Monday, May 1, 2017

Core human psychology principles are what hold us back with security

Core human psychology principles are what hold us back with security


2015 marks my 26th year working in IT and my 20th year focusing on information security. Im so fortunate to work in such an amazing field and even luckier to have gained some wisdom over the years that has allowed me understand the true challenges we face with information security!

As much as the vendors, researchers, and criminal hackers want us to believe its the threats that cause all the problems, Im convinced otherwise. Across the millennia of human existence, people with ill-intent have been a given - a fact that cannot be changed. Threats, both large and small, will always exist in the physical and digital realms. What can change is our approach to the threats we face, especially in the digital world.

You know the saying "Its not what happens to you but how you react to it that matters." Thats nearly 2,000-year-old wisdom from Greek philosopher Epictetus. And it still applies to our world today! 

Whats most important with information security is not just we "react" but how we "respond" and minimize the impact when things go awry. This can only be done through well thought out plans which, in turn, requires seeing the bigger picture and "getting" security.

Ive written a few pieces recently on how human psychology impacts information security - both positively and negatively - such as:

Blog Archive