Welcome to the Re-thinking the Human Factor podcast. Hosted by Bruce Hallas, it is a podcast about information security awareness, behaviour and culture for information security professionals.
Bruce is the author of “Re-thinking the Human Factor”, and the founder of Marmalade Box a strategic information security consultancy that specialises in security awareness behaviour and culture. He is also the founder of The Analogies Project, an online library of analogies for security professionals to use in communicating the information security story.
In this show, Bruce interviews guests from outside the information security industry who specialise in aspects of awareness, behaviour and culture and invites them to share how they have effectively tackled the challenges we face as security professionals.
Bruce also invites leading security professionals and CISOs to review the episodes with him so that you can hear what they’re taking away from the podcast.
Guests include best selling author Dan Ariely, Gert Hofstede and Rachel Lawes, John Pollack who was Bill Clinton’s former speechwriter, and Greg Michaelidis, the former Director of Communication at Homeland Security for President Obama’s Administration
If you’re interested in nudge theory, behavioural economics, storytelling, organisational culture and communication, then you’ll find something of interest.
Awareness, Behaviour, Legal and Regulatory Requirements, with Jonathan Armstrong Welcome to Series 2, Episode 7 of the Re-Thinking the Human Factor Podcast. Joining us on the show today is Jonathan Armstrong, a lawyer who helps multinational clients with risk and compliance across Europe. Recent projects include lots on data breach, GDPR & data transfer, UK Bribery Act 2010, internal investigations, ethics & compliance code implementation, emerging technology, and corporate governance & online reputation. He has also written articles on technology and compliance related topics. He is a Fellow of The Chartered Institute of Marketing (FCIM) and Vice-Chair of the New York State Bar Association International Section. Jonathan has also spoken at conferences in the US, China, Brazil, Canada, Vietnam, Singapore, Dubai & across Europe. In addition, he’s been involved in the development of a number of technology applications going back to the 1990s and was twice a Regional Finalist in the UK Government dti/ISI Awards for Innovation in e-commerce. JOIN JONATHAN ARMSTRONG AND BRUCE HALLAS AS THEY DISCUSS THE FOLLOWING: Training / Practice for helping to not only reduce the likelihood of cyber attacks, but also how to address a problem when something goes wrong (which it inevitably will at some point) The law is increasingly saying that companies must implement some form of education and awareness training, and when a breach does happen, companies must have their arguments ready pre-breach so they can respond effectively to a breach and be able to defend their efforts to stave off the attack Those who have managed breaches most effectively are those who have run simulations and had a plan in place Stakeholder management The role Education and Awareness plays in terms of how a regulator might look at a breach How to spot training programs that will pass regulations vs those that won’t The disparity between the cost of high-quality training vs the cost of handling a breach or facing fines for non-compliance MORE ABOUT JONATHAN ARMSTRONG: LinkedIn Please subscribe to the podcast in iTunes, and if you enjoyed this interview, please share with your friends and colleagues and leave a 5 star rating and review. Thanks for listening and sharing. Bruce & The Re-thinking the Human Factor Podcast Team
On Episode 6 of series 2 of the Re-Thinking the Human Factor podcast, we are joined by Dr Char Sample to dive into the topic of culture and the role it plays when it comes to cybersecurity. But this podcast chat is not what you will expect to hear when it comes to culture; we're going to explore how your cultural values can be used against you in cybersecurity attack. Some of the topics we're going to dive into during this podcast episode include Cultural Dimensions, Geography of Thought, and Values as a Vector for Attack. Culture and cybersecurity Dr Sample is a researcher-fellow employed for ICF at the US Army Research Laboratory in Adelphi, Maryland and has over 20 years experience in the information security industry. Dr Sample’s area of research examines the role of national culture in cybersecurity behaviours. At the moment, Dr Sample is continuing research on modelling cyber behaviours by culture. Other areas of research are information weaponisation, data fidelity and fake news. Dr Sample is a frequent collaborator with the University of Warwick, in the UK which is where she completed her fellowship. “It’s an old Russian proverb: ‘TRUST, BUT VERIFY.’ We put all of our eggs in trust and we left verify exposed.” JOIN CHAR SAMPLE AND BRUCE HALLAS AS THEY DISCUSS THE FOLLOWING: The meshing of two schools of cultural thought to create a more complete cultural model from which to approach awareness, behaviour, culture, and even defence campaigns: Hofstede’s Cultural Dimensions Theory Nisbett’s work: “Geography of Thought: How Asians and Westerners Think Differently…and Why”
