENESS MEDIUM AWARENESSMEDIUM AWARENESS HIGH AWARENESSHIGH AWARENESS

Organization’s awareness score was 87%

Organization’s competence score was 65%

LOW COMPETENCELOW COMPETENCE

MEDIUM COMPETENCE

MEDIUM COMPETENCE HIGH

COMPETENCEHIGH

COMPETENCE

?

?

Page 27: The difference between the Reality and Feeling of Security

27

Threat forecast

Page 28: The difference between the Reality and Feeling of Security

• Natural disasters

• Diminishing end user security awareness

• Moving to cloud

• Social media proliferation & data leaks

• Corporate frauds

• Attacks using GPS tracking

• Economic espionage

• Introduction of new devices (smart phones etc.)

• Online leaks

• Fast development and release of apps without testing

• Smart outsourcing resulting in less workforce loyalty

Emerging threats 2013 (report by ISF)

Page 29: The difference between the Reality and Feeling of Security

29

Summary

Technology (Firewall)

ProcessPeople

Information

Technology and processes are only as good as the people that use them

Page 30: The difference between the Reality and Feeling of Security

Let’s switch ON the Human Layer of Information Security Defence

Thank YouAnup Narayananwww.isqworld.com