Masha Sedova on Changing Security Behavior

195 views
β€’
March 13, 2019
by
RSAC Cybersecurity
YouTube video player
Masha Sedova on Changing Security Behavior

TL;DR

Security programs should target measurable employee behaviors with relevant support delivered to the right person at the right time. Instead of relying on repeated presentations or phishing tests alone, organizations can use existing network data, active practice, behavioral science, practical tools, positive incentives, and leadership alignment to help employees build safer habits.

Transcript

Good morning. We are here at RSA 2019 doing Women in Cyber interviews, and this morning I'm sitting down with Masha Sedova. You got it. Hi, Tenzing. Good to meet you. Thank you for being here. Yeah. Um, Masha, you are with Elevate Security. You're the co-founder. Yep. Tell us a little bit about what Elevate does. Yeah, so we are a security behavior... Read More

Key Insights

  • Elevate Security is a behavior change platform that aggregates employee actions observed through existing network security tools, identifies strengths and weaknesses, and uses behavioral science to help enterprises shift habits that affect their security posture.
  • Traditional security awareness is often ineffective because employees can mute presentations, skip through material, and answer quiz questions without receiving practical resources or developing habits that help them make safer decisions during their daily work.
  • Security awareness has progressed through three phases: compliance programs measured by completion, mock phishing programs measured by clicks and reporting, and a broader behavior change approach focused on the full range of actions that influence organizational risk.
  • Phishing is only one critical security behavior, and repeatedly testing employees can alienate them by making them feel that the organization is waiting for them to fail rather than helping them succeed.
  • Security behavior change requires a varied toolbox that can include training, phishing simulations, motivation, password managers, positive incentives, executive alignment, management support, adequate resources, and some enforcement tied to clearly defined organizational outcomes.
  • Passive instruction has a stated content retention rate of 15–20%, while active approaches involving discussion, practice, learning by doing, or teaching others have a stated retention rate of 70–90%.
  • Tabletop exercises and simulations are among the strongest learning methods discussed because they require participation and practice, but their difficulty to scale can limit how broadly organizations deploy them.
  • Personalized security guidance works by using behavioral data to determine who needs particular support, allowing organizations to present relevant information at the moment of need instead of assigning the same collection of best practices to everyone.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What is security behavior change?

Security behavior change is an approach that identifies the employee actions most important to an organization’s security posture and applies suitable interventions to shift those actions. Its toolbox can include training, mock phishing, motivation, password managers, positive incentives, executive and management alignment, resources, and enforcement. The goal is broader than completing training or reducing phishing clicks because many behaviors contribute to organizational risk.

Q: Why is traditional security awareness training ineffective?

Traditional awareness training often relies on repeated presentations that tell employees information without ensuring that they practice or apply it. Employees may mute the material, fast-forward through it, and complete the quiz without changing their habits. According to Sedova, this approach can make people nervous about security threats while failing to give them the practical tools, support, and empowerment needed to respond effectively.

Q: How has enterprise security awareness evolved?

Enterprise security awareness has moved through three phases in Sedova’s account. The first was compliance, in which auditors asked organizations to demonstrate education efforts and completion totals became the main metric. The second centered on mock phishing, click rates, and reporting rates. The third focuses on changing the broader set of employee behaviors that are critical to each organization rather than concentrating on training completion or phishing alone.

Q: Why are phishing simulations insufficient for security behavior change?

Phishing simulations are insufficient because phishing is only one of many behaviors required to secure an organization. Repeatedly testing employees can also make them feel that the security team is setting them up for failure and waiting for a mistake. Simulations can remain part of the program, but they should sit within a wider strategy that provides motivation, practical tools, relevant training, leadership support, and appropriate incentives.

Q: What is the difference between passive and active security training?

Passive training tells employees information and has a stated content retention rate of 15–20%. Active training asks people to discuss ideas, practice tasks, learn by doing, or teach others, producing a stated retention rate of 70–90%. Computer games may be only lightly active, while tabletop exercises and simulations demand greater participation. Sedova considers these participatory methods especially useful, although they can be difficult to scale.

Q: How can behavioral data personalize employee security training?

Behavioral data can show which employees need help with particular risks, allowing security teams to avoid assigning identical training to everyone. Existing network tools can provide signals such as malware downloads, infection rates, malicious browsing rates, and VPN usage. If an employee has not exhibited a particular risky behavior, the organization may decide that related training is unnecessary and focus attention where evidence shows a need.

Q: Why does timely security guidance matter?

Timely guidance matters because information presented immediately after a relevant action is both applicable and demonstrably necessary. For example, a prompt delivered when an employee makes a mistake can connect instruction directly to the behavior that needs to change. This differs from a one-size-fits-all program that distributes a broad collection of best practices without considering what each person already knows or does correctly.

Q: What organizational support helps employees adopt safer security habits?

Employees need more than information to adopt safer habits. Sedova identifies practical tools such as password managers, positive incentives, executive alignment, management alignment, sufficient resources, motivation, and some enforcement as parts of an effective behavior change toolbox. These measures can support defined outcomes and make security easier to practice, addressing the gap between making employees concerned about threats and empowering them to act safely.

Summary & Key Takeaways

  • Masha Sedova describes Elevate Security as a security behavior change platform that aggregates employee activity from existing network tools. It identifies behavioral strengths and weaknesses, then applies solutions rooted in behavioral science. The approach resembles a Fitbit for security because it uses observed behavior to provide relevant insights and encourage healthier habits.

  • Traditional security awareness began as a compliance exercise measured by training completion, then shifted toward mock phishing and metrics such as click and reporting rates. Sedova argues that phishing represents only one of many critical behaviors. The emerging phase focuses on changing the specific behaviors that materially affect each organization’s security posture.

  • Effective behavior change requires more than distributing information. Active methods such as discussion, practice, teaching others, tabletop exercises, and simulations produce stronger retention, although some are difficult to scale. Timely guidance based on actual behavior can also improve relevance by directing training and resources only to employees who demonstrably need them.


Read in Other Languages (beta)

Share This Summary πŸ“š

Explore More Summaries from RSAC Cybersecurity πŸ“š