How to Build a Behavioral Cybersecurity Program

210 views
August 22, 2022
by
RSAC Cybersecurity
YouTube video player
How to Build a Behavioral Cybersecurity Program

TL;DR

Behavioral cybersecurity should reduce security risk by measurably improving human behavior, not merely deliver entertaining awareness content. An effective program combines behavioral science, psychology, cognitive science, research, training, and data analysis, while also considering customer sentiment, employee wellness, cybersecurity professionals’ working practices, and the broader business value produced by security measures.

Transcript

Hi there. Um, first I wanna thank everybody. To be very upfront with you, when they tell me the last day and early morning, and I'm sitting there, and then they're like... I'm like, "Do you have any other times? 'Cause I don't even show up to the conference at this time." So I appreciate all of you actually being here, 'cause I would not be here my... Read More

Key Insights

  • Behavioral cybersecurity is the combined application of behavioral science, psychology, and cognitive science to create positive changes in security-related behavior. It should operate as a comprehensive discipline rather than as a new label for conventional security awareness activities.
  • The primary job of a behavioral cybersecurity professional is to reduce risk through human behavior. Helping users and creating educational content may support that objective, but those activities are not sufficient unless they produce meaningful, measurable reductions in security risk.
  • Security awareness is only one part of behavioral cybersecurity. A complete program can also address customer security and sentiment, the working practices of cybersecurity professionals, employee wellness, user experience, and the overall business impact of security measures.
  • Entertainment is not evidence of training effectiveness. Funny videos, engaging series, and favorable audience reactions may improve the experience, but practitioners must determine whether the content changes behavior and reduces risk rather than relying on enjoyment as the principal success measure.
  • User mistakes can reveal organizational failures rather than isolated individual incompetence. The NSA password example shows that extensive security instruction may still omit practical guidance and that systems can permit predictable credentials, making program design and controls part of the problem.
  • Behavioral science requires more than copying an idea from a popular book or article. Applying isolated techniques without understanding their context, limitations, and critical nuances can turn a professional discipline into unsupported practice that only appears scientific.
  • Measurement is a critical part of behavioral cybersecurity. The presenter points to data science in marketing as an example of how programs can closely examine effectiveness, while stressing that behavioral security includes marketing elements without being reducible to marketing.
  • Business value is necessary for sustaining behavioral cybersecurity work. Every cybersecurity role should produce a return for the organization, and practitioners seeking larger budgets must demonstrate that their programs deserve additional support through risk reduction and other positive outcomes.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What is behavioral cybersecurity?

Behavioral cybersecurity is the comprehensive use of behavioral science, psychology, and cognitive science to improve security-related behavior. Its central purpose is to reduce risk associated with human actions. Security awareness can contribute to that purpose, but the discipline should also incorporate research, training, data science, customer considerations, user experience, professional practices, wellness, and measurement of program effectiveness.

Q: How does behavioral cybersecurity differ from security awareness?

Security awareness is a limited component of behavioral cybersecurity, not an equivalent term. Awareness commonly focuses on informing employees or delivering educational content. Behavioral cybersecurity has a broader risk-reduction mandate that includes measuring and changing behavior, improving customer security and sentiment, supporting cybersecurity professionals, considering wellness, applying relevant sciences, and demonstrating positive business impact.

Q: What is the main goal of a behavioral cybersecurity program?

The main goal is to reduce security risk through changes in human behavior. Activities such as helping users, distributing training, or producing engaging materials should serve that goal rather than become ends in themselves. A program should therefore assess whether its interventions improve behavior and create business value, while also considering customer experience and the practices of cybersecurity professionals.

Q: Why is entertaining security training not enough?

Entertaining content can make training more pleasant, but enjoyment does not prove that the material changes behavior or reduces risk. A high percentage of participants calling content engaging only shows that they liked the experience. Behavioral cybersecurity practitioners should evaluate effectiveness directly, connect the training to risk reduction, and treat favorable audience sentiment as a possible benefit rather than the primary result.

Q: What does the NSA password story reveal about security failures?

The story shows how an organization can provide extensive security instruction yet overlook simple, predictable behavior. A new employee with the account identifier “Kirk” used “captain” as her password, but her security training had apparently never identified that choice as problematic. The lesson is to examine training and systems instead of treating the user as the sole cause of failure.

Q: Why should behavioral cybersecurity be treated as a discipline?

Behavioral cybersecurity should be treated as a discipline because sound practice requires research, training, data science, careful measurement, and integration of several relevant sciences. Reading a popular behavioral book or an article does not provide the expertise needed to apply its ideas responsibly. Without scientific nuance and evaluation, practitioners may implement isolated techniques that sound credible but do not reliably reduce risk.

Q: How should a behavioral cybersecurity program measure success?

A behavioral cybersecurity program should measure whether its work changes security-related behavior and reduces risk. Engagement, humor, and positive reactions may provide useful supporting information, but they are not adequate measures by themselves. The presenter argues for data science and close examination of effectiveness, with results tied to customer sentiment, professional practices, user experience, and business return where relevant.

Q: How can behavioral cybersecurity teams justify larger budgets?

Behavioral cybersecurity teams can strengthen their budget case by demonstrating that their work deserves additional investment. That requires connecting activities to measurable risk reduction, improved behavior, customer security and sentiment, better professional practices, or other business value. The presenter’s position is that cybersecurity teams receive the budgets they deserve, so they must embed behavioral science and prove effectiveness rather than merely state their needs.

Summary & Key Takeaways

  • Behavioral cybersecurity is a comprehensive approach to changing security-related behavior through behavioral science, psychology, and cognitive science. Security awareness belongs within this approach, but it is only one component. The broader discipline should address employee risk, customer security and sentiment, professional practices, wellness, measurement, and demonstrable value to the business.

  • Security programs can fail even in highly security-conscious organizations when training does not address practical behavior. The presenter’s NSA password story illustrates how extensive general security instruction can overlook a predictable password choice. Instead of simply blaming a user, practitioners should examine the training, policies, systems, and controls that permitted the behavior.

  • A credible behavioral cybersecurity discipline requires research, training, data science, careful measurement, and attention to scientific nuance. Practitioners should not treat popular books, articles, psychological techniques, or entertaining videos as complete solutions. Programs earn stronger organizational support by showing effectiveness, reducing risk, improving experiences, and connecting their work to business returns.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