Robin Bylenga started her cybersecurity presentation with a story – about her time growing up in West Texas, being bucked off every horse she tried to ride – her father always insisted she get back up and try again.
The point of the story quickly became obvious – Bylenga was trying to humanise herself and create a connection with the audience, a packed room at Dynamic Earth for DIGIT’s Scot-Secure 2023.
This is the exact thing she recommends companies do to improve their cybersecurity – maybe not tell a story involving barnyard animals, but to connect with their employees.
Blind Spots in Cybersecurity
Bylenga went on to point out the ‘blind spots’ deteriorating cyber perspectives – keying in too closely to technological advancements is blocking out both the route of many cyber problems, and potential solutions.
“We can’t spend all of our time and money on processes, not logic,” Bylenga said.
When analysing the processes that go into cybersecurity incidents and attacks, however, certain things become clear.
“We’ve seen the data, heard that 95% of cyber attacks are caused by human error, that humans are the weakest link,” Bylenga said.
While Bylenga does not like this ‘negative’ language, it would logically follow that if humans are central to the problem, they might be key to the solution.
And we are desperate for a solution – amid major cybersecurity staff shortages and an increasingly digital world, cyber attacks are increasingly sophisticated and perverse. From nation state actors trying to take down hospital infrastructure, to email phishing attacks trying to access personal information, the threat landscape is less secure than ever.
As the pandemic shifted many workers remote, the increase of Internet of Things (IoT) devices only increased the number of avenues for potential attack and leak risks.
Startling statistics were presented: by 2025, 347 billion emails will be sent and received daily.
The global cost of data breaches will reach $9billion, according to IBM.
And financial loss will increase by 76% due to successful phishing attacks, according to the State of the Phish report by ProofPoint.
Throughout all of these changing issues and landscapes, people remain central to cybersecurity.
During the Scot-Secure event, NHS Highland was chastised for their lack of proper data protection practices: a simple human error of CC-ing rather than BCC-ing an email revealed personal health data. Human errors such as clicking on scam links can be devastating for a company.
While cybersecurity technology may be advancing, in many companies security can still come down to simply following ‘best practices.’
But the humaneness of people is often ignored in favour of developing and investing solely in technology – processes rather than logic.
“We’ve got brilliant tech,” Bylenga assured the audience full of cyber specialists, “but we can’t get so secure and have a false sense of security that the tech alone is going to protect us.”
Human Errors, Human Solutions
According to the 2023 Gartner report on cybersecurity, by 2025, a lack of talent or human failure, will be responsible for over half of all significant cyber events.
While the report understands that human error is a major factor in cyber incidents, it also predicts that 50% of CISOs will adopt a human centric design to reduce ‘operational friction’ within cybersecurity.
This prediction comes after finding that 90% of employees who admitted undertaking a range of unsecure actions during work knew their actions would increase cyber risks,, but did so anyway.
This phenomenon is what Bylenga classifies as a non-malicious, with intent incident, where employees put their company at risk not due to any malicious intentions, but to side-step protocol, get their work done faster, improve efficiency, or even by simply using their own non-secure device.
But why would people knowingly put their organisations at risk? Surely, they would be to blame for any incidents or successful phishing attacks.
Recommended
- Scot-Secure 2023 | What does the Cyber-threat Landscape Look Like?
- ICO Reprimands NHS Highland for “Serious” Data Breach
- Maintaining Trust in AI-Based Journalism
Shifting the Blame Game
According to Bylenga, this thought process is entirely wrong.
“The Information security department needs to be a part of a department of trust, not a department where people feel intimidated, or where people feel stupid, or uneducated,” Bylenga insists, indicating a culture shift is needed to better enhance security.
“Malicious acts are a very, very small part of what actually happens in our corporations,” Bylenga informed the audience. “Much more of it has to do with mistakes or systemic issues.”
Accidentally disclosing passwords, skipping trainings, violating protocols to get work done faster, are more typical instances affecting the companies.
But in mitigating these issues, Bylenga insisted on building a department of trust – “Because ultimately, in reducing risk, we want people to report.”
Removing blame, but not accountability, would encourage more employees to proactively report any incidents without fear of repercussions.
Getting to understand a department can better direct training, and building a human connection is vital for effective communication from both parties.
When pressed about how to properly discipline an employee who regularly broke protocol by clicking on phishing links, potentially jeopardising a company, Bylenga stuck to her guns.
Firing was out of the question.
“That’s just never the right move,” she said. Understanding a team and why a person may be making these choices was more important in the long run of avoiding future cyber incidents.
Part of her recommendations included managing by walking around, asking questions about day to day operations, and understanding employee concerns before making decisions on training or security protocols.
Reaching out to people where they are, rather than where you might want them to be, is also key in creating relevant training practices.
Understanding systemic issues, rather than shifting blame to individuals, is vital in building a communicative, trustful, and secure company.
“Security is all of us, and it takes a whole team, not just the technology,” Bylenga drove home the point.





