An industry-wide consultation process to find a solution to the human-centered cybersecurity puzzle ... [+] has started
Can the OutThink human-risk framework project solve the cybersecurity people puzzle?
Angela Sasse is the professor of human-centered security both at Ruhr University Bochum in Germany and London's UCL. She's also the chief scientific adviser to predictive human risk intelligence platform startup, OutThink, which recently completed a 1.2 million ($1.5 million) seed-funding round. Professor Sasse is to write the world's first comprehensive framework for the management of human risk in cybersecurity. The project, led by OutThink, will run for six months and is already starting to attract buy-in from some Fortune 500, FTSE 100 and Euronext 100 names. To succeed, however, it needs more collaboration from CISOs and security practitioners, which is why Professor Sasse is launching an industry-wide consultation process.
There's certainly little doubting that there is a human side to cybersecurity risk. You only have to read the technology news headlines whenever a major news event, such as coronavirus, strikes. The cyber-criminals looking to exploit human nature are never far behind. With phishing kits for sale that target Amazon, Apple and PayPal users, for example, the social engineering threat is now an off-the-shelf one. And that's before you start looking at other aspects of human risk.
A recent review published by the European Union Agency for Network and Information Security (ENISA) found that there were only a small number of models when it came to the behavioral aspects of cybersecurity. None of these, it concluded, were a "particularly good fit for understanding, predicting, or changing cybersecurity behavior." Indeed, the ENISA report found many ignored the context of cybersecurity behaviors and that there was evidence to support models that enabled "appropriate cybersecurity behavior" had more effect than those relying upon threat awareness training, or punishment, as drivers for more secure conduct. This was what spurred Professor Sasse to start the new initiative. "Investment in technical security measures continues to dominate the way in which CISOs attempt to manage cyber risks," Professor Sasse said, "whilst employees suffer as their productivity is hindered by limiting solutions, meaning they often circumvent security so that they can do their jobs. This framework is the perfect opportunity to right these wrongs."
OutThink human risk framework project buy-in from Vodafone Group and Centrica
Amongst those to already have expressed an interest in the OutThink project are Imogen Verret, head of security awareness at Vodafone Group. "For me, security awareness training is only the starting point," she said, adding, "Im keen to work on the project with OutThink and other security practitioners to design a solution that works for both the business and the employee."
Dexter Casey, group chief security officer at Centrica, has said that the job of a modern CISO is far from easy, which is something of an understatement. "We all know about 'people, process, tech being the three pillars of effective security," Casey said, "and make significant investment to address processes and technology, but there's a serious gap when it comes to sensible guidance on the people side of security." Casey is hopeful that the framework being discussed can provide "realistic, actionable, practical advice for CISOs so that they can solve one of their biggest problems."
I contacted another academic, Daniel Dresner, who is an acquaintance of mine and professor of cybersecurity at the University of Manchester. Professor Dresner says that when he hears that title, a comprehensive framework for the management of human risk, it sounds like another worthy attempt to deal with the challenge of cybersecurity. That it is a separate framework concerns him though, and Professor Dresner says we will continue to fail to properly address security risk because "we should adopt the attitude that there is no such thing as human error, it is just people being human," adding that "mantras of 'weakest link' and then 'strongest asset' have held us back from considering technology and people at the same time." In an email conversation with Professor Dresner, he said that as soon mention of the people side of security is made then "the tired and restrictive practice of denying technology as a solution is rolled out to protect the polarization like the courtiers' fear in 'The Emperor's New Clothes." Therefore, Professor Dresner says, the important basics of the UK National Cyber Security Centre (NCSC) Cyber Essentials, designed to help protect organizations from cyber-attack, are "sacrificed on the altar of too-simple." If considered properly, he says, "you realize that the protection they afford is proportionate, and they are not that simple when scaled up. They are," Professor Dresner concludes, "as simple as possible, but no simpler."
Ian Thornton-Trump, CISO at Cyjax, is also somewhat "pessimistic about frameworks to begin with," he says, "as anyone with a background in the National Institute of Standards and Technology (NIST) cybersecurity framework can understand it's a gargantuan task to audit, let alone implement, without substantial effort and investment across the organization." Apart, that is, for a framework which Thornton-Trump calls out as existing already: "employee morale and organizational stress." It's low morale and stress that causes mistakes or security issues related to insider behavior, Thornton-Trump says, "I wonder how many S3 buckets were made public due to mistakes by IT resources that were under stress and of low morale?" Perhaps folk just need to be better managers and champions of change, he concludes.
