Skip to main content

Human Layer Security Magazine: The Rise of Security Augmentation

Page 1

ISE

N TA

THE R

OF S

TION

ISSUE 001

E M EC URITY A UG


Cover Artwork by Cornelia Li


ISE

N TA

THE R

OF S

TION

ISSUE 001

E M EC URITY A UG


02

ISSUE 001

EDITOR’S NOTE

You don’t need us to tell you that the threat landscape is rapidly evolving. Or that the perimeter has disappeared. Or that the stakes are higher than ever when it comes to data protection and cybersecurity. You also probably don’t need a refresher on current events like REVil or Log4j… So, instead of telling you more of what you already know, Human Layer Security passes the mic to security, risk, and compliance practitioners and leaders to share hot takes, best practice, and inspiring anecdotes. After all, the #1 source of information for the security community is…the security community. People are the focus here, and in our first-ever edition, seven contributors cover everything from security awareness training to building a start-up. Want to be a part of issue number two? We want to hear from you. Email us at: contribute@humanlayersecurity.com


Featured in Issue 001 PAGE 06

SECURITY CULTURE

INTERVIEW

How to Lead With Empathy Q&A with Tracy Z. Maleeff Security Researcher at Krebs Stamos Group

PAGE 14

REMOTE WORK

SECURITY AWARENESS TRAINING

The Unwritten Rules of Onboarding Employee Remotely Article by James McQuiggan Security Awareness Advocate at KnowBe4

PAGE 22

AI/ML

THOUGHT LEADERSHIP

The Rise of Security Augmentation Article by Cole Gromus Author and Consultant at Strategy of Security


PAGE 36

HUMAN ERROR

RESEARCH

Employee Burnout Will Cause Your Next Data Breach Article by Jeff Hancock Professor of Communication at Stanford University

PAGE 48

SECURITY CULTURE

INTERVIEW

Why Developers Should Care About Security Q&A with Guy Podjarny Co-Founder and CEO at Snyk

PAGE 56

DATA LOSS PREVENTION

SECURITY AWARENESS TRAINING

How to Minimize the Risk of Data Exfiltration During The Great Resignation Article by Josh Yavor Chief Information Security Officer at Tessian

PAGE 62

COMPLIANCE

THOUGHT LEADERSHIP

How to Equip Everyone to Live More Safely Online Article by April Falcon Doss Author and Executive Director of Law and Policy at Georgetown University


06


SECURITY CULTURE

INTERVIEW

How to Lead With Empathy Q&A by Tracy Z. Maleeff Artwork by Emanuel Santos


In a RE: Human Layer Security Podcast episode, Tracy Z. Maleeff (a.k.a. The “InfoSec Sherpa”) explains why it’s so important for security leaders to lead with empathy to help get employees on-side and protect their company from threats like phishing and malicious insiders.

At the time of this Q&A, Tracy was an Information Security Analyst at the New York Times. She is now employed by the Krebs Stamos Group. Listen to the whole episode at humanlayersecurity.com/podcast or on Apple, Spotify, and read on for the highlights.


09

What is your advice to people who are trying to start a career in security, especially if their previous career experience isn’t from that area? Q

A couple of things. The first one is networking, networking, networking. And I mean people and computers. If you don’t have a tech background, I always tell people to pick up the CompTIA Network+ book or whatever equivalent suits you. You need to understand how information is processed—or travels through “the interwebs”—so that you can understand what you're doing and what you're talking about. But it's also networking with people. Get out and talk to people. Ask them about their greatest failure and how they recovered from it. I have found that people love to talk about themselves, they take a point of pride in demonstrating their resilience and what they've learned from something. So that's always a fun icebreaker question. In fact, I've never had anyone scoff at that question. People usually light up and are excited to tell me about a time they wiped the logs or did something that they weren’t supposed to, and how they recovered from it. The other thing I would recommend is staying on top of the news—being able to speak, even just briefly, about what's going on in the world as it relates to cybersecurity. True story: the day of my job interview to be a security operations center analyst was the

same day as WannaCry. Now, when I woke up that morning, I started to hear some news, and I don't think at the time we had a name for it yet. We just knew that something was going on—mostly in the UK, mostly with the NHS. We didn't know much. But I remember thinking to myself: “If I were interviewing me today, I would ask me my thoughts about this topic, and maybe to ask for some examples of how I would remediate it.” And that's exactly what I did. I had about a 45-minute drive to the interview. I listened to a news channel to learn everything that I could about it. And sure enough, the very last question was, “There seems to be something developing today, what do you know about it?” And they actually said, “Give us three ways you'd remediate it.” And because I was aware of what was going on and I anticipated questions, I was able to knock that out of the park.


As a former librarian moving into the security world, what did you see for the first time? Have you been able to see things that others haven’t by bringing a fresh perspective? Q

Oh absolutely. That’s how my “Empathy-as-a-Service to Create a Culture of Security” talk came about. I was shocked to see how people in the industry regarded users. But that’s the dirty secret in the librarian world, too. A lot of librarians like to complain about library users. They’re not necessarily open about it… Well, maybe on librarian Twitter they’re open about it…

Thin k

But I was observing a lot of what felt like openly hostile attitudes that InfoSec people had towards end-users. And that really

shocked me. Because empathy—understanding what a user is asking for—is foundational in library science. So that really threw me for a loop when I first started, and it made me think a lot about my library science roots. There’s this seven-step process of helping library users called a “reference interview,” and I created a whole talk around these seven steps.

out things like... ab

How do you avoid making assumptions?

How can you listen to what the end user is not saying, in order to help them? How can you listen differently? How can you approach problems differently?


11

I always give the example of how a user will say, “I saw an email that looked suspicious. I clicked on a link, I went to the site, I closed the browser, and then I called you.” So my question is, “OK, well, what transpired between opening the browser, looking at the website, and closing it?” And this has actually happened to me—I’ve had people say, “Oh, well, it asked for a username and password, I entered it, and the site didn’t do anything, so I just closed it.” Well, they just gave away their username and password and they didn’t mention it the first time. Perhaps because they didn’t think it was important, because the “website” didn’t work—maybe they thought it didn’t go through. Or maybe they were scared to admit what they did beacuse they didn’t want to get fired.

So having that empathy and that keen listening skill, to circle back around and say: “Let’s hone in on this: what transpired there?” That’s something that I’ve been really trying hard to emphasize. I’m not asking people to feel sorry for end users. I’m just asking them to remember what it’s like to be scared of something that’s different. You didn’t always know how to code; you weren’t born with that skill. You messed up at times, and things felt scary. So, I think that’s the difference between the people who’ve been in tech or security for a long time and those of us who come into it from a different realm. We have that different perspective and a different way of doing things, and I feel like technical people forget what it’s like to have computers and websites be scary, and I want people to remember that.