Design for success - Whether you’re designing a phishing campaign, an education awareness campaign, how you’re going to manage incidents, whatever it is, it’s about understanding that all of this is being done with people in mind, either as the victims, the perpetrators, or the middle people. You can’t shape culture in the short-term, which causes a clash between organisational culture and security culture. Organisational cultures often look for success metrics every quarter, but culture takes much longer to change. We all have cultural lenses, and those cultural lenses help us (or don’t help us) with the definition of what it is that we see. The Cultural Dimensions Theory is old enough that we now have tons of data to analyse around the 6 dimensions. Cultural values are very enduring because those values are reinforced all throughout society. So, you’ve got this lifelong influence on culture / shaping of culture, and you’re trying to set up a security culture within your organization — Which one is going to win? Insights around culture and how that relates to victims. How important is the role of values in decision-making? Also, Char shows an example of how to map behaviour to Hofstede’s Cultural Dimensions to give a possible answer to the question. Culture as a vector for attack. “We have a tendency to want to throw technology at the problem. But of you don’t take the cultural values of the person who’s sitting at the end of the computer there, and who’s going to be the recipient of this data, if you don’t take that into account, you can at best have a partial success.” Further study and research Hofstede’s Cultural Dimensions Theory Nisbett’s “The Geography of Thought: How Asians and Westerners Think Differently…and Why” About Dr Char Sample LinkedIn Please subscribe to the podcast in iTunes, and if you enjoyed this interview, please share with your friends and colleagues and leave a 5 star rating and review. Thanks for listening and sharing. Bruce & The Re-thinking the Human Factor Podcast Team
Observations and Take-Aways: Episodes Review with Craig Thomson, Security & Awareness Manager On this episode of the Re-Thinking the Human Factor Bruce Hallas is joined by Craig Thomson, the Security Education & Awareness Manager at Nationwide Building Society. He is an experienced Education specialist with a demonstrated history of delivering impactful results in the Defence, Air & Space and Information Security arenas. He is skilled in the management of Training Programme and solution design using SAT and ADDIE methodologies to deliver engaging and meaningful training and communications that create measurable behavioural change. Craig values using effective emotional intelligence skills to develop teams and solutions in support of achieving business strategy goals. “Awareness is a two-way street… Awareness is just as much about actually being aware ourselves of who our target audience is…” JOIN CRAIG THOMSON AND BRUCE HALLAS AS THEY DISCUSS: Their shared connection around the armed forces and applicable observations they’ve made about L&D and recruitment for the Armed Forces The importance of people having vested interest in policy creation The problem of cognitive dissonance within company culture (i.e. ‘This is what the policy says, but what push comes to shove, here’s what we actually do’) What motivates people to take part or give their time to engagement with awareness initiatives Awareness is a two-way street Lessons learned around conducting surveys as a means of gathering information about one’s target audience, and other means of garnering useful information and feedback from those people The difference environment makes in training, accurate observation, and behaviour change Sharing ideas across a network of security professionals The concept of “Awareness” as communications that give people a sense of understanding and control over upcoming change in their work environment, which helps them not feel as stressed about the change, which then helps to overcome their innate desire to avoid or not comply with the desired change in behaviour If / how metrics can be used to enhance Awareness strategy and creation MORE ABOUT CRAIG THOMSON: LinkedIn Please subscribe to the podcast in iTunes, and if you enjoyed this interview, please share with your friends and colleagues and leave a 5 star rating and review. Thanks for listening and sharing. Bruce & The Re-thinking the Human Factor Podcast Team