One experienced CISO, founder of NSC42 and chair of the Cloud Security Alliance UK chapter, Francesco Cipollone, is more enthusiastic about the opportunity the OutThink project could provide. "The NIST cybersecurity framework is being widely adopted in enterprises and SMBs," Cipollone says. While organizations have initially been focusing on NISTs pillars of identify and protect, "now there is increasing attention on the other two pillars of detect and respond," he says. So, the NIST framework provides guidance on how to detect and respond to a generic attack while the framework proposed by OutThink can focus on human risk. "A holistic view and framework focused on the risks from humans, like the insider threat or misconfiguration issues, is very much needed," Cipollone says. "The recent focus of malicious actors on social engineering in conjunction with open-source intelligence (OSINT) techniques to target the human aspect of an organization, traditionally the weakest link," he concludes, "makes this framework even more valuable."
Professor Sasse is being joined by Dr. Shorful Islam, OutThinks chief product and data officer, who has a Ph.D. in psychology and deep expertise in modeling human behavior but knows for the project to be successful more collaborators are needed. "I am glad to have the buy-in of so many esteemed security professionals," Professor Sasse said, "it validates what we are trying to do and will ensure that the framework suits the needs of the CISO. I would invite anyone else that wants to get involved to get in touch."
If you are a CISO, security practitioner or researcher, and would like to join the project, then you can visit OutThink at booth 1647F at the RSA conference in San Francisco between February 24 and 28, or by email to hello@outthinkthreats.com
Here is the original post:
FTSE 100 And Fortune 500 Businesses Join Forces To Tackle The Human-Centered Security Problem - Forbes
- Study links most alligator attacks to risky human behavior - Gulf Coast News and Weather - Southwest Florida News - April 27th, 2025 [April 27th, 2025]
- UF study finds risky human behavior is the cause for most alligator bites - The Palm Beach Post - April 19th, 2025 [April 19th, 2025]
- Study Finds 96% of Gator Bites Are the Result of Risky Human Behavior - Gizmodo - April 19th, 2025 [April 19th, 2025]
- A Growing Pathway to Understanding Human Behavior - University of Northern Colorado - April 19th, 2025 [April 19th, 2025]
- The Rehearsal S2: Nathan Fielder Explores Human Behavior - Hollywood.com - April 19th, 2025 [April 19th, 2025]
- A Bad Rap: Most alligator bites are caused by risky human behavior, UF researchers say - WCJB TV20 - April 19th, 2025 [April 19th, 2025]
- AI humanoid robot learns to mimic human emotions and behavior - Fox News - April 19th, 2025 [April 19th, 2025]
- INTERVIEW: Dying for Sex Director Shannon Murphy on Portraying Authentic Human Behavior by Blending Comedy & Drama - The Knockturnal - April 10th, 2025 [April 10th, 2025]
- 7 Must-Read Psychology Books That Will Help You Decode Human Behavior - Times Now - April 10th, 2025 [April 10th, 2025]
- Vet shares warning against common human behavior that gives dogs anxiety - The Mirror US - March 30th, 2025 [March 30th, 2025]
- BBVA Foundation awards the psychologists who changed the way we understand and predict human behavior - WebWire - March 15th, 2025 [March 15th, 2025]
- Human behavior is driven by fifteen key motives - Earth.com - February 25th, 2025 [February 25th, 2025]
- Nature Human Behavior is back, this time touting allyship - Why Evolution Is True - February 25th, 2025 [February 25th, 2025]
- 30 Times Courtrooms Became The Stage For The Strangest Human Behavior - Bored Panda - February 3rd, 2025 [February 3rd, 2025]
- The Impact of AI on Human Behavior: Insights and Implications - iTMunch - January 23rd, 2025 [January 23rd, 2025]
- Disturbing Wildlife Isnt Fun: IFS Parveen Kaswan Raises Concern Over Human Behavior in Viral Clip - Indian Masterminds - January 15th, 2025 [January 15th, 2025]