Why do you think the security industry has this default hostility towards the “human in the loop?” Why do you think that, as an industry, we generally believe it’s on the person to make the right decision from a security perspective? Q

12

That’s a tough question. I’m trying to figure out how to diplomatically answer that... I think some of it just stems from security initially being born out of tech, which historically was always “a room in the basement”—just the forgotten scary place… And I think tech and security weren’t woven into the workplace early on, so it always had this “others” kind of feeling.

not necessarily all the tech workers have. We hear how much diversity and inclusion is lagging in tech, so I feel like the people haven’t kept up with all the technological changes that computers have seen.

They’re still kind of that old school “sheriff” mentality: “I’m the one who does security I also think here, and you listen to me!” the skill set that one needs to be good at tech is that “ones and zeros” kind of attitude. It doesn’t really leave room for humans. Technology has evolved—but

People can change once they see examples, so that’s why I do my best to lead by example.

And I encourage others to, as well, because I think that some folks don’t even know what it means to be empathetic, and maybe need some examples.

Tracy Z. Maleeff Security Researcher at Krebs Stamos Group Tracy is an Information Security Professional with a Master of Library and Information Science degree. She’s a frequent author and speaker on InfoSec and research topics, and has presented at several industry conferences. Known as the “InfoSec Sherpa” (@InfoSecSherpa), she maintains an OSINT blog and cybersecurity newsletter, and is committing to being “your guide up a mountain of information”.


14

REMOTE WORK SECURITY AWARENESS TRAINING

The Unwritten Rules of Onboarding Employees Remotely Article by James McQuiggan Artwork by Pete Gamlen


I got into security awareness over 15 years ago. Back then, cybersecurity training consisted of a lunch and learn with a PowerPoint presentation, and perhaps some donuts to entice people. You may also have had computer-based training where you go through and click ‘next’ repeatedly until you reach a 5-question multiple-choice quiz. That was it. You might remember the information, you might not. Most of the time, if you weren’t interested, you wouldn’t. The new school approach to security education is based on totally different concepts and includes a variety of different factors. It is not just computer-based training once a year. At its core, the new school version must be engaging and interesting, and needs to appeal to the end-user…especially now that employees are being onboarding and working remotely.


17

Onboarding new users remotely VS. In a physical office Between the COVID-19 pandemic and the Great Resignation, the world has more people working from home (WFH) than ever before. In fact, according to the Wall Street Journal, only 33% of people have returned to the office since the vaccine rollout. And as more and more people are WFH, organizations face new challenges around onboarding new employees. There’s also the issue of people leaving. Research shows 55% of employees are considering leaving their current employer this year and two in five (39%) are currently working their notice or actively looking for a new job in the next six months. This churn has the most significant impact on the Information Technology (IT) and Human Resources (HR) departments.

So, what are the unwritten rules of onboarding employees securely? It starts with HR. But let’s be honest. Coordinating new resources like laptops, phones, security tokens, ID badges, a desk to work, enrollment into the computer-based training, and possibly on-the-job training was hard enough in a physical office. But now? With remote and hybrid set-ups? It’s much more complex. HR and IT departments have to provide all new employees with their equipment on time, ready to go on day one, to prevent new starters from using their personal computers to log into the organization’s resources.


Starting in March 2020, onboarding teams have had to rewrite policies to address the WFH environments. Instead of getting incoming cohorts set-up at a physical desk, 18 onboarding teams now have to arrange for the delivery of new employees’ work machines and all accessories like monitors, mice, and other hardware. All of this just to get them online. In-person inductions have been replaced with online training, which means it’s essential that training presentations (whether related to data privacy or company policies) are interactive. HR and onboarding processes must be engaging, tailored, and make new starters feel welcome. But, it’s not just the first week or two that’s important. Employees need ongoing training to help them stay connected and safe.


The importance of Security Awareness Training (SAT) As employees ramp and take on more responsibility, security awareness training along with an understanding of their organization’s security culture becomes critical. The end-user should feel a connection to it so that they’re compelled to take an interest in security... to make them think twice about clicking a phishing link, or reusing a password. Helping employees connect with security will drive an overall security culture change. If users don’t relate to it, they’re not going to care. New users should receive their first phishing assessment and check their social engineering knowledge within a few weeks of starting. That’s because anyone with an email address for the organization holds a proverbial key through the electronic front door for cybercriminals to access the user’s system, and the organization’s data and networks. Plus, new starters are prime targets for bad actors.

But it’s essential to communicate these things without invoking fear. Phishing assessments shouldn’t be about “catching” people out. Humans don’t like to get caught. That can breed anger and frustration. It has to be a learning moment, not a “gotcha!” moment. You have to give people a chance to get better. That’s because humans can (actually) be cybersecurity’s strongest asset. While - yes - well over 50% of data breaches are the result of some kind of human interaction – whether someone misconfigured a firewall or a user clicked on a phishing email… that doesn’t mean that humans are the weakest link when it comes to cybersecurity. It’s not that simple.

Phishing assessments shouldn’t be about “catching” people out. Humans don’t like to get caught. That can breed anger and frustration. It has to be a learning moment, not a “gotcha!” moment. You have to give people a chance to get better.

19


A recent report from an identity resource group analyzed a variety of different organizations and their budgets. The report revealed that about 3% of the average 20 organization’s cybersecurity budget goes towards training – towards the human aspect. That’s just 3% on training your developers, training your security team, and security awareness training for employees.

you’ve got so many data breaches being caused by human action, that’s not a lot of money. People love to say that humans are the weakest link, but I think that humans can be the strongest link; companies just aren’t training them. And it all starts with onboarding.

So only $30,000 of a $1 million dollar budget would go towards training, and when

How do you keep new employees engaged? CYBER MUNCHIES

Give Away People like free stuff, and offering up lunch, coffee, or organizing a virtual happy hour (whatever is most aligned with your company culture) is a great way to reward people for their involvement in SAT. For example, a friend of mine is a CISO at a law firm and he runs a monthly contest. Whoever spots the most phishing emails gets their name on the notice board and a $25 gift card for coffee. What has become clear is that the employees could not care less about the gift card! They want to see their name on that list – and they want to see it at the top – it’s a competition for them.

Freebies


MAKE IT SPECIAL

Keep Things Interesting

Consider some of the training sessions you must do – accounting, finance, or expenses. It is very difficult to learn if you are only doing it because your boss told you to, and you don’t really care about the subject.

One of the best ways to keep new employees engaged is to have separate, “special events” as a part of the onboarding process every day. It could be having virtual trivia based on GDPR requirements, or having the Chief Information Security Officer (CISO) dial-in to do an open Q&A with the new employees. You get the idea.

