Jerry: Linda, do you think Im paranoid? Linda: Youre not really - - PowerPoint PPT Presentation

jerry linda do you think i m paranoid linda you re not
SMART_READER_LITE
LIVE PREVIEW

Jerry: Linda, do you think Im paranoid? Linda: Youre not really - - PowerPoint PPT Presentation

Jerry: Linda, do you think Im paranoid? Linda: Youre not really paranoid if everyone really is after you, Jerry. Jerry: Maybe all security people are crazy! Linda: No, theyre just insecure. Everything You


slide-1
SLIDE 1

Jerry: “Linda, do you think I’m paranoid?” Linda: “You’re not really paranoid if everyone really is after you, Jerry.” Jerry: “Maybe all security people are crazy!” Linda: “No, they’re just … insecure.”

slide-2
SLIDE 2

Everything You Learned is Wrong

Getting Over Our Insecurities and the Truth About Cyber Security

slide-3
SLIDE 3

Three Things Insecure People Heard

  • There are things that you can do to

become secure.

  • Real-time security is our goal.
  • We gained a good understanding of our

adversaries.

slide-4
SLIDE 4

Insecure

in·se·cure adjective \ˌin-si-ˈkyu̇r\

1. not confident or sure : <feeling somewhat insecure of his reception> 2. not adequately guarded or sustained : <an insecure investment> 3. not firmly fastened or fixed : <the hinge is loose and insecure> 4. not highly stable or well-adjusted: <an insecure marriage>

slide-5
SLIDE 5

Insecure People …

  • Respond to people who

validate them or tell them what they want to hear – that they are good or ok or smart.

  • Don’t believe the truth, they

believe in their own truth.

  • Act on their mistaken beliefs
slide-6
SLIDE 6

There are things that you can do to become secure.

slide-7
SLIDE 7

Cyber Security Psychology

Belief Action Result

False belief Action False Result

We can be secure We are secure

Actions

slide-8
SLIDE 8

“Blackberries are secure as long as they don’t have cameras.”

slide-9
SLIDE 9

What is the risk, threat, and vulnerability in our environment to our data? Does this device appreciably reduce or increase any of these factors? Is my answer based on fear, uncertainty, and doubt? i.e., insecurity?

slide-10
SLIDE 10

Truth

  • Security doesn’t have a constant value

(“yes” or “no”)

  • Function of risk, threat, vulnerability, et. al.
  • Ignorance isn’t bliss
slide-11
SLIDE 11

Real-time security is our goal.

slide-12
SLIDE 12

Schrodinger’s Security

Real-time becomes retrospective the moment you observe it.

slide-13
SLIDE 13

Truth

  • We used to rely only on verification and

validation of controls

  • Then, we learned that real-time was even

better

  • Ultimately, we will need to develop

predictive capabilities

slide-14
SLIDE 14

We gained a good understanding of our adversaries.

slide-15
SLIDE 15

“If you know the enemy and know yourself you need not fear the results

  • f a hundred battles.” -- Chinese General Sun Tzu
slide-16
SLIDE 16

The adversary looks a lot like “us”.

slide-17
SLIDE 17
  • A healthy amount of paranoia

is good, as long as we aren’t afraid of the boogeyman.

  • A healthy amount of humility

keeps us on our toes and sharp – never resting on our laurels.

  • Know your strengths, know

your limitations, and continue to learn, grow, and share.