- The interplay of time and space in human behavior: a sociological perspective on the TSCH model - Nature.com - January 1st, 2025 [January 1st, 2025]
- Thinking Slowly: The Paradoxical Slowness of Human Behavior - Caltech - December 23rd, 2024 [December 23rd, 2024]
- From smog to crime: How air pollution is shaping human behavior and public safety - The Times of India - December 9th, 2024 [December 9th, 2024]
- The Smell Of Death Has A Strange Influence On Human Behavior - IFLScience - October 26th, 2024 [October 26th, 2024]
- "WEIRD" in psychology literature oversimplifies the global diversity of human behavior. - Psychology Today - October 2nd, 2024 [October 2nd, 2024]
- Scientists issue warning about increasingly alarming whale behavior due to human activity - Orcasonian - September 23rd, 2024 [September 23rd, 2024]
- Does AI adoption call for a change in human behavior? - Fast Company - July 26th, 2024 [July 26th, 2024]
- Dogs can smell human stress and it alters their own behavior, study reveals - New York Post - July 26th, 2024 [July 26th, 2024]
- Trajectories of brain and behaviour development in the womb, at birth and through infancy - Nature.com - June 18th, 2024 [June 18th, 2024]
- AI model predicts human behavior from our poor decision-making - Big Think - June 18th, 2024 [June 18th, 2024]
- ZkSync defends Sybil measures as Binance offers own ZK token airdrop - TradingView - June 18th, 2024 [June 18th, 2024]
- On TikTok, Goldendoodles Are People Trapped in Dog Bodies - The New York Times - June 18th, 2024 [June 18th, 2024]
- 10 things only introverts find irritating, according to psychology - Hack Spirit - June 18th, 2024 [June 18th, 2024]
- 32 animals that act weirdly human sometimes - Livescience.com - May 24th, 2024 [May 24th, 2024]
- NBC Is Using Animals To Push The LGBT Agenda. Here Are 5 Abhorrent Animal Behaviors Humans Shouldn't Emulate - The Daily Wire - May 24th, 2024 [May 24th, 2024]
- New study examines the dynamics of adaptive autonomy in human volition and behavior - PsyPost - May 24th, 2024 [May 24th, 2024]
- 30000 years of history reveals that hard times boost human societies' resilience - Livescience.com - May 12th, 2024 [May 12th, 2024]
- Kingdom of the Planet of the Apes Actors Had Trouble Reverting Back to Human - CBR - May 12th, 2024 [May 12th, 2024]
- The need to feel safe is a core driver of human behavior. - Psychology Today - April 15th, 2024 [April 15th, 2024]
- AI learned how to sway humans by watching a cooperative cooking game - Science News Magazine - March 29th, 2024 [March 29th, 2024]
- We can't combat climate change without changing minds. This psychology class explores how. - Northeastern University - March 11th, 2024 [March 11th, 2024]
- Bees Reveal a Human-Like Collective Intelligence We Never Knew Existed - ScienceAlert - March 11th, 2024 [March 11th, 2024]
- Franciscan AI expert warns of technology becoming a 'pseudo-religion' - Detroit Catholic - March 11th, 2024 [March 11th, 2024]
- Freshwater resources at risk thanks to human behavior - messenger-inquirer - March 11th, 2024 [March 11th, 2024]
- Astrocytes Play Critical Role in Regulating Behavior - Neuroscience News - March 11th, 2024 [March 11th, 2024]
- Freshwater resources at risk thanks to human behavior - Sunnyside Sun - March 11th, 2024 [March 11th, 2024]
- Freshwater resources at risk thanks to human behavior - Blue Mountain Eagle - March 11th, 2024 [March 11th, 2024]
- 7 Books on Human Behavior - Times Now - March 11th, 2024 [March 11th, 2024]
- Euphemisms increasingly used to soften behavior that would be questionable in direct language - Norfolk Daily News - February 29th, 2024 [February 29th, 2024]
- Linking environmental influences, genetic research to address concerns of genetic determinism of human behavior - Phys.org - February 29th, 2024 [February 29th, 2024]
- Emerson's Insight: Navigating the Three Fundamental Desires of Human Nature - The Good Men Project - February 29th, 2024 [February 29th, 2024]
- Dogs can recognize a bad person and there's science to prove it. - GOOD - February 29th, 2024 [February 29th, 2024]
- What Is Organizational Behavior? Everything You Need To Know - MarketWatch - February 4th, 2024 [February 4th, 2024]
- Overcoming 'Otherness' in Scientific Research Commentary in Nature Human Behavior USA - English - USA - PR Newswire - February 4th, 2024 [February 4th, 2024]
- "Reichman University's behavioral economics program: Navigating human be - The Jerusalem Post - January 19th, 2024 [January 19th, 2024]
- Of trees, symbols of humankind, on Tu BShevat - The Jewish Star - January 19th, 2024 [January 19th, 2024]
- Tapping Into The Power Of Positive Psychology With Acclaimed Expert Niyc Pidgeon - GirlTalkHQ - January 19th, 2024 [January 19th, 2024]
- Don't just make resolutions, 'be the architect of your future self,' says Stanford-trained human behavior expert - CNBC - December 31st, 2023 [December 31st, 2023]
- Never happy? Humans tend to imagine how life could be better : Short Wave - NPR - December 31st, 2023 [December 31st, 2023]
- People who feel unhappy but hide it well usually exhibit these 9 behaviors - Hack Spirit - December 31st, 2023 [December 31st, 2023]
- If you display these 9 behaviors, you're being passive aggressive without realizing it - Hack Spirit - December 31st, 2023 [December 31st, 2023]
- Men who are relationship-oriented by nature usually display these 9 behaviors - Hack Spirit - December 31st, 2023 [December 31st, 2023]
- A look at the curious 'winter break' behavior of ChatGPT-4 - ReadWrite - December 14th, 2023 [December 14th, 2023]
- Neuroscience and Behavior Major (B.S.) | College of Liberal Arts - UNH's College of Liberal Arts - December 14th, 2023 [December 14th, 2023]
- The positive health effects of prosocial behaviors | News | Harvard ... - HSPH News - October 27th, 2023 [October 27th, 2023]
- The valuable link between succession planning and skills - Human Resource Executive - October 27th, 2023 [October 27th, 2023]
- Okinawa's ants show reduced seasonal behavior in areas with more human development - Phys.org - October 27th, 2023 [October 27th, 2023]
- How humans use their sense of smell to find their way | Penn Today - Penn Today - October 27th, 2023 [October 27th, 2023]
- Wrestling With Evil in the World, or Is It Something Else? - Psychiatric Times - October 27th, 2023 [October 27th, 2023]
- Shimmying like electric fish is a universal movement across species - Earth.com - October 27th, 2023 [October 27th, 2023]
- Why do dogs get the zoomies? - Care.com - October 27th, 2023 [October 27th, 2023]
- How Stuart Robinson's misconduct went overlooked for years - Washington Square News - October 27th, 2023 [October 27th, 2023]
- Whatchamacolumn: Homeless camps back in the news - News-Register - October 27th, 2023 [October 27th, 2023]
- Stunted Growth in Infants Reshapes Brain Function and Cognitive ... - Neuroscience News - October 27th, 2023 [October 27th, 2023]
- Social medias role in modeling human behavior, societies - kuwaittimes - October 27th, 2023 [October 27th, 2023]
- The gift of reformation - Living Lutheran - October 27th, 2023 [October 27th, 2023]
- After pandemic, birds are surprisingly becoming less fearful of humans - Study Finds - October 27th, 2023 [October 27th, 2023]
- Nick Treglia: The trouble with fairness and the search for truth - 1819 News - October 27th, 2023 [October 27th, 2023]
- Science has an answer for why people still wave on Zoom - Press Herald - October 27th, 2023 [October 27th, 2023]
- Orcas are learning terrifying new behaviors. Are they getting smarter? - Livescience.com - October 27th, 2023 [October 27th, 2023]
- Augmenting the Regulatory Worker: Are We Making Them Better or ... - BioSpace - October 27th, 2023 [October 27th, 2023]
- What "The Creator", a film about the future, tells us about the present - InCyber - October 27th, 2023 [October 27th, 2023]
- WashU Expert: Some parasites turn hosts into 'zombies' - The ... - Washington University in St. Louis - October 27th, 2023 [October 27th, 2023]
- Is secondhand smoke from vapes less toxic than from traditional ... - Missouri S&T News and Research - October 27th, 2023 [October 27th, 2023]