This week: Bart Sights. In cybersecurity, when planning the implementation and ongoing operations, consider how the technology can wear in like jeans. Thoughtful design leads to a security capability which improves with age. Principle: Wear in, not wear out.
Previously: Think of Roberto Giolito who let his design be ugly where it didn’t matter, in order for the design to be Car of the Year where it did matter. Ruthlessly prioritize. Principle: Dare to be ugly.
At a time when public health departments have been stretched thin by the coronavirus pandemic, telehealth solutions have helped ease the strain by connecting doctors remotely to patients. That has been especially useful during a time when everyone has been advised to maintain social distancing to help reduce the spread of the virus.
Part of the issue involves making sure the professionals who are operating the telehealth tools “have good visibility into who is compliant and who is not,” says Wolf Goerlich, advisory CISO at Cisco’s Duo Security. “A good deal of time and attention is spent on that.”
The actual appointment itself presents challenges, Wolf notes, because doctors and patients may all have different devices, different network settings and conditions, and varying bandwidth constraints.
Throughout this process, there are a number of security systems at work, says Goerlich. There is a need to confirm the clinician is who they say they are. The clinician and patient devices need to be certified as healthy and free of malware or are not going back to a command-and-control site.
“From a technical perspective, it comes down to really good authentication, access controls, adaptive access policies, device health and the integrations that happen along the way,” Goerlich says.
This post is an excerpt from a press article. To see other media mentions and press coverage, click to view the Media page or the News category. Do you want to interview Wolf for a similar article? Contact Wolf through his media request form.
Denim jeans are magical. Wear after wear, they mold themselves to ourselves. Denim jeans are hazardous. The way we produced these jeans in 1850s is far from eco-friendly. Jeans both document our personal experiences and reflect our societal shift towards environmentalism.
Denim also harbors a lesson for security capabilities. We’ll get back to that in a moment. But first, did you know Levi Strauss has a resident mad scientist?
That would be Bart Sights. Sights leads the Eureka Innovation Lab. When he joined Eureka, it didn’t look good. The techniques to produce and finish a pair of jeans used incredible amounts of water and left behind a bath of chemicals. Neither were concerns back in the 1850s when water was plentiful and production was a fraction of the scale it is today. To address this, Sights and his team kept the outcomes but tossed everything else. Starting with what makes jeans good jeans, the so called four Fs of fiber, fabric, fit and finish. Then working backwards to find different ways to achieve each. Eventually, Sights completely revolutionized the entire manufacturing process. Jeans stayed jeans. But the chemicals were filtered and recycled. And the water? Eureka’s process reduced water by 96%.
Bart Sights brought his love of denim and his need to innovate together, modernizing the means yet preserving the ends. The secret is to never forget where you are coming from. Sights’ earliest memory of denim goes back to getting three pairs of Levis ever school year. “I would watch with amazement as they changed and aged as I wore them every single day for a year, literally becoming a walking history of my experience and expression. To me, that is the magic of denim jeans.”
Patina. The design term for that sort of magic is patina. In jeans, this comes from the indigo dye and how it wears while being worn. Leather also develops a patina as it picks up oils from the skin and scuffs from the environment. The copper awning on your house oxidizing a lovely green? Patina. The counter-intuitive idea is using materials and creating designs which get better with age and use. The object becomes etched, documentation of where it has been, nostalgia manifest. If you’ve wondered why we love such items, now you know.
In cybersecurity, having people love us is a high target. Perhaps even out of reach. Still. When planning the implementation and ongoing operations, consider how the technology can develop a patina. Tuning a SIEM is one example, with each time making the rules and reports more comfortable. Machine learning has a natural patina as exposure to data wears it in and shapes it to reflect our organization. So, ML on email for fraud detection is another IT example. On the process side, slot time into operations to smooth out edges and improve the work. Much like Bart Sights re-envisioning production while keeping true to the outcomes, we too can squeeze a lot of water out of the process. Thoughtful design leads to a security capability which improves with age.
Design to wear in not wear out.