What makes our brains tick, and why does that matter for change managers and organizational heads? The Human Brain vs. Awareness, Behaviour, and Culture Hilary Scarlett is an international speaker, consultant and author on change management and neuroscience at Scarlett & Grey. Hilary’s work has spanned Europe, the US and Asia and concentrates on the development of people-focused change management programmes, coaching and employee engagement. Her specialities include: change management employee communication employee engagement leadership coaching (Inst of Leadership & Management accredited) “A need for control, a need to be able to predict what’s coming up is really important to the brain.” JOIN HILARY SCARLETT AND BRUCE HALLAS AS THEY DISCUSS: The necessity of understanding how our brains work The human brain’s distaste for change A brief rundown on what the brain actually is, i.e. what it does, how it’s made, the structure of it How understanding what our brains do and how they work can guide efforts towards creating proper learning environments and organizational cultures where people can more easily learn and thrive Why our brains are often lazy by default Growth mindset within an organizational culture The importance of prioritizing tasks by order of importance because the brain’s energy / ability to process information critically will become increasingly depleted as the day goes on Tools for getting the brain back on track and restoring some of its energy during the day Understanding how brains process change and what it means for Change Managers The power of storytelling in communications, understanding, and memory “Change is extremely difficult for us if we feel it’s unpredictable and uncontrollable… People further down the hierarchy who feel they don’t have that same sight at what’s coming up and don’t have that same control or influence, their brains are in a much more stressed place than [the boss].” FURTHER STUDY AND RESEARCH Neuroscience for Organizational Change by Hilary Scarlett Edgar Schein Neuroplasticity The Endowment Effect Mindset by Carol Dweck MORE ABOUT HILARY SCARLETT: LinkedIn Please subscribe to the podcast in iTunes, and if you enjoyed this interview, please share with your friends and colleagues and leave a 5 star rating and review. Thanks for listening and sharing. Bruce & The Re-thinking the Human Factor Podcast Team
Did you know up to 80% of information is forgotten within 24 hours? Admittedly, this is not an encouraging statistic for those of us seeking to raise awareness, change behaviour, and foster an appropriate organizational culture. For this reason, we at the Re-Thinking the Human Factor Podcast are looking for answers from outside the security industry from people who can provide an evidence-based path forward which can help us to improve learning and development. We’re happy to share some fresh insights with you on the topic of improving the training experience, likelihood of learning, and stickiness of memory after the training is completed. Evidence-Based Methodology to Improve Learning and Development Stella Collins joins Bruce in Series 2 / Episode 3 of the Re-Thinking The Human Factor podcast to have a deeper look into how we can improve learning and development using evidence base methodology. She is a learning specialist, an expert in Brain Friendly learning, author of Neuroscience for Learning and Development, and the Creative Director of Stellar Learning, a business whose goal is to transform training, learning and communication - particularly when it's tough, technical or tortuous. They support and train their clients to build excellent relationships and make critical messages stick. With a BSc in Psychology, an MSc in Human Communication, a coaching diploma, 15 years in the IT industry, and more than 15 years in L&D, she injects a theoretical knowledge of learning and communication with creative and practical ideas and hands-on experience. Stella says “there’s no such thing as a boring topic – just boring training.” JOIN STELLA COLLINS AND BRUCE HALLAS AS THEY DISCUSS: The importance of knowing the background behind a neuroscientific finding, i.e., who’s done the research, what was on their agenda when they did it, and whether the proper research methodology and statistical analysis was used to arrive at the conclusion on which your team is now basing its L&D and policy changes The empowering nature of evidence-based ideas Effective planning for L&D training, including making people excited about going through the training, and making the most of the time you have with people rather than wasting time and money on a captive audience that will forget most of what they learned within 24 hours (see our opening statement