How Can Risk Management Restore Digital Trust?

2.4K views
•
March 6, 2019
by
RSAC Cybersecurity
YouTube video player
How Can Risk Management Restore Digital Trust?

TL;DR

Digital trust is restored by understanding, prioritizing, and managing risk, rather than trying to eliminate every threat. Organizations should measure business impact, build reliability and resilience, govern data throughout its lifecycle, address ecosystem risk, and combine human judgment with machine capabilities to make innovation safer and more trustworthy.

Transcript

Welcome to RSA Conference 2019. And now please welcome President RSA, Rohit Ghai, and cybersecurity strategist and entrepreneur, Nilufer Radziwall. Good morning, everyone. On behalf of RSA, a Dell Technologies business, welcome to the 28th RSA Conference. Our theme for the day is better. So what do you think, Nilu? Is our future going to be better?... Read More

Key Insights

  • Trust is to the economy what water is to life, because economic activity depends on confidence in data, technology, organizations, and institutions. The imagined trust crisis shows that society often takes this resource for granted until misinformation, manipulation, surveillance, and institutional failures begin depleting it.
  • Peer-to-peer trust can rise while institutional trust falls. Digital platforms enabled people to invite strangers into their cars, homes, businesses, and financial activities, yet election interference, fake news, deepfakes, polarization, and organizational misrepresentation simultaneously weakened confidence in governments, media, and companies.
  • Restoring digital trust is about managing risk rather than eliminating it. The healthcare analogy recognizes that harmful sources cannot always be removed, but they can be understood and controlled through informed priorities, appropriate technology, resilient systems, and decisions focused on what matters most.
  • Information literacy is a defense against manipulation. Teaching citizens to recognize actors, motives, biased sources, deepfakes, and polarizing voices can reduce their susceptibility to influence campaigns without restricting protected expression or attempting to remove every malicious participant from the information environment.
  • Cybersecurity and risk management converge when practitioners measure both the likelihood and business impact of potential loss events. This risk orientation replaces an evaporating network perimeter with reliability, resilience, informed trade-offs, and protection focused on the organization’s most important assets and outcomes.
  • Data governance is an essential competency in a hyperconnected economy. Data should be labeled when created and continuously afterward, while consumers retain ownership and visibility into copies and flows. Managing provenance becomes critical because data moves through complex supply and distribution chains as a primary asset.
  • Ecosystem risk can exceed an organization’s direct digital risk. As technology, data, suppliers, and partners become deeply connected, exposure increasingly comes from third through Nth parties rather than only from systems the organization owns and directly controls.
  • Human and machine capabilities are more trustworthy together than either is alone. Machines can process vast amounts of data and produce faster answers, but bias, limited empathy, ethical concerns, adversarial conditions, and weak explainability make human judgment necessary for responsible decisions.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How can risk management restore digital trust?

Risk management can restore digital trust by replacing the unrealistic goal of eliminating every threat with a disciplined process for understanding, prioritizing, and controlling risk. Practitioners assess the likelihood of potential loss events and, more importantly, their business impact. This approach directs protection toward what matters most while strengthening reliability, resilience, data integrity, privacy, and informed decision-making.

Q: Why is trust compared to water in the digital economy?

Trust is compared to water because both are foundational resources that people often take for granted until scarcity becomes visible. Water sustains life, while trust sustains economic activity, institutional legitimacy, information exchange, and technology adoption. The comparison also suggests a shared response: society must practice responsible consumption, make deposits rather than only withdrawals, and actively preserve the resource through better behavior and governance.

Q: What caused the trust crisis described in the talk?

The trust crisis emerged from several connected forces: election interference, nation-state influence campaigns, fake and biased news, deepfakes, political polarization, pervasive surveillance, and misleading claims by public and private institutions. Organizations also failed to assure the integrity, privacy, and reliability of data. Together, these failures weakened confidence in democracy, media, governments, businesses, and the interconnected digital economy.

Q: How does information literacy reduce digital risk?

Information literacy reduces digital risk by helping people identify who created a message, understand the creator’s motives, evaluate the reliability of sources, and distinguish fact from misinformation and opinion. It makes citizens harder to target, manipulate, or mislead through influence campaigns, biased reporting, deepfakes, and polarizing content. The approach manages harmful information without attempting to eliminate every bad actor or restrict protected expression.

Q: Why is cybersecurity shifting away from perimeter defense?

Cybersecurity is shifting away from perimeter defense because the traditional boundary separating trusted internal systems from external threats has evaporated. In a world connecting people, devices, clouds, software, and data, organizations cannot simply lock networks down. Practitioners must instead evaluate potential losses, understand business consequences, strengthen reliability and resilience, and allocate protection according to the importance of assets and outcomes.

Q: How should organizations govern data in a hyperconnected economy?

Organizations should label data at creation and continue updating those labels as the data moves and changes. Consumers should own their data and have clear information about its copies, locations, and flows. Because data travels through supply and distribution chains as a primary asset, organizations need strong provenance and governance capabilities to preserve integrity, privacy, reliability, accountability, and trust across the broader ecosystem.

Q: Why can third-party and Nth-party risk exceed first-party risk?

Third-party and Nth-party risk can exceed first-party risk because an organization’s exposure increasingly depends on its entire ecosystem, not only its own digital footprint. Data, software, suppliers, partners, and connected services create chains of dependency that extend beyond direct control. A weakness or harmful action several relationships away can therefore affect the organization, making ecosystem visibility and risk management essential.

Q: Why are humans and machines more trustworthy together?

Humans and machines are more trustworthy together because their strengths and weaknesses differ. Machines process vast amounts of data and can reach answers faster, while humans contribute judgment, empathy, ethical reasoning, and contextual understanding. Machines may inherit bias from their data, struggle in adversarial environments, and fail to explain their conclusions. Human oversight helps evaluate those limitations and support responsible decisions.

Summary & Key Takeaways

  • Trust became the essential requirement of the biodigital era as technology spread everywhere, including inside human bodies. Yet peer-to-peer trust grew while confidence in governments, news sources, social institutions, and businesses declined, creating a trust crisis that threatened data-driven commerce and broader human progress.

  • The proposed response was to focus on the trust landscape alongside the threat landscape. Security and risk practitioners learned that restoring trust requires understanding, prioritizing, and managing risks. They protected organizations by evaluating the business impact of potential losses and building reliable, resilient operations instead of attempting complete network lockdown.

  • By 2049, data flows through a hyperconnected economy, technology patches itself, and embedded risk engines adjust functionality according to changing conditions. Consumers own their data, provenance and governance are essential competencies, and ecosystem exposure exceeds first-party risk. Human judgment and machine capabilities must also work together to strengthen trustworthiness.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