Cybersecurity that fits like a favorite pair of jeans, photography Blake Burkhart
This article is part of a series on designing cyber security capabilities. To see other articles in the series, including a full list of design principles, click here.
Taking a day off work, I’m thinking about how work gets structured. Use standards such as CIS Critical Security Controls, NIST SP800-54b, and the National Initiative for Cybersecurity Education (NICE). Define what the team will do and, just as important, what the team will not do.
The common belief in CyberSecurity is that end-users want security that’s all but invisible. But studies are showing a surprising fact: people want to be involved and want to put in some effort. Let’s take a closer look at the IKEA Effect and Effort Justification cognitive biases and see if we can’t piece out what’s going on.
It’s time to rethink risk – both how to operationalize it and how to define it. With all the incompatible views of risk from different stakeholders through an enterprise, it’s hardly surprising that so many organizations struggle to get beyond checklist security mentality.
“Start with a listening tour: What (those other LOB executives) care about, what their business objectives are,” says J. Wolfgang Goerlich, advisory CISO of Duo Security. “You must interpret and explain security needs as business outcomes. Security can no longer be about avoiding the bad things. It must align to the business direction.”
I’ve been vocal about my disillusionment over risk management. It has it’s place, to be sure. It was my starting point. And I gave a number of talks advocating risk management, say 2008-2015, including one for the Society of Information Risk Analysts (SIRA). Risk management techniques are excellent at prioritizing efforts within the security function. But having built programs around risk management, I’ve realized the limitations.
People don’t think in terms of risk. Risk treatment tables don’t resonate with our stakeholders. High or low is meaningless without context. People don’t get it.
People also don’t act on risk. Wendy Nather coined this “cheeseburger risk management,” a term which I love. People will eat cheeseburgers even though they know the risk. They’ll eat right up until they have a heart attack. Only then will people get serious about what they eat, and as evidence shows, that discipline only lasts for a short time.
This post is an excerpt from a press article. To see other media mentions and press coverage, click to view the Media page or the News category. Do you want to interview Wolf for a similar article? Contact Wolf through his media request form.
With apologies to Yves Saint Laurent, who once said fashion fades but style is eternal. While we’re all caught up in what’s changing, it’s imperative to look at aspects of CyberSecurity that are, if not eternal, certainly are long-lived.
People are stressing their jobs, their health, their family, and their friends. Meanwhile, people are working from home with lessened security. These two are a dangerous combination.
Small and midsize businesses (SMBs) have long had a reputation for being behind the curve in cybersecurity, especially compared with large companies that have more resources. A new report shows SMBs are just as capable of defending themselves, despite facing similar challenges.
“We see time and time again that SMBs are actually punching above their weight,” says Wolfgang Goerlich, advisory CISO with Cisco Security. “They’re doing better than we would’ve anticipated.”
Overall, the numbers indicate small businesses are placing a stronger focus on security over time. The same sentiment is echoed in data from The Manifest, which recently released results from a survey of 383 smaller organizations, most of which had fewer than 50 employees.
Goerlich attributes the rise in public scrutiny to two factors. One is the realization of supply chain and third-party risks, which are prompting customers to ask more questions. Even small suppliers selling tools are getting hit with inquiries more often. Another is the trickle-down effects of regulation and compliance requirements, which usually affect larger vendors first and then are passed down to smaller suppliers. Now, they’re reaching the SMBs surveyed here.
“If you’re a customer, your voice alone may not move the needle … but the voices of multiple customers move the needle in a significant direction,” he says of the rise in inquiries. Requirements for today’s SMBs are issues that enterprises were struggling with six years ago.
One thing I’ve long called for is companies to demand more from their vendors, in terms of security. This creates market pressure. This ties security to revenue. And ultimately, these steps result in improved security because customer demand results in executive support for security teams.
Good security delivers a business result and, in doing so, increases the security posture. Here, the business result is keeping existing customers and attracting new ones. The last six years has seen this call turn into a reality.
This post is an excerpt from a press article. To see other media mentions and press coverage, click to view the Media page or the News category. Do you want to interview Wolf for a similar article? Contact Wolf through his media request form.