ONGOING SUPPORT

Regular

Check-ins

Have a daily morning check-in with groups of new hires, whether it’s a five-minute or fifteen-minute call. It’s an excellent opportunity to remind them of everyday events, meetings, and other important information they’ll need to settle in and ramp up.

James McQuiggan Security Awareness Advocate at KnowBe4 James is a Security Awareness Advocate at KnowBe4, where he trains and engages with employees and security leaders about the importance of security awareness training. He also teaches Identify Security at a collegiate level and is the Education Director for the Florida Cyber Alliance.


22

AI/ML

THOUGHT LEADERSHIP

The Rise of Security Augmentation Article by Cole Gromus Artwork by Cornelia Li


As technologists, we’ve all been convinced that automation is the solution to our problems. But augmentation is what we really need. We just don’t know it yet... There is no discipline where this is more true than security. We’re constantly outmatched and under-resourced. Threats come at us from around the globe and at any time. The better we can scale the limited number of humans we have to protect our companies, the safer we will be. The roots of our false sense of belief in automation are deep-seated. Take a look at marketing for nearly any security product. You’re bound to see automation as one of the core value props. When a belief is so pervasive, it’s hard to avoid it without consciously taking a step back to reexamine its accuracy. Why do we allow ourselves to fall for this too-goodto-be-true story? Because we’re human, and humans are fallible. The promise of automation makes us believe the right tool can make our problems go away. And let’s face it: our companies would love for their security problems to magically disappear. This is where our trouble begins. We either fall into the trap and put too much faith into automation, or we put up our defenses and become skeptics. We need to reframe our positive or negative views on automation and form a more nuanced opinion. To accomplish this, we need to reevaluate our beliefs about automation and establish a new mental model about when to use automation, augmentation, and human intelligence.


The spectrum of security automation beliefs

LEVEL OF CONVICTION

HIGH LEVEL OF CONVICTION

The first step towards determining when to use automation in our security programs is to understand where we fall on the spectrum of beliefs about security automation. The paradigm many of us follow tends to gravitate towards one end of the spectrum.

LOW LEVEL OF AUTOMATION

On one extreme, we’re so bullish on automation that we’ve falsely convinced ourselves we can automate everything. We try to automate tasks that have no business being automated, almost as an act of defiance. Or, on another extreme, we’ve been burned so badly that we believe humans are the only reliable way to get things done. We insist on doing everything manually, even if it’s prohibitively expensive or tedious to do so.

HIGH LEVEL OF AUTOMATION

25


If we can convince ourselves to prioritize augmentation over highly manual or highly automated processes, we end up with a more moderate and balanced view. The ideal mix for getting important work done is a combination of automation, human intelligence, and the true force multiplier: augmentation.

HIGHLY AUGMENTED

LEVEL OF CONVICTION

26

The paradigm of the future looks different. By reframing our mindset around the traditional view of automated vs. manual, we unlock a powerful new model.

LEVEL OF AUTOMATION


A prioritization model for security augmentation 27

Some forward-thinking leaders have already started to adopt this new augmentation-first paradigm. On a recent CISO Series podcast episode, LinkedIn CISO Geoff Belknap shared his perspective on automation:

“I’m not disappointed by what automation has delivered, but I think I have taken a very realistic view of what automation could do. Which is make smart humans able to make faster decisions, make better decisions.”

One way to help ourselves adopt this mindset is by using a model to guide our decision making. In our day-to-day lives as security professionals, most of our decision-making comes

down to risk and urgency. Consciously or unconsciously, we spend our days triaging the tasks that come at us along these two vectors. As a result, they’re the axes in our model. Our decision about the best way to execute different types of work comes down to specific criteria for each quadrant in the model. Based on where tasks map on the scale of risk and urgency, we can determine how to approach the work and the types of tools we should be using.

Expertise

RISK

This is exactly the mindset we need to take towards automation. First, be realistic about what automation is capable of. With that expectation, focus on areas where augmentation can help humans make faster and better decisions. That’s the winning formula.

Augmentation URGENCY

Repetition

Automation


HIGH RISK HIGH URGENCY

Augmentation Tasks that are both high risk and high urgency should be augmented using a combination of human intelligence and machines. This is the area where both speed and quality matter. Any gains in speed from machines or judgment from humans can make a big difference. A few ideas specific to security are outlined in the next section.


29

LOW RISK

HIGH URGENCY

Automation Tasks that are low risk and high urgency are good candidates for automation. They’re important enough to be done, but not complex enough where human intervention is valuable. Let the machines do the fast, repetitive work. Processes like access provisioning are great candidates for automation. Once roles or business rules have been established and applications have been integrated with access control systems, certain access can be automatically granted for every new employee. Human intervention is only needed for exceptions or errors.


30

HIGH RISK LOW URGENCY

Expertise Tasks that are high risk and low urgency typically require expertise, or human intelligence, to be completed. They’re complex enough that creativity and time to weigh potential options is valuable. People with specific expertise are best suited for this type of work. Security strategy, architecture, and engineering are inherently creative exercises. They’re high risk because the wrong strategy, architecture, or system design can have catastrophic consequences. However, machines can contribute relatively little to the creative process. In this case, it’s best to let the experts do their work.


LOW RISK

LOW URGENCY

Repetition Tasks that are low risk and low urgency but still need to be done can be executed through manual repetition. As much as we’d like to augment or automate everything, we have to prioritize. Sometimes a manual process is good enough. For example, monitoring and following up on security policy exceptions is a repetitive task that’s more effective with a human touch. Instead of sending out automated reminders that are easy to ignore, it’s often better for a human to do the work.


Security augmentation in the real world 32

New tools create new opportunities for augmentation in security. Here are a few ideas about how to start using augmentation in your own work.

Risk and Compliance

Fraud Detection An early example of human augmentation in security is PayPal’s approach for fighting fraud. As recounted by Peter Thiel in Zero to One, the young company had more than $10 million losses from fraud each month. PayPal engineers first built an automated system that was ineffective because fraudsters adapted their techniques. However, they discovered an augmented approach was highly effective. Thiel described the incredible results: “This kind of man-machine symbiosis enabled PayPal to stay in business, which in turn enabled hundreds of thousands of small businesses to accept the payments they needed to thrive on the internet. None of it would have been possible without the man-machine solution—even though most people would never see it or even hear about it.” Instead of relying solely on automation, PayPal added the power of human judgment to mitigate fraud. The solution was so impactful that it saved the company.

Risk and compliance is a notoriously manual process that is starting to see the benefits of augmentation. A new generation of continuous compliance tools like Drata, Secureframe, and Vanta has entered the market. Augment your compliance teams with these tools to manage evidence collection workflows, reporting, and testing. Save your people for designing controls, interpreting results, and remediating any issues that come up. When implemented effectively, you can reduce your compliance timelines from months to weeks.