above) The importance of what happens after L&D training, like inter-staff communication and ensuring that the work environment is conducive to easy adoption of new skills and policies What is training, actually? Likewise, what is learning? Neuroplasticity, or the fact that our brains are flexible and able to create new pathways for learning throughout life Ways to maximizing the potential for learning when engaging in training efforts When it comes to learning and memory, humans are not sponges as the metaphor suggests The future of L&D and self-directed learning “An experience, as opposed to fact…When we have an experience, we remember that sensory information… Emotion is massively sticky. Emotions and senses are hugely important.” FURTHER STUDY AND RESEARCH Neuroscienece for Learning and Development by Stella Collins Stellar Learning (Make Your Message Sticky) Choice Architecture Neuroplasticity MORE ABOUT STELLA COLLINS: LinkedIn Please subscribe to the podcast in iTunes, and if you enjoyed this interview, please share with your friends and colleagues and leave a 5 star rating and review. Thanks for listening and sharing. Bruce & The Re-thinking the Human Factor Podcast Team
Understanding decision making in the workplace is almost like the holy grail. What we want is for our colleagues to make better decisions, but for this to happen we need to take a few steps back. Decision making in the workplace takes place in the context of the organisational culture. Often when we talk to people about organisational culture, they see culture as something so big that it becomes too overwhelming to think about. Instead, they prefer to take the path of least resistance, focusing on awareness and driving behaviour. However, behavioural science keeps pointing to the fact that individuals need to feel involved in policy creation if buy-in and actual behavioural change is to occur. But, won’t this take too much time? How can an organisation possibly gain buy-in from all their employees? Interestingly, the amount of interaction that people need in order to feel that they are involved is probably a lot less than you think… Individuals, Groups, Decision-Making, And Self-Regulation Susan Weinschenk joins Bruce in Series 2 / Episode 2 of the Re-Thinking The Human Factor podcast to have a deeper look into this topic. Susan has a Ph.D. in Psychology. She applies research in brain science and psychology to predict, understand, and explain what motivates people and how they behave. Her consulting includes applying behavior science to the design of websites, software, medical devices, tv ads, physical devices, presentations, experiences, and physical spaces. She is an author, teacher, mentor, and consultant to Fortune 1000 clients, government, non-profit, and start-ups. Her books include: How To Get People To Do Stuff, 100 Things Every Designer Needs to Know About People, 100 Things Every Presenter Needs to Know About People, and Neuro Web Design: What makes them click? Susan’s specialties include Behavioural Science, Brain Science, Psychology, and User Experience. JOIN SUSAN WEINSCHENK AND BRUCE HALLAS AS THEY DISCUSS: The influence of individual self-stories on a person’s behaviour Brain function and value-based, goal-directed decision-making vs. habit-based decision-making The importance of similarity in environments between the one in which a person is trained vs. the space where that person will encounter actual on-the-job issues, and how different environments can hamper training and habit-based decision-making What choice architecture is and how it relates to how you build an actual environment to bring around the behavioural outcomes you’re looking for Whether any gains around behaviour can be made without taking into consideration the broader cultural context The power of social norms and groups to regulate behaviour The necessity of involving at least some members of strong-tie teams/communities in development of policies in order to increase buy-in and ensure wider-spread behavioural change The importance of looking at Cyber Security as if it were a product, understanding that having repeat customers of the product is the end goal Drivers of motivation behind people’s engagement with awareness campaigns, and what kind of behavioural change can be expected through gamification and rewards-style motivation “The amount of interaction that people need in order to feel that they were involved is probably a lot less than you think…” FURTHER STUDY AND RESEARCH Re-thinking the Human Factor Ep 05 with Ciaran McMahon Choice Architecture Robin Dunbar (Dunbar’s Number) The IKEA Effect MORE ABOUT SUSAN WEINSCHENK: LinkedIn Please subscribe to the podcast in iTunes, and if you enjoyed this interview, please share with your friends and colleagues and leave a 5 star rating and review. Thanks for listening and sharing. Bruce & The Re-thinking the Human Factor Podcast Team
