Last week, I attended the National Cybersecurity Alliance (NCA) Convene: Boston Conference to gain more perspective about how to become a more effective cybersecurity awareness professional. The sessions were great and I’m here to share with you my thoughts!
In the session about reviewing the past five years of Oh Behave! The Cybersecurity Attitudes and Behaviors Report, NCA Executive Director, Lisa Plaggemier made me think about how our approaches in cybersecurity awareness can (and should) change. Lisa shared key findings from the data collected from the past five years showing that while cybersecurity awareness is up, worry and victimization about cybercrime is up too. Fatalism is winning. Security looks confusing.
To summarize, it seems, cybercrime is worsening and people are tuning out.
I think that as security awareness professionals, we have done a wonderful job ensuring that cybersecurity awareness is visible everywhere inside of our respective organizations and beyond. While worrying about cybercrime and victimization sits squarely on our minds, changing behavior is hard. I think that education has helped individuals identify scams, keep devices updated, and report cybercrime because we have provided relevant information and guidance. I also think that cybercrime has been there all the time (hidden) and now we have educated everyone to report the crime, we see a real picture of the true damage. But with cybercrime on everyone’s minds to avoid and prevent, the reports from IC3, IBM, Verizon, ITRC, Javelin, and others show it’s not even getting any better.
In the session, Lisa emphasized that we have the science and the data about perceptions in cybersecurity awareness. She asked security awareness professionals “whether we have the courage to change what we’re doing.”
Instead of using fear as a tactic to encourage change, she suggested using methods like “social proof” as a method for leveraging people’s (good) behaviors. In addition, Lisa suggested using clearer and easier to understand language to communicate security guidance. She also suggested using choice friction and secure by design as the default means for changing the environment because we can’t change people.
I like these suggestions that Lisa provided. In a way, we can show others how to live securely by showing up with real examples of living with better security. If I can show you how everyone else is staying secure, that should encourage you to follow better secure behavior, right? My phone privacy screen is one example. My password manager setup is another. My presentation on increasing your online privacy using my own personal examples is another. And so on.
Lisa’s second suggestion about communicating security guidance effectively speaks to me. I think it’s time to consider recruiting professionals who have backgrounds in technical writing and technical communication. For example, I was trained as a technical communicator in undergrad and grad school. I gained content strategy and cybersecurity communication from my roles in traditional and digital marketing and cybersecurity awareness. My background is oriented in science, engineering, and research. While I may not fully understand what a subject matter expert in cybersecurity does, my role is to seek the information they have, adeptly ask questions for the sake of communicating their message accurately, and articulate that message clearly for my intended audience.
My goal is to make cybersecurity awareness, guidance, and education as accessible as possible.
In my professional conversations with technical communicators and content strategists, we often discuss being the last ones at the conversation table, why not be the first ones included at the table? The same thing can be said for cybersecurity awareness communicators: we need a seat at the table earlier with engineers, experts, and directors.
Lastly, we have to talk about friction. The idea of changing the environment is something that is not talked about more often. What this means is to design secure systems right out of the box. Lisa suggests that we advocate for secure by design approaches, making it harder to go to an option that is less secure.
For example, using MFA over strong passwords by removing the option for passwords. Other examples I can think of are private-by-default social media settings, automatic rotating MAC addresses on devices using public WiFi, auto-clearing of advertising cookies after a week, generating private email addresses, and setting automatic updates turned on by default. Of course, if you want to opt-out of the safer and better settings away from the default, you can change the settings. Most people won’t change the default settings anyway, so why not make them better?
As a side note, the internet did increase security by moving from HTTP to HTTPS around 2015 with the introduction of free Let’s Encrypt SSL certificates and in 2018 when Google Chrome (and later Firefox) would set a warning about visiting insecure websites, so it’s possible to accelerate other secure by design systems elsewhere. Social media by default, anyone? Right to your privacy and remove your data with one click?
We have the ability to make cybersecurity awareness better for everyone. From communicating clearer, advocating for secure by design systems, and showing safer habits by example are ways we can improve perceptions of cybersecurity awareness and avoid more losses to cybercrime. We’re so good at showcasing doom and gloom examples but we have the ability to soften the message with positive actions and advocate for change which can go a very long way for a much safer and secure online life.
Let’s see what the next five years of data shows.
Read more about the National Cybersecurity Alliance, the Oh Behave! Reports in collaboration with CybSafe, and the NCA Convene Conferences held twice a year.
Also, consider voting for this session at SXSW for this session before August 23: The Police Said No, But We Did it Anyway: Chasing the Con.
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.