Incident Detection and Response When investigating security incidents, one of the biggest challenges engineers have is quickly and accurately identifying anomalous events. More data means more false positives. That’s a distraction when time is of the essence. Incident detection and response engineers can augment themselves by iteratively building automated detection rules as they see anomalous events in the environment. High quality rules benefit the entire team by cutting down on false positives so real incidents can be identified faster.

Cloud Configuration Management Monitoring and maintaining cloud security configurations is a daunting task, particularly in multi-cloud environments. One small change can open a gaping hole and expose your cloud infrastructure to significant risks. This process can be augmented by continuously scanning your cloud configurations with cloud workload protection platforms. Automating checks for misconfigurations means you’ll find them faster and don’t need humans to intervene until anomalies are found.

Application Security Testing Engineering teams are continuously under pressure to move fast and ship. Manual application security reviews add friction and decrease velocity. Security teams can be augmented by embedding automated vulnerability scanning into development and build processes. Using automation strategically can allow your security teams to focus manual reviews on specific areas of risk and save hours of effort for each release.

Email Security Employees send and receive thousands of emails per day and are continuously targeted by attackers. As Forrester noted in a recent study, security teams spend up to 600 hours each month addressing email security incidents. It’s impossible to keep up with all the threats your employees are facing. Augment your employees and security teams using platforms like Tessian to alert users when they’re seeing a suspicious email or potentially sharing sensitive data. Engaging people in-the-moment is far more effective than investigating incidents and remediating data loss after they’ve occurred.


Security’s augmented future The next evolution of security is going to be led by augmentation, not automation. The greatest value comes from combining humans and machines and letting each do what they’re best at. In the famous words of mathematician Richard Hamming:

“Machines should work. People should think.” It's unfair to view tools as magic bullets. They're not going to solve all our problems. However, it's equally as unfair to view tools as enemies. We can't expect people to do everything on their own — they need tools. Top security leaders are making strategic choices about how and when to use automation, augmentation, and human intelligence. The stakes are higher than ever. The right choices can be the difference between a good night's sleep and becoming another news headline.

Cole Grolmus Author and Consultant at Strategy of Security Cole writes Strategy of Security and advises enterprises, startups, and investors on strategic cybersecurity projects. He was previously a Director in PwC’s Cybersecurity, Privacy, and Risk practice and the cofounder of an enterprise SaaS startup.

35


36


HUMAN ERROR

RESEARCH

Employee Burnout Will Cause Your Next Data Breach Article by Jeff Hancock Artwork by Sua Balac


Understanding how stress impacts your employees’ cybersecurity behaviors could significantly reduce the chances of people making mistakes that compromise your company’s security. Consider this. Research shows a shocking 93% of employees feel tired and stressed at some point during their working week, with 1 in 10 feeling tired every day. And perhaps more worryingly, nearly half (46%) said they have experienced burnout in their career. Then consider that nearly two-thirds of employees feel chained to their desks, as 61% say there is a culture of presenteeism in their organization that makes them work longer hours than they need to. Nearly 70% of employees also agreed that there is an expectation within their company to respond to emails quickly. Employees are overwhelmed, overworked, and are feeling the pressure to keep pace with their organization’s demands.


The effects of the pandemic are still being felt In the wake of a global pandemic, people have experienced extremely stressful situations that affected their health and finances, against a backdrop of political uncertainty and social unrest, while simultaneously juggling the demands of their jobs. The shift to remote working has also meant that people are (still) surrounded by new distractions. It’s no wonder over half of respondents (57%) say they feel more distracted when working from home.

So, why am I telling you all of this? Because people tend to make mistakes or decisions they later regret when they are stressed and distracted. That’s because when our cognitive load is overwhelmed, and when our attention is split between multiple tasks, we aren’t able to fully concentrate on the task in front of us. We can all relate, I’m sure.

39


42

What does this mean for security? Not only are these findings incredibly concerning for employees’ health and wellbeing, these factors could also explain why mistakes that compromise cybersecurity are happening more than ever. The majority of employees (52%) said they make more mistakes at work when they are stressed. Younger employees seem to be more affected by stress than their older co-workers, though. Nearly two-thirds of workers aged 18-30 years old (62%) said they make more mistakes when they are stressed, compared to 45% of workers over 51 years old. The research also revealed that 43% and 41% of employees believe they are more error-prone when tired and distracted, respectively. In fact, people cited distraction as the top reason for why they fell for a phishing scam at work while 44% said they had accidentally sent an email to the wrong person (44%) because they were tired. While these mistakes may seem trivial on the surface, phishing is the number one threat vector used by hackers today and one in five companies told us they have lost customers as a result of an employee sending an email to the wrong person. Far from red-faced embarrassment, these mistakes are compromising businesses’ cybersecurity. The other problem is that hackers are preying on our vulnerable states, and using them to their advantage. Cybercriminals know people are stressed. They also know a lot of people are looking for new jobs as the Great Resignation has turned into The Great ReEvaluation. The lure of a ‘too-good-to-be-true’ deal or ‘get a new job fast’ offer may suddenly look very appealing, especially if the email appears to have come from a trusted source.


52%

MAKE MORE MISTAKES AT WORK WHEN STRESSED

62%

18-30’S MAKE MORE MISTAKES AT WORK WHEN STRESSED

43%

EMPLOYEES BELIEVE THEY ARE MORE ERROR PRONE WHEN DISTRACTED

41%

EMPLOYEES BELIEVE THEY ARE MORE ERROR PRONE WHEN TIRED

45%

OVER 51’S MAKE MORE MISTAKES AT WORK WHEN STRESSED

44%

SENT AN EMAIL TO THE WRONG PERSON BECAUSE THEY WERE TIRED


44

So what can businesses do to protect employees from mistakes caused by burnout? Business and security leaders need to realize that it’s unrealistic for employees to act as the company’s first line of defense. You cannot expect every employee to spot every scam or make the right cybersecurity decision 100% of the time, particularly when they’re dealing with stressful situations and working in environments filled with distractions. When faced with never-ending to-do lists and back-to-back Zoom calls, cybersecurity is the last thing on people’s minds. In fact, a third of respondents said they “rarely” or “never” think about security when at work. Businesses, therefore, need to create a culture that doesn’t blame people for their mistakes and, instead, empowers them to do great work without security getting in the way. Understand how stress impacts people’s cybersecurity behaviors and tailor security policies and training so that they truly resonate for every employee.

“Educating people on how hackers might take advantage of their stress and explaining the types of scams that people could be susceptible to is an important first step.”


For example, a hacker could impersonate the Head of IT, supposedly reaching out to set-up new work accounts, and ask the employees to share their account credentials. Or a hacker may pose as a trusted government agency requesting personal information in relation to a vaccine passport scheme.

