How to Build a People-Centric Security Culture

1.1K views
•
February 22, 2017
by
RSAC Cybersecurity
YouTube video player
How to Build a People-Centric Security Culture

TL;DR

Treat employees as active defenders by giving them resources, positive incentives, and safe ways to report suspicious activity. Because phishing clicks cannot realistically be reduced to zero and technical controls are imperfect, organizations should plan for human error, measure tests carefully, and combine employee participation with technology as a defense-in-depth strategy.

Transcript

Everybody, thank you so much for being here. It is my pleasure to talk to you today about how you can expand your blue team by creating a security culture. Before we get started and go too far deep into this, I want to define blue team as, uh, your incident response team or the organization that helps defend your, uh, employees against outside atta... Read More

Key Insights

  • Employees are both a potential security risk and a valuable source of breach information. The cited survey found that employees helped discover breaches more effectively than any other internal process or technology, supporting greater investment in their defensive capabilities.
  • People-centric security is an approach that places employees at the center of organizational problem-solving. Its purpose is to give people resources that help them defend the organization, instead of defining security work primarily as finding and criticizing employee mistakes.
  • Phishing is presented in three categories: stealing credentials, persuading someone to run a malicious executable, and convincing someone to visit a website through a link. These attacks depend on human action, while the latter two also require weaknesses in the technology stack.
  • Defense in depth is necessary because neither people nor technology provide a complete solution. Perfect two-factor authentication, fully patched systems, and browsers without vulnerabilities could reduce dependence on human judgment, but those conditions do not reflect the reality described in the presentation.
  • Phishing click-through rates are difficult to compare because test difficulty can change dramatically. In the speaker's programs, a highly difficult simulation caught seventy-five percent of employees, while a remarkably easy simulation caught ten percent, making the raw percentages misleading.
  • Phishing test difficulty is affected by context, including geography, seasonal relevance, and time of day. A tax-themed message may be convincing during tax season in the United States but less relevant in Europe, even when employees receive the same test.
  • Repeated phishing formats can sensitize employees to the test rather than improve their general security judgment. Even when two simulations appear equally difficult, better results may reflect advance familiarity with the organization's testing patterns instead of broader resistance to real attacks.
  • A zero percent phishing click rate is not a realistic operational goal. The cited 2013 Verizon report found that three-email campaigns had a better than fifty percent chance of receiving a click, while ten-email campaigns had a 99.9 percent chance of receiving one.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How can an organization build a people-centric security culture?

An organization can build a people-centric security culture by treating employees as full participants in defense and giving them resources to identify and report threats. Security teams should focus on empowerment, positive motivation, behavioral science, and a safe-to-fail environment. The goal is not merely to catch mistakes, but to help employees contribute useful information to incident detection and organizational protection.

Q: Why should employees be treated as part of the blue team?

Employees should be treated as part of the blue team because they can provide vital information about suspicious activity and breaches. The cited research found that employees were key to discovering breaches, exceeding other internal processes or technologies. Although insecure behavior can create vulnerabilities, engaged employees can add a broad human detection layer that supports the formal incident response and security organization.

Q: What is people-centric security?

People-centric security is the perspective that employees are central to solving security problems rather than merely causing them. Under this approach, security professionals provide employees with resources and motivation to help defend the organization. It replaces labels such as weakest link, wetware, or problem user with a model in which people are respected as capable and valuable security participants.

Q: What are the three phishing attack categories described?

The three categories are credential stealing, running a malicious executable, and clicking a link that leads to a website. Credential theft requires a person to provide a username and password. Executable attacks require someone to run malicious software and may also depend on an unpatched system. Link attacks combine social engineering with a downstream weakness, such as a browser vulnerability.

Q: Why must phishing defenses combine people and technology?

Phishing defenses must combine people and technology because technical controls are not perfect and human behavior cannot provide a complete solution by itself. Perfect two-factor authentication, completely patched systems, and browsers without vulnerabilities would greatly reduce the consequences of employee actions, but those conditions are not realistic in the presentation. Empowering employees therefore adds another layer to a defense-in-depth strategy.

Q: Why is phishing click-through rate an unreliable success metric?

Phishing click-through rate is unreliable when simulations are not comparable in difficulty and context. The speaker created one difficult test that caught seventy-five percent of employees and another easy test that caught ten percent. Geography, tax season, time of day, and familiarity with previous simulations can also change results, so a lower percentage does not necessarily demonstrate stronger security behavior.

Q: Can security training reduce phishing clicks to zero?

Security training should not be expected to reduce phishing clicks to zero. The cited 2013 Verizon report found that campaigns containing three phishing emails had a better than fifty percent chance of getting clicked. Campaigns containing ten emails had a 99.9 percent chance of receiving a click. Organizations should therefore accept that someone will eventually click and plan their defenses accordingly.

Q: What does a safe-to-fail security culture mean?

A safe-to-fail security culture begins with the assumption that employees will sometimes make mistakes, including clicking phishing links. Instead of treating every mistake as proof that people are the problem, the organization uses positive incentives, behavioral science, and vulnerability reporting to improve detection. Planning for failure allows security teams to prepare layered responses while encouraging employees to report suspicious events promptly.

Summary & Key Takeaways

  • A people-centric security program treats employees as participants in organizational defense rather than as the weakest link. Employees can introduce vulnerabilities through insecure behavior, but they can also provide vital information that helps discover breaches. Security teams should therefore focus on equipping and motivating people to contribute effectively to incident detection and prevention.

  • Phishing can involve credential theft, malicious executables, or links leading to vulnerable websites. Each path combines some degree of human vulnerability with technical weaknesses. Since perfect two-factor authentication, fully patched systems, and invulnerable browsers do not exist in the presented scenario, employee awareness should complement technical controls as an additional defensive layer.

  • Click-through rates are unreliable when phishing simulations vary in difficulty, geography, timing, context, or familiarity. A difficult test produced a seventy-five percent failure rate, while an easy test produced ten percent. Because repeated campaigns will eventually attract a click, organizations should plan for failure and prioritize useful reporting and rapid detection alongside prevention.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