They say there is no patch for human stupidity. And: "The problem exists between chair and keyboard" (PEBCAK for short). They say: "That's a layer 8 issue." or "The weakest link in the chain will always be Bob, who clicks on a flipping phishing link."
They? Tech people mostly or friends and colleagues of tech people, because these are good insider jokes that show you know tech. It was I, who said it.
But all this might not even be true after all.
- 1.
There might just be a patch for "human stupidity"
- 2.
The problem might also exist elsewhere
- 3.
The issue might stretch through the whole stack
- 4.
Maybe it's the whole chain that's weak
So, let's get some weight on these scales:
1. Patch The People
Assuming, it is true, that there is no patch for human stupidity: Why do we even educate, like, at all? Because, at some point in everyones lives they knew little, then they got educated and became less stupid. Claiming people to be uncapable seems more like a foul and easy answer to the question: why. Assuming bad intent would be too far and pretty much every other explanation is far too complicated to be practical. And calling them stupid boosts our own standing as well, which is, well, not nice, but it does feel nicer.
But more than anything else, calling people stupid sets us apart from others. They can't do it better, but I can. They are stupid; I am great. So besides being easy it also boosts our ego. But it does not help. People who get called stupid on a somewhat regular basis tend to either just shut down or even accept that they might be stupid and cannot learn anything. Neuroplasticity does teach us otherwise though. Humans can learn, given beneficial circumstances and the right impulses at the right time plus social and emotional backing and such.
This means: There is a patch for human "stupidity". If we locate the bug in the Knowing than the patch is Teaching. "Now now," I hear you cry. "They get their mandatory annual security training but they still didn't learn!" Yeah, sure.
Let's try this: Do you know, without looking it up, how to help a person, say, in shock or with hyperthermia?
If yes:
- 1.
the training was very recently
- 2.
you use the knowledge somewhat regularly
- 3.
you needed that knowledge in an emotional moment
- 4.
or your brain made a strong connection to another well remembered knowledge
The vast majority of people will have experienced some training in some field where they received an information, but they forgot and cannot bring that up in their daily life. And this is ok.
When I started in InfoSec, I tried to learn everything. Just gotta try harder, amirite? Well, safe to say, I scrapped that approach, because in the meantime, alone, more information emerged in the field than I could have possibly learned. This is ok. And it is ok for Bob, not to be up to snuff on phishing. Because, you know, Bob is really good at figuring out solutions for tenants against their landlords. Like, really good. He gets them emotionally, he can translate what they say into legal terms, he knows his way around the law and the recent cases, he can do the math and he almost always finds a way to strike some balance and figure out a solution for his clients. He also is very invested in the problems of his clients. He can use the computer by the way. He installs all the updates in a timely manner - good job, Bob! But he just cannot get a glimpse on which emails would be suspicious and what to do about that if he caught one. Also, he doesn't have time for that because his employer is low on budget and he has to fit as many cases in his working hours as possible.
What I'm getting at are the following things:
- 1.
People are good at something and that can occupy them already. The fear of being replaced by an AI and not finding another job because every manager and their uncle are convinced all the jobs can be done by an LLM now does not really help in that regard.
- 2.
When people don't get the time to learn about security in their working hours, they most likely won't do the security in their working hours; which is bad.
Patching people will involve more than just information. Which leads me to the next point.
2. Where's The Problem?
What we really care about is less the people and more what they do. The actions or omissions. The decisions. We established, that knowlege would help, but it is not that easy to get that knowledge into people's brains in a way for them to act on that knowlege in the right moment in the right way. Obviously, we need people to more than just know.
We need them to:
- 1.
know,
- 2.
recognize the risks and threats
- 3.
act good and securely and
- 4.
care enough to consistently keep at the other three.
This is what we want from people, but we cannot do this for the people, meaning we depend on them doing those for us. So we have to provide an environment that allows them to do these things.
The Knowing
This often is already in action some way or another. When we want to address this part we should consider several aspects. Do we use web based or in-person training? Which technical depth is appropriate for different departments or teams? How much time of each employee are we willing to spend on the training? But also: Which metrics do we need (e.g. for compliance) and which do we want? How do we address naysayers? Which channels do we want to use (training platform, newsletter, intranet, regular webcasts, etc.)? To get an effective training program, some thought and intent has to be invested.
The Recognizing
I'd classify recognizing not as something that simply happens because you know something. It's closer to a skill that you have to develop. That's the point, where I do recommend phishing simulations; although with certain rules:
up front communication; be as transparent as the process allows you to
no individual metrics; I don't care if Bob had a bad day and clicked or looked right through the ruse and clicked just to see the teachable moment, the aggregates are plenty a metric
no repercussion; don't even think about it, people don't learn adequately when threatened
the simulations are there to train recognition; appearance and emotional techniques of phishing
And since other channels gain traction (chat, phone calls, etc.) it might be good to invest in measures that lead people through such events in a controlled environment. It's easier to recognize if you experienced it. Phishing simulation rules apply where they fit.
The Acting
Good actions come from good guardrails. We'll gain much in security, when the secure action also is the easiest. That means investing in good UX on user facing tech and processes. This is hard. This involves your identity management and everyone concerned with internal communications and your ISO and the team leads. One of the easiest measures would be implementing a report button in the email client which forwards an email to it/security for risk check. When "just doesn't look right" consistently leads to reporting, because it is easier than weighing the risk of interacting with social engineering against the risk of being shunned by the helpdesk, then we have a safe default to work with. The report button can be adopted generally. But the hardest task is to figure out which aspects should be changed in which way. Usually, in my experience at least, there's rarely a backchannel that doesn't dismiss complaints. So to enable safe acting is to enabling this feedback first; in process, tech and culture.
The Caring
While the acting part is hard, the caring part extends the measurement. That's security culture; that's first prize. But it's almost impossible to reliably measure and even harder to implement. But in the short I'd pin it to reciprocity. If you can honestly convince your employees that you care about them and the struggles they face and the effort they invest, then you're on a good track. That's part of a organisational culture which can also hold a mature security culture.
The Problem - it's complicated
There is more to Security Awareness than just awareness. If we want people to know, recognize, act and care we have to put in some effort; more than the annual training for the check on the list.
Also: Didn't we forget some people?
3. Non-user People
When referring to the human factor, security folks tend to point towards the end users. This would carry more weight, if it wasn't for stuff like:
default/reused/short passwords on admin consoles
admin consoles on the open web
Next Generation Firewalls with 1 rule: any-any-accept-nolog
setting up LLM-Chatbot with write privileges for account reset
shaming people for asking mundane questions
hard coded credentials in security appliances
uploading access tokens on public GitHub repo
diverting budget from security to marketing
benchmarking AI agents for cybersecurity while maintaining internet connection via proxy
All this is done by people and it has direct or indirect security consequences. Security relevant mistakes aren't done by end users alone. And the grave ones can rarely be blamed on them. From software development to configuration; from management to process and service responsibility; Cyber is People1.
Especially infosec people shouldn't choose the "easy" path of shoving all the blame on end users busy doing their day job (Thanks Bob).
4. The Weak Chain
When we speak of people as the weakest link in the chain we explicitly shift the blame on the users. But actually many components failed to contain an attack: People, Process, Tech and their subcomponents. Do you like cheese?
According to the Swiss Cheese Model incidents happen because all of our security layers, like slices of swiss cheese, aligned the holes to make the incident possible. I mean, we know this. Defense-in-Depth, multi-layered Security; this is not new and not niche, so why do we still talk like a single link decides the outcome? The chain metaphor over simplifies security architecture and it's not helping. We don't want a chain, we want at least a net. A string can snap but the next knots keep it together. A link was clicked, but an immediate report enables swift remediation. This is a many people and many skills effort.
There are a lot of people putting much thought in designing software, processes and networks with many components and they think about possible deviations and how to mitigate them. They think like the attacker and prep the tech and the policy accordingly. Threat modeling, Red Teaming, Assume Breach, Business Continuity; we rarely apply that to people with the same thoroughness as to tech and processes. We could, though. But, just like the tech requires some understanding and working with technical constraints, people require understanding, accepting and working with people constraints.
People do make mistakes. Our brains try to lessen the energy consumption. People do have emotions and, frankly, we want them to.
It's Always About People
In InfoSec we do like to tend to tech and processes, because they provide facts and numbers. They are deterministic and they produce those KPIs and reports and checklists and then we can say: We're secure. The firewall rule matches or it doesn't and we can look into the logs and we can track number of blocks and tell management "We defended against 3 bagillion cyberattacks this month!"
And I do get that we need something to show efficacy and something to prove our compliance because this, also, is part of the job. But I would like to challenge you to first of all keep an open mind towards the people problems. And those do involve us people as well. People, in the narrow sense of end users, are not THE problem; People, in the wider sense, are, because we don't apply the same thoroughness to ourselves that we demand of the rest of cyber.