Step number two? Prioritizing employee wellbeing. Phishing will always be a threat, but that doesn’t mean people should constantly worry and keep their guard up — that would be exhausting. A simple combination of awareness and self-care when online can make a big difference. Once employees know the tactics a hacker might use and the psychological factors like stress, emotions, and distraction to look out for, it will be easier for them to spot an email scam without the anxiety. It will also help to encourage work-life balance. Make sure employees are, actually, stepping away from their computer when they can, and make sure managers have constructive conversations about the pressure to be “always-on” when working remotely, and the potential negative impact psychologically.

Jeff Hancock Professor of Communication at Stanford University Jeff is the Harry and Norman Chandler Professor of Communication at Stanford University. He’s well-known for his research on how people use deception with technology, and his work has been published in over 80 journals.

45


Sign Up Now SIGN UP TO THE HUMAN LAYER SECURITY NEWSLETTER

Subscribe to our monthly email newsletter for the latest cybersecurity insights. We publish new articles and interviews online every week. Sign up and find many more articles, podcasts, and video content at our home on the web. (And invite your friends to subscribe, too)

Find Us at humanlayersecurity .com


SECURITY CULTURE

48

INTERVIEW

Why Developers Should Care About Security

Q&A With Guy Podjarny Artwork by Quinton Winter


In a RE: Human Layer Security Podcast episode, Guy Podjarny, Founder and President of Snyk, explained why he believes decentralized application security is no longer a “nice-to-have”, and the benefits of putting security in the hands of developers.

Listen to the whole episode at humanlayersecurity.com/podcast or on Apple, Spotify, and read on for the highlights.


51 Q

Why did you start Snyk and what’s your mission?

I’ve been working on application security for over a decade now, and I’ve seen the market evolve quite a bit. But I’ve always been guided by the idea that application security should be put in the hands of developers. In the first wave of the DevOps movement, I left IBM and founded a web performance company. I was really engaged in the community and learned to appreciate the changes to development that DevOps has brought to bear. Snyk represents the realization that security needs to be embedded into development, and that it isn’t just a “nice-to-have” or an optimization play. It’s a musthave, and companies need to cater to developer’s needs. The idea was to create a developer-tooling company that tackles security, and the key for us was to think about the user—not just the buyer; to think about the developer as the primary user. We call this “developer-first security”, and ask ourselves:

What would it take to get a developer to embrace security? ASK 1

What would it take to get a developer excited by a solution that helps them tackle security? ASK 2

What would it take to break through and embed security into the development process? ASK 3


52

How do developers think about security vs. security professionals? Q

Where security professionals focus more on breadth, developers focus more on depth. When someone working in cybersecurity sees a vulnerability, they think about risk. They zoom out. If they hear “vulnerable log4j library”, their first questions will be around how exposed they are. When a developer hears about the same issue, their default action is to zoom in on their particular application. Their first questions revolve around functionalities, performance, and scalability. And it makes sense. If you think about the actual job of someone working in cybersecurity, their job is to understand, identify, and help reduce risk. Even though they care about fixing the issues, that’s not their job. That’s the developer’s job.

Why is security a must-have and not just a nice-to-have? Q

The world is increasingly dependent on software being built by independent teams that move fast. The faster you can get a line of code in the hands of a customer, see what the customer has done with it, then adapt to those needs and change the code…the better. The tighter that feedback loop, the better the business does.

The problem is, security tends to get in the way of this process. It remains centralized, requiring things to be reviewed, audited, and supervised— it doesn’t empower teams to work independently, which slows them down. And that’s a problem that has to be solved. Fundamentally, it’s only the companies that make security a seamless part of their processes that will succeed financially and thrive.


54

Q

How has Snyk confronted friction between developers and security?

Simplification is key. As humans, the equation is simple: you have to care about something more than it burdens you. Caring could be related to consequences, pride, money….there are a variety of reasons why you might care about something. As a company, Snyk tries really hard to communicate why developers should care. The problem is, for most developers, there was no real incentive to care about security.

They didn’t get recognition from security teams, and it slowed them down in shipping features of capabilities. Lose-lose. The primary thing that we’ve done is simply make it easier for them. Don’t get me wrong, we do our fair share of explaining the “why” and “what-ifs”, but our success boils down to simplifying security. We make it easy to pick up, use, connect, and integrate seamlessly. It’s a part of their natural code reviews.


Q

How can companies embed security into their business? 55

Security carries the risk of either being too restrictive or too easy to ignore or work around. The key is to make it collaborative. Instead of having it be dictatorial, it needs to be decentralized, just as we’ve done with the Operations department, before the DevOps change. A decade ago, Ops was the department of “no”. They were the ones slowing things down. They were ticket-operated, teams weren’t incentivized to help, and instead maintained the “status quo”. But today, DevOps teams are platform builders. They’re enablers. They’re empowers. They aren’t just focused on risk; they’re focused on unlocking business value. That’s the same transition we need to see with security.

This notion of a “blameless post-mortem” is one of the key strengths of the DevOps movement. When there’s an outage, you seek out the root cause and how to fix it as opposed to the person. It’s not about finding who to blame, it’s about finding the problem and addressing it.

Guy Podjarny Co-Founder and CEO at Snyk Guy is the co-founder and CEO at Snyk.io, focusing on open source and cloud security. He was previously the CTO at Akamai, following their acquisition of his start-up, and has been an evangelist for web performance, DevOps, and applications security for well over a decade.


56


DATA LOSS PREVENTION

SECURITY AWARENESS TRAINING

How to Minimize the Risk of Data Exfiltration During The Great Resignation Article by Josh Yavor Artwork by Lisk Feng


While - yes - data exfiltration, “bad leavers”, and insider threats have been top of mind for security leaders for decades, there’s suddenly a renewed sense of urgency to solve these problems. Why? Three words: The Great Resignation. The trend has continued well into 2022, with record high numbers of people quitting their jobs and seeking opportunities for better positions, better pay, better work/life balance and even exploring a career in a completely new industry.


59

WHAT IS THE GREAT RESIGNATION? The Great Resignation, also known as the Big Quit, and more recently as the Great Re-Evaluation, is an ongoing economic trend in which employees have voluntarily resigned from their jobs en masse, beginning in early 2021.

Is the Great Resignation really a problem for security teams? I hate to be the bearer of bad news, but yes… According to a recent survey 55% of people are considering leaving their current employer this year, with two in five (39%) workers currently working their notice or actively looking for a new job in the next six months. These numbers didn’t shock me. In fact, I’d argue the number is much higher. 45% of IT leaders say incidents of data exfiltration have increased in the last year as people took data when they left their jobs.

And we have every right to be worried. One in three (29%) employees admitted to having taken data with them when they quit. The figures were much higher in the US, with two fifths of US employees (40%) saying they’d taken data with them when they left their job. But I’m not a glass-half-empty sort of guy. So, instead of looking at the problem, let’s talk about the solution.