Welcome to Series 2, Episode 1 of the Re-Thinking the Human Factor Podcast. It's fantastic to be back after a 3-month break! As we like to do every so often, Episode 1 of Series 2 begins with a conversation with Louise Cockburn, a listener to our show whom we invited to come on and share insights she's picked up from previous episodes of the podcast, as well as her own experiences and thoughts on the challenge of security awareness, behaviour and culture. Louise is the information security awareness and culture manager at Quilter (prev. Old Mutual Wealth), and she had much to say about the need for creativity in communications, the power children hold in shaping behaviour and culture, personnel buy-in, and more, but the overarching theme of the conversation centered around one thing - behaviour. Tune in to hear all about it. Further Resources Re-thinking the Human Factor Book Our new book, Re-Thinking the Human Factor, which is available on Amazon In the nine chapters of the book, we challenge some of the assumptions that many people make when designing education and awareness programs to raise awareness, influence behaviour and foster an appropriate organizational culture. Also, we bring in a load of insights, some of which have come from the research that Bruce and his team has done over the last seven years, whilst some stem directly from the interviews that we've done in Series one of the podcast. Also, it's a short read. LinkedIn Group We have recently launched the Re-Thinking the Human Factor LinkedIn Group, where we want to enable you to continue the discussion around the human factor in information security. We hope that by having a space to hold these discussions that we can all better understand the role that awareness, behaviour, and culture can have on our information security objectives. Thanks for tuning in!
Welcome to Series 2, Episode 1 of the Re-Thinking the Human Factor Podcast. It's fantastic to be back after a 3-month break! As we like to do every so often, Episode 1 of Series 2 begins with a conversation with Louise Cockburn, a listener to our show whom we invited to come on and share insights she's picked up from previous episodes of the podcast, as well as her own experiences and thoughts on the challenge of security awareness, behaviour and culture. Louise is the information security awareness and culture manager at Quilter (prev. Old Mutual Wealth), and she had much to say about the need for creativity in communications, the power children hold in shaping behaviour and culture, personnel buy-in, and more, but the overarching theme of the conversation centered around one thing - behaviour. Tune in to hear all about it. Further Resources Re-thinking the Human Factor Book Our new book, Re-Thinking the Human Factor, which is available on Amazon In the nine chapters of the book, we challenge some of the assumptions that many people make when designing education and awareness programs to raise awareness, influence behaviour and foster an appropriate organizational culture. Also, we bring in a load of insights, some of which have come from the research that Bruce and his team has done over the last seven years, whilst some stem directly from the interviews that we've done in Series one of the podcast. Also, it's a short read. LinkedIn Group We have recently launched the Re-Thinking the Human Factor LinkedIn Group, where we want to enable you to continue the discussion around the human factor in information security. We hope that by having a space to hold these discussions that we can all better understand the role that awareness, behaviour, and culture can have on our information security objectives. Thanks for tuning in!
The challenge with creating behavioural change is doing it well enough that people actually change their behaviour consistently. And beyond that, it's about ensuring that other people in the organisation can observe this new behaviour around them so that they come to the realise this is simply "the way we do things around here" in other words, the organisational culture. When we set about creating behavioural change, the ultimate objective is for that change to become embedded in the culture, because that's when we start to see the results we're looking for. Creating Behavioural Change that Becomes Part of Culture In today's podcast episode this is what we're going to be exploring. Bruce is joined on the podcast by Su Ee Wong. Su Ee’s journey towards becoming a safety and health (S&H) professional is an unusual one. She started off in biomedical science and a serendipitous stint in the HR office of an academic institution sparked an interest in workplace safety and health. The unique blend of her science background, HR experience, and