It’s a common cliché in cybersecurity that humans are the weakest link in an organisation’s defences. All the tools, tech, and processes mean nothing when one wayward click can give attackers access to vulnerable systems.
However, despite this, organisations frequently neglect the human element when securing their operations and fail to build a strong security culture. Their employees lack adequate training, or utilise user-unfriendly systems, making mistakes more likely and increasing the potential of users circumventing controls with dangerous workarounds.
With people so crucial to security, there is one group that doesn’t neglect them – cybercriminals. They will exploit any weak spot to penetrate or evade defences. Social engineering techniques, which manipulate people into giving hackers access, are the foundation of the majority of cyberattacks – 99%, according to Proofpoint’s The Human Factor report.
When breaches frequently occur due to mistakes made by an individual, a robust security culture is as important as good cybersecurity tools.
For award-winning cyber anthropologist Lianne Potter, who will be speaking at DIGIT’s Scot-Secure 2022 conference on March 23rd, the human element is the foundation of cybersecurity. And it’s one that security teams neglect at their own peril.
Weak Links
While it may be a common idea, saying that people are the weakest link in cybersecurity, Potter warns, can actually weaken an organisation’s security culture.
“It always makes me bristle when people call other human beings the weakest link,” she says. “The terms security teams use, like insider threat, least privileged, zero trust, we don’t endear ourselves to other people.
“So how are we going to get people onboard if we use terms like that?”
It is this that drives Potter to warn that the biggest threat to cybersecurity is a failure on the part of cybersecurity practitioners to properly work with other teams.
“It’s that kind of thinking that turns people off from engaging with us,” she explains. “We need people onside as the first line of defence because they’re seeing the things that we can’t possibly have – oversight, day in and day out.”
Building Security Culture
Potter uses lessons from the social sciences to identify gaps in security cultures and areas for improvement.
She notes that when establishing a security programme, it is vital to get the organisation’s induction right as it is often your first touchpoint with a colleague and a perfect opportunity to embed security early. After all, most personnel will only engage with the security team when they start, or during an incident.
One technique Potter uses is to tell people stories about all the times she has been a victim of hacking.
“It makes the new person realise if this can happen to someone who lives and breathes security, it could happen to anyone.
“That enables people, when something happens to them, to come to us for queries. And it opens that door in a way that telling them what they should and shouldn’t do doesn’t achieve.”
Emotional Response
Fear, uncertainty and doubt have a longstanding place in propaganda and manipulation. For cybercriminals, these are essential emotions to manipulate in their victims. For cybersecurity professionals, it is vital to dispel them.
That said, fear can be a powerful tool in building security. It emphasises the seriousness of cybersecurity, and the potential consequences of a breach.
But it can also erode confidence and trust among personnel. After all, if people fear getting in trouble for making a mistake, they are likely to conceal their actions or delay reporting it.
The ability for the security team to cooperate with other groups throughout an organisation is critical to building a security culture. And above all, this needs everyone to trust each other.
“One of the hardest things to do when you’re setting up a security programme is getting people to trust you to report things,” Potter says. “You need to embed a culture that says it’s okay to report, that you’re not going to get in trouble for reporting things.
“The last thing you want as a security practitioner is for someone to click on something and then sit on it. Once you’ve a culture when that happens, one where people are immobilised with fear, you’ve lost and the cybercriminals have won.”
The question is how to build a strong security culture, where everyone is trusted, accountable and invested.
“The security team is the best place to start,” Potter explains. “There’s no point building a new security culture if your security team aren’t on for the journey.
“And to do that we have to look at how are they engaging with each other? Are they supporting each other in their own endeavours as a team? Because if that’s not happening, then how can we expect everyone else to support us?”
Give and Take
Reciprocity is a principle that Potter uses to build trust and cooperation between teams. This involves doing favours to build a relationship with a team, and in turn receiving similar favours down the line.
“In terms of security, I’ve given gifts of access before,” she explains. This involves approving the use of tools, data, or systems, especially where previous responses have been no.
“If I give the gift of access to a tool that has previously been denied, the other team will want to do something in return. And that could be something as simple as helping me out with a vulnerability management scan.”
With greater cooperation comes greater security buy-in. When everyone is on the same page, understanding the threats, and confident in their roles and abilities, people are happier to be held accountable for their actions.
“Accountability in security is the gold standard,” Potter says. “But people don’t often volunteer themselves willing to be held accountable on an RACI matrix; it’s one of the biggest struggles in security. This is because often, accountability means, at some point, you are going to be blamed for something or you are going to have to explain your actions eventually.
“If you don’t give people the psychological safety to be able to ask for help, to be able to challenge things or give them the tools they need when eventually something does go wrong, they’re going to have to justify their actions.
“And if you don’t give people that environment where they feel like they could say I did this for this reason, then no wonder nobody’s going to be accountable.
“But that’s where reciprocity comes in,” she continues. “If you slowly start building those relationships then you can see more people wanting to be accountable because they know that even if something does happen, and maybe they have made a poor decision, they can justify it.”
Read more Leader Insights
- Scottish startups need to scale-up, not sell out
- Demystifying tech to address the skills shortage
- Transforming the BBC with responsible AI
Another technique Potter uses is participant observation. Typically, this involves embedding oneself in another team and observing how they work.
“The idea is you get so ingrained that you actually become part of their world and they no longer see you as an outsider,” she says. “And then you start seeing all the pain points and blind spots.”
This helps the security team build up a realistic image of typical behaviour across an organisation.
“What happens too often is security policies are based on a lot of best practices,” Potter warns. “Which is great, you need those. But you also need to back that up with your understanding of what it is really like to live and breathe and work in your organisation in different departments.
“Sometimes best practices aren’t necessarily what’s ‘best’ for your business needs, so you need a security team that is able to see the wider strategic picture.”
Tools to Develop Security Culture
So where do tools and technology fit into a good security culture? While they are undoubtedly powerful, they need to be used correctly, in a way that supports their users.
“I’m all for tools that remove the boring elements. I am all for automation,” Potter says. “But it needs to be done with contextual understanding.”
Take phishing emails, for example. Simplicity and ease of use is essential to reduce the time and thinking needed to deal with a potential attack.
“People will always choose the path of least resistance, anything more complex and people avoid it or put off doing it,” Potter says. “You want to reduce as many barriers as possible to people reporting phishing emails.
“What I try and encourage is to create a reporting scheme that’s just to forward on the email. Anything that has any more steps is not going to happen.
“It’s almost like training people to be a bit more automated. I want the user to say to themselves: ‘I’m not sure about this email, but I want to move on with my day’, and they can put that email straight into the phishing reporting system.
“We, as a function, need to reclaim ownership of security mishaps and avoid putting so much stock into explaining ‘why’ we do things as a security team – after all, we’re the ones who care about it, everyone else has other priorities. All we should care about is our colleagues knowing how to respond, or how to avoid.
“The why is often of very little interest to the average person…unless you have a good story to tell! And cybersecurity certainly has plenty of them!”
Scot-Secure 2022 | Cybersecurity Conference
The 8th annual Scot-Secure Summit will take place on 23rd March at Dynamic Earth in Edinburgh, and will be streamed live through our virtual conference platform.
The programme will focus on promoting best-practice cyber security; looking at the current trends, key threats, and offering practical advice on improving resilience and implementing effective security measures.
To find out more and sign up for the event, click here.