Prevention is better than cure 60

There are of course various security solutions that can help you monitor and limit data movement. But the problem doesn’t start when employees get itchy feet. It goes all the way back to onboarding. That’s because most employees don’t even know that taking data is a no-no. So when they take data (whether it’s a list of contacts, a sales deck, or a scorecard), their behavior is intentional, but not malicious.

They don’t actively want to cause harm to the organization that they’re leaving. They (generally) don’t have plans to sell data to a competitor or the dark web – although it has certainly happened. They simply have a belief that because they worked on it, it’s theirs to take and, more often than not, are just trying to be the best employee they can be for their new gig. We can all relate.

This distinction between intention and malice is very important, and underscores the value of clearly communicating expectations and boundaries from the outset. So, what does this look like? At the security-level, it’s important to communicate the consequences of data exfiltration for both the individual and the company, without threatening employees or “making an example” of previous mistakes. Likewise, direct managers must constantly reinforce the importance of data protection, and clearly define what is actually acceptable to move outside of the company network (if anything). At every level, the key is to make it clear that data exfiltration attempts are unethical, could represent an illegal data transfer, and could land everyone involved in regulatory hot water.


Best practice for offboarding checklists A lot of the heavy lifting can (and should) be done early in the employee lifecycle, we absolutely cannot overlook the importance of a thoughtful, comprehensive, and closely monitored offboarding process that reinforces expectations at the time notice is given. HERE ARE 5 MUST-HAVES FOR EVERY OFFBOARDING CHECKLIST:

Give people a secure way to get personal documents (like family photos) off their work laptop. Limit or remove employee’s access to corporate accounts and assets, and transfer their ownership of any systems. Change passwords on any shared accounts. Modify physical access control to prevent exemployees from physically accessing your office. Back-up and wipe corporate data that is stored on the employee’s personal devices.

Josh Yavor Chief Information Security Officer at Tessian Josh is CISO at Tessian, leading information security, threat intelligence, and security research. Most recently he served as CISO for Cisco Secure and led cloud security for Duo Security, with earlier stops at Facebook, Oculus, and iSEC Partners. Josh is an aspiring woodworker and recovering middle school teacher.

61


62

COMPLIANCE

THOUGHT LEADERSHIP

How to Equip Everyone to Live More Safely Online Article by April Falcon Doss Artwork by Hady Tse


You shouldn’t have to be an expert to understand what happens to your data. And yet, data-driven technologies have expanded so quickly over the past 20 years that many – perhaps most – people struggle to understand what it means for them. What kinds of data they generate as they go through everyday life, who is collecting that information, and how that data is being used: to manipulate their viewpoints, to recommend or deny them opportunities, and to influence nearly every aspect of their lives in work, school, health care, insurance, finances, in their personal relationships, and even to shape the society – the culture, politics, public health, and civil discourse – that they participate in every day.


65

Growing concerns around data privacy: DNA testing, social media, remote work, and beyond This January 28, nations throughout the world marked the sixteenth annual Data Privacy Day. The occasion was first commemorated by the Council of Europe in 2007 in response to concerns about the privacy-eroding impacts of automated data processing. In the sixteen years since, those concerns have, if anything, grown – and it’s become harder than ever for an average person to understand what’s happening to their data, and why they should care. Part of the challenge is that, all too often, the ways that personal data impacts individuals and society are hard for the average user to see. Not many users realize all the risks associated with participating in

modern online life; and even when they do, many don’t know what practical steps they might be able to take in order to achieve a balance between privacy, convenience, entertainment, and utility that will be more in line with their personal level of comfort and concerns. Despite this murky sense that it’s hard to know exactly what’s going on underneath the algorithmic hood, we all intuitively sense that data-driven technologies are reshaping nearly every aspect of everyday life. It’s no wonder, then, that so many internet users sympathize with sentiments like the one of a former tech CEO who wrote, “Privacy is dead, and social media holds the smoking gun.”

“Privacy is dead, and social media holds the smoking gun.” This widespread feeling that people don’t trust big tech with their privacy isn’t limited to particular platforms or technologies. According to a 2020 recent survey, threequarters of adults believe they have little control over personal information collected about them; 86% of adults are very concerned with how free online services use their data; and nearly seven out of ten are

very concerned about the security of online shopping and the privacy and security of devices like smartphones and tablets, fitness trackers, smart speakers, and other internetenabled devices. And with good reason. Not long after internet use became ubiquitous in commercial and social life for everyday people, examples of online harms began to mount.


A quick recap of the past twenty years helps put the challenge in context.

2003

The human genome is mapped, paving the way for the inexpensive DNA testing that’s being used for everything from mapping family trees to medical diagnoses and assessing ethnicity to matching dogs with errant poop that their owners have failed to clear from community-owned land – all raising privacy concerns along the way.

2004

Facebook is launched, evolving in less than twenty years to a platform used by more than three billion people worldwide and underpinning a tech business empire of social media and chat messaging functions that have reshaped small business advertising, the news industry, and content promotion, and – for users of WhatsApp – formed the backbone of communications in countries around the world. 2007

The first iPhone is released, leading to a digital environment in which today more than 300 million users in the United States and 6 billion subscribers worldwide carry palmsized, and staggeringly powerful, computers with them at nearly all times of day.


The number and variety of smart devices in our homes have expanded to include not just TVs, but video doorbells and security systems, smart toilets, stoves and thermostats, childrens’ toys and nanny-cams, and voice-activated digital assistants that serve up music, jokes, and weather reports, and listen attentively for our every command. Schools have been transformed with digital assistants in the classroom, facial recognition cameras in classrooms and in school hallways, videoenabled proctoring software for remote test-taking, and – of course – through the pandemic, online classes on Zoom. SINCE THEN

The workplace has been similarly transformed. Employers expect 24/7 email responsiveness, and can track their staff’s location and activity on work-issued smartphones; employee ID badges are RFIDenabled, tracking a user’s location in the workplace in minute detail; video surveillance monitors against theft;

and keystroke logging and webcams attempt to make sure that personnel working from home aren’t wasting company time. And information about us is being used on the job with an ever-expanding set of 67 consequences. Artificial intelligence algorithms trained on personal data are continuing to reveal disturbing civil rights implications in everything from job applicant screening to ride-share services and engaging in real estate transactions. Even our interpersonal relationships are changing, as “spouseware,” revenge porn, cyberstalking and sextortion, and cyberbullying allow deeply malicious use of technology to harass, threaten, and intimidate current and former spouses, partners, and love interests. Society as a whole is bearing the brunt of this and we needn’t look any further than collective impact of the viral spread of election-related hoaxes, COVID disinformation, extremism, and conspiracy theories of all kinds.

All of these risks and harms are made possible by a few common threads: the rise of cheap data storage, the steady growth of computer processing capacity, and the seemingly-unlimited troves of personal information that are created, collected, processed, analyzed, and used by the myriad platforms, devices, systems, and apps that each of us interact with in our daily lives.


The (marginal) impact of data privacy regulations 68

In an early attempt to stave off some of the pitfalls of the internet, the first data breach notification law was passed by California in 2003, requiring holders of certain kinds of information – Social Security number, payment card details, and the like – to notify individuals if their protected information was accessed by someone unauthorized, or was otherwise compromised. At the same time, federal law was imposing data privacy and security obligations in particular contexts, such as in the healthcare and financial services sectors.

By 2018, every major jurisdiction in the U.S. had a data breach notification law, and similar data breach obligations had also been incorporated into the General Data Protection Regulation (GDPR) that applied directly throughout the European Union and set a benchmark that influenced privacy and data protection laws around the world. And, jurisdictions such as California and the EU enacted privacy laws that required more detailed information to be provided as part of obtaining user consent for the collection and processing of certain kinds of information. Online harms are hardly limited to data breaches, however, and the rise of new privacy laws has done little to assuage the concerns that people have about how their information will be used. According to the Internet Crimes Complaint Center, or IC3, unit of the Federal Bureau of Investigation, over 100,000 senior citizens in the U.S. fell victim to internet-enabled scams and crimes that resulted in over $1 billion in harm in 2020 alone. Despite lawmakers’ and security professionals’ attempts to keep current, the

nature of online threats continued to grow. The period between 2015 and 2022 saw unprecedented growth in cybersecurity incidents like ransomware,business email compromise, and cyber-induced wire fraud schemes that don’t necessarily compromise personal information, but that wreak considerable havoc on the lives and fortunes of individuals and corporations. The use of stalkerware, usually used illegally to track and monitor the activities and locations of current or former intimate partners, has grown worldwide and presents an ever-growing challenge in domestic violence cases as well as in divorce and custody proceedings. Some types of online harms have become so commonplace that we’ve almost become inured to them, with companies arguing in court that they shouldn’t be held liable for data breaches because they’ve become so common that no one can be sure that any identity theft or other harm results from this breach instead of previous ones.


And 2016 marked a watershed year in the expansion of online disinformation and malign influence campaigns, as Russian intelligence services were accused, and their 70 private sector collaborators criminally charged, with using personal information and cyber means to attempt to interfere with democratic elections around the world. At the same, social media giants like Facebook – now with some three billion users, or half the population of the globe – were charged with siphoning off information for sharing with political consulting firms like Cambridge Analytica, and allowing conspiracy theories, extremism, and other harmful content to spread like viral wildfire. As noted in legislative hearings in the United States, the United Kingdom, and elsewhere in the world, at best, these platforms seem to have turned a blind eye to the spread of misinformation and disinformation online, and at worst, taking cynical advantage of the opportunity to increase corporate profits through the individually-tailored advertising that caused company revenue to soar even while anti-vaxxers contributed to the public health crisis of a global pandemic by insisting that the baseless information they’d seen online – rumors that covid vaccines would cause infertility, or cause magnets to stick to a person’s body, or serve as a vector for injecting 5G wireless signal nanochips – were true.

All of these harms depend on the collection of vast amounts of personal information from unsuspecting users of digital platforms, devices, and services. All of them also depend on unscrupulous actors using that information, and the detailed personal profiles that result, for microtargeted messaging to manipulate, influence, scam, cheat, or disadvantage individuals in some way – often in ways that aren’t apparent to the individual victim, or to society as a whole, until after the fact, after the harm has been done. Against this backdrop of the personal, financial, and societal harm caused by malicious use of personal information, the privacy and protection of personal data has never been a more urgent or important task.


Communicating the consequences of digital citizenship Although it’s true that technology is creating new pressure on personal boundaries nearly every day, we have an opportunity to keep the privacy glass half-full: We live in a time when legislatures around the world are passing privacy and data protection laws, when judges are approving lawsuits addressing invasions of privacy through use of personal data, and when everyday people of all ages and around the world are taking increasingly proactive approaches to trying to understand how information about them is being generated, collected, and used.

Privacy isn’t dead yet. But there’s no denying that the contours of everyday privacy and data use are constantly changing in ways that many people don’t see. And much like effective cybersecurity requires approaches that deal with people, processes, and technology, any effort to mitigate individual and societal privacy risks requires more than just laws and regulations. It also requires a concerted public awareness campaign to help ordinary people around the world better understand the risks and consequences of digital citizenship: of what can go wrong with online interactions and data-intensive technologies; of how to understand the privacy risks and make informed choices about various platforms, app, devices, and services; and how to take sensible precautions, consistent with their

own personal comfort level based on a wellinformed understanding of the risks, in how they choose to use, or opt-out of, various categories of data-intensive living. This is a perfect time for the government, the private sector, academia, and not-forprofit organizations to launch a concerted and holistic public education and awareness campaign. It could go a long way in mitigating the downsides of data-driven tech, making all of us better prepared to make privacy choices that we’re individually at ease with, and making society more resilient to the swirl of online bias, misinformation, cyber crime, and other ills that arise at the intersection of data privacy, security, and everyday life online.

71


While government agencies have produced a great deal of content from cybersecurity warnings to brochures on identity theft, these materials aren’t always easily 72 digestible, and individuals have to know they exist and seek them out. A more proactive, and perhaps more effective, approach would be for educators, privacy advocates, government regulators, and others to focus on creating and delivering a modern and updated version of the classic public service announcement, with

a series of holistic, entertaining, accessible, and comprehensive content and programs for raising awareness and educating the public at large about the privacy, data security, social, and cultural hazards of data-driven technologies. The hazards of online life are wide-ranging, and so the topics addressed by digital literacy programs should be as well, helping people better understand how to protect themselves online, and how to avoid taking actions – even inadvertently! – that could harm others online.