S&H interest got her a Mid-Career Training Sponsorship where she was given the opportunity to train as an S&H professional in a University. As the core businesses of a University are research and teaching, she is able to apply her knowledge in research to better manage the S&H of staff and students. Her passion is in creating a safe, healthy and happy environment that the community can thrive in. She strongly believes that the activities we engage in should do no harm to our people or to Mother Earth. [1] JOIN SU EE WONG AND BRUCE HALLAS AS THEY DISCUSS: Su Ee’s post that told of an experiment conducted around the public safety problem of how to change the behaviour of jaywalkers who were crossing the street no matter what color the light was. Making policies fun, interesting, and engaging can help catalyze behavioural change. The importance of creating policies that have as little friction as possible to follow. When we want to change behaviour, a lot of us think that should be through punishment, like handing out fines for doing something. We think if we give them a slap on the wrist, that changes behavior. But it might not be sustainable in the long run. How do we get something more creative that is more positive to change the behaviour and then reinforce it later so that this behavior sticks until it becomes second nature? In organizations, people at different levels will have different cultural norms. Though one might craft the perfect awareness campaign based on research gathered from within the various organizational levels at their local office, those same campaigns might not elicit the response one is anticipating in the overseas office possibly due to a sort of a national culture. The importance or recognizing policy “champions” for their work. How do we incorporate people’s natural biases in how we design awareness campaigns? Creating an environment and culture where people can share their insights and engage with leadership or the local champion, without blame, to create trust between workers and leaders, because that will be one of the best ways to manage problems knowing that leadership can’t be everywhere all at once. What Su Ee Wong did to understand root causes of behaviors in her organization. Awareness is just as much about policy-makers themselves becoming aware as it is about crafting the right kinds of campaigns and procedures. FURTHER STUDY AND RESEARCH Re-thinking the Human Factor Ep 09 with Dan Ariely Shortcut by John Pollock Choice Architecture Infosec Europe MORE ABOUT SU EE WONG: LinkedIn [1] Please subscribe to the podcast in iTunes, and if you enjoyed this interview, please share with your friends and colleagues and leave a 5 star rating and review. Thanks for listening and sharing. Bruce & The Re-thinking the Human Factor Podcast Team
We like to invite listeners to the podcast to come on the show and share insights that they’ve picked up from previous episodes of the podcast. We also invite them to share their own experiences and thoughts on the challenge of security awareness, behaviour and culture. In this show, Ed Tucker, the 2017 European CISO of the Year joins us to lift the lid on the challenges he sees and the insights he’s picked up. Ed feels there is a common theme between what Robert, Ciaran and Gert discuss and what happens in the reality of the organisation, which highlights the common failings of ineffective security people. The theme he highlights is ignorance. Tune in to hear all about it. About Ed Tucker Ed is the current European Chief Information Security Officer of the Year, UK Security Professional of the Year, and Security Leader of the Year and has been recognised for his massive contribution and sharing of best practice with the wider security world. Ed is the former Head of Cyber Security for the UK Tax Authority HMRC, where he led the Cyber Security and Response Capability for eight years. Ed designed and built the Cyber Security capability for HMRC, developing two intelligence driven Cyber Security Command Centres; the first in-house developed capabilities in UK Government. Ed implemented security controls across all HMRC's email domains and reduced phishing emails purporting to be the UK Tax Authority by 500 million a year 2016 through spearheading the use of DMARC (Domain-based Message Authentication, Reporting and Conformance). Ed also instigated the take down of 14,000 fraudulent websites harvesting data and has had a broad spectrum of responsibilities in his fifteen-year career including Online Fraud, Hacking Analysis & Capability Scoring and Forensic Investigations. A regular speaker at events such as InfoSec Europe, European Information Security Summit, European CISO Conference, InfoCrime Summit, and now eCrime, Ed is a highly regarded industry expert on all aspects of data protection.