In order to do this, the subjects covered should include, at a minimum, helping people understand: Data breaches, identity fraud, and identity theft

Password management practices

The role of social engineering in online scams

Other common scams for gathering personal identity and financial information

Core concepts relating to the business model of online platforms

“If you’re not paying for the product, you are the product” Platform revenue is directly correlated with time spent online “If it enrages, it engages” The way that features like automatic scroll are designed to keep eyeballs on screen


They should also include helping people understand:

The ways in which personal information is used to support targeted advertising How to assess the likely security of an online shopping platform or site

The ways in which personal information is used to support targeted advertising

How to understand what privacy settings they have enabled in commonly used social media platforms, apps, and devices

How to assess the likely credibility of information online and identify – and avoid spreading – misinformation and disinformation The impact on relatives as well as one’s own privacy of DNA testing The impact of cyberstalking

73

How to identify secure and insecure websites

The flaws, fallibility, and biases that are so often present in artificial intelligence algorithms

The roles of data brokers and data aggregation, online behavioral profiles, sharing and sale of personal information, and targeted advertising

The difference between first-party and third-party cookies and how they gather information and where that data is likely destined to go How ad blockers, cookie settings, and other browser settings can give users an added measure of control for the privacy-related issues they care about The difference between the considerable data collection that happens in “private” or “incognito” mode on most browsers and how to use browsers and search engines that offer greater degrees of privacy protection and anonymity The myriad ways location information is collected, used, and shared, including a high level understanding of the steps that can be taken to limit that collection – as well as the mobile device location information collection that individual users can’t control The ways in which micro-targeting is used to influence political and social opinions

The risks associated with biometric information collection

The ways in which still images can be manipulated into deep fakes The ways in which digital citizenship ought to include respect and concern for the privacy rights of others and the well-being of society The types of cognitive bias and critical thinking habits that make all of us susceptible to scams, phishing attacks, and online disinformation

and more


74

One-size-doesn’t-fit-all As important as the topics are, it’s perhaps equally important to consider how the information will be delivered, and to develop different public education and awareness campaigns that are tailored to different audiences and via different mediums. For example, in the wake of the 2016 U.S. presidential election, researchers examining online behavior concluded that senior citizens were more likely to be duped by online fake news, with Americans over the age of 65 sharing nearly seven times as many articles from fake news domains as younger internet users. There’s clearly an urgent need to reach out to older Americans via the means they’re most likely to trust, such as traditional television public service announcements (PSAs) that can be broadcast during local television news shows and during prime time network and cable television programming. Digital literacy campaigns are already a feature of many public libraries and often include content for seniors as well as other age groups; those efforts can be expanded with further funding and support. Educational efforts targeted towards senior citizens can also be produced as modules – like the beginner’s guide to mobile technologies produced for senior citizens in Belarus – and made available through senior centers, elder care and other long-term care facilities, and through faith communities.


In addition to helping raise the overall level of digital literacy, public education and awareness campaigns for all ages and demographics could really benefit from conversations about how to talk to people of differing views and in different groups about issues relating to fake news, conspiracy theories, and other harmful online content. Articles on “How to talk politics with your relatives at Thanksgiving” have become an annual tradition, with an increasing number of stories addressing “How to talk to your grandparents about fake news.” Part of

any public awareness campaign should be practical tips and skills for talking with friends and loved ones who’ve fallen victim to online misinformation, or who have 75 started believing in baseless conspiracy theories that are spreading online. There’s also a need for more studies in this area, as researchers are still working to understand just how people are impacted by misinformation in particular contexts, such as in healthcare, and how best to counteract that inaccurate or deliberately false messaging.


For younger age groups, it’s easy to envision a Schoolhouse Rock for Digital Literacy or Online Life. Generations of American children grew up learning the basics 76 of civics from short musical videos like “I’m Just a Bill,” grammar from cartoons like “Conjunction Junction,” and basic math functions from titles like “Figure Eight.”

Their power lies in their tight focus, catchy tunes, memorable lyrics, and charming animation. A similar approach for a new era – a Schoolhouse Rock for digital citizenship could make a tremendous contribution in making accessible and memorable information that – like government operations or grammatical structure – strikes many people as dry or tedious or hard to recall, until presented in ways that are not just digestible, but delightful. This kind of content could air on TV, be played on streaming services during previews and ad breaks, could circulate

on YouTube, or appear in news feeds on social media – in other words, it could arise everywhere that online users, of all ages, are found. And of course for children enrolled in K-12 and post-secondary education, digital citizenship and online literacy should be incorporated into regular curriculum at all ages. Efforts to help school children spot deep fakes and fake news have a track record of success in Finland, whose efforts could be a model for similar approaches elsewhere in the world.


These programs should also consider how to address digital literacy and disinformation differently across platforms. According to one study, many platforms serve as a petri dish for the global growth of online conspiracy theories, while one major platform (Twitter) helps reduce them. The ways that each major platform contributes to virality should inform how those platforms’ inherent features can be used to support digital literacy and to counter disinformation. And organizations – government entities and non-profit foundations – that provide funding for the arts should create grant opportunities for writers, musicians, playwrights and performance artists, graphic novelists, illustrators, and others to create content that can deliver digital literacy messaging in a whole range of venues, mediums, and context. Despite the galloping pace of data-driven technologies, Data Privacy Day gives us an opportunity to reflect on practical steps that the global community can take to harness the best opportunities – convenience, entertainment, innovation, education – from those technologies, while making a concerted investment of time, energy, and resources in efforts like public awareness and education campaigns that can help ensure that Data Privacy Day will still be meaningful in another sixteen years from now.

April Falcon Doss Author and Executive Director of Law and Policy at Georgetown University April is the Executive Director of the Georgetown Institute for Technology Law and Policy and Author of “Cyber Privacy: Who Has Your Data and Why You Should Care.” She also served as the Associate General Counsel for Intelligence Law at NSA, Senior Minority Counsel for the Russia Investigation in the Senate Select Committee on Intelligence, and was the Former chair of cybersecurity and privacy at a major U.S. law firm.

77


78

Thanks to our Contributors Tracey Z. Maleeff Security Researcher at Krebs Stamos Group James McQuiggan Security Awareness Advocate at KnowBe4 Cole Grolmus Author and Consultant at Strategy of Security Jeff Hancock Professor of Communication at Stanford University Guy Podjarny Co-Founder and CEO at Snyk Josh Yavor Chief Information Security Officer at Tessian April Falcon Doss Author and Executive Director of Law & Policy at Georgetown University


Want to Join? SHARE YOUR TIPS AND HOT TAKES!

We know the #1 source of information for security leaders and practitioners is... other security leaders and practitioners. That’s why all of our content is crowd-sourced from the security community. We want to hear from you! Articles, Opinions, Q&As, long-form and short-form content — and if you have ideas for topics that you’d like to see covered in a future issue, we’d love to hear that, too.

Email contribute@ humanlayersecurity .com


Colophon Maddie Rosenthal Director of Content at Tessian Leon Brown Design Director at Tessian Mihai Toma Designer at New Genre Anita Arabadzhieva Designer at New Genre

humanlayersecurity.com @humanlayersec ISBN 978-1-3999-1872-5 Printed by Pressision


© Tessian 2022


Human Layer Security is a magazine about the changing world of cybersecurity. Instead of focusing on networks, applications, and devices, Human Layer Security focuses on people: Employees. Me. You. Us.

ISBN 978-13999-1872-5


Turn static files into dynamic content formats.

Create a flipbook
Human Layer Security Magazine: The Rise of Security Augmentation by Human Layer Security - Issuu