EPISODE 10 SUMMARY - RACHEL LAWES ———————————————— Joining Bruce Halas on Episode 10 of the Re-thinking the Human Factor Podcast is Dr. Rachel Lawes, who comes to the show with a background in the field of semiotics. Don’t worry, if you’re not familiar with the term, you’re probably in good company. However, upon learning more about Rachel and the field of semiotics prior to recording the interview, we knew she had something of interest, substance, and worth to bring to the conversation around Cyber Security Awareness, Behaviour, and Culture. MORE ABOUT RACHEL If you go to market research conferences, [you’ve] probably met [her] already. [She’s] one of the original founders of British commercial semiotics and [she] never stops being excited about what it can do. [She] uses semiotics and related methods, backed up by a comprehensive knowledge of social science, to rejuvenate brands, innovate products and services and steer comms. [She] delivers research, insights and strategic guidance to brand owners. [She] delivers training in advanced research methods for both client side and agency side users. [She] also supplies consultancy services to ad agencies, design agencies and large branding agencies. From time to time [she] works with universities because [she] loves to teach. [1] JOIN RACHEL LAWES AND BRUCE HALLAS AS THEY DISCUSS: What semiotics is. In reference to a challenge often put our way regarding the applicability of insights from without the security industry — whether the insights gained through semiotics be applied to both sides of the fence, so to speak, both externally AND internally, as in the case of within an organization. One fascinating consequence of digital culture — that written language has taken on a life of its own in a way that really haven’t seen in our life times. It’s no longer really required that you follow the rules you learned in school. What’s more important is getting your message across, which might involve substantial use of abbreviations, emoji’s, etc. People communicate using language and text now more than they have done for a long long time.
The work of semiotics is partly about observing what’s going on in a given audience to try to understand what it is they’re giving off, what the signs are you see in the audience which may be a reflection on how they would respond to you presenting something to them. How Semiotics can help one engage more effectively and influence changes more effectively. Studying signs and symbols (semiotics) gives one an understanding of what is driving people’s behaviour from a cultural perspective. This is important because, as discussed with Gert Jan Hofstede in Episode 06 of the Re-thinking the Human Factor Podcast, culture forms everybody - there’s no escape from it. FURTHER STUDY AND RESEARCH Semiotics Tone of Voice Episode 06 - A Chat With Gert Jan Hofstede About Culture and Security. MORE ABOUT RACHEL LAWES: Website [1] Please subscribe to the podcast in iTunes, and if you enjoyed this interview, please share with your friends and colleagues and leave a 5 star rating and review. Thanks for listening and sharing. Bruce & The Re-thinking the Human Factor Podcast Team
EPISODE 09 SUMMARY - DAN ARIELY ———————————————— Dan Ariely, recently voted as the second most influential psychologist in the world, joins Bruce Hallas on Episode 09 of the Re-thinking the Human Factor Podcast. Dan’s speciality is in the study of behavioural economics with a focus on communicating his findings in a language anyone can understand. ‘[His] immersive introduction to irrationality took place many years ago while [he] was overcoming injuries sustained in an explosion. The range of treatments in the burn department, and particularly the daily “bath” made [him] face a variety of irrational behaviors that were immensely painful and persistent. Upon leaving the hospital, [he] wanted to understand how to better deliver painful and unavoidable treatments to patients, so [he] began conducting research in this area. [He] became engrossed with the idea that we repeatedly and predictably make the wrong decisions in many aspects of our lives and that research could help change some of these patterns.’ [1] “You have to understand that part of your job as a security expert is not just to create security but to create appreciation. Because if you create security with no appreciation, you’re not going to get people to value it and want to participate in it.” Join Dan Ariely and Bruce Hallas as they discuss: What behavioural economics is (10:50) Preferences, how we form them, and the effect our preferences have on our behaviour. (19:01) Untapped demand, or the idea that there’s a big difference between people’s preferences and what they end up doing, and the fact that those differences have a lot to do with friction (the easiest decision will often be the one that is chosen) (23:04) The role of behavioural economics in better designing the operating environment within which employees are trained and work within in order to maximize the potential for positive cyber security behaviours (24:56) The concept of “endowment”, or the idea that people who have contributed to something feel a greater sense of value about that something as well, and the “Ikea effect”, which simply understood is that labour leads to love (29:39) Value cues, and the need for cyber security policy creators to communicate the value of following their policies to their audience (33:59) Another big challenge in the cyber security industry - the fact that security failures happen infrequently, and what that teaches people about how they need to behave (41:36) Effective and ineffective methods for motivating positive cyber security behaviours from employees (44:30) The effect of overconfidence in our own knowledge and ability on our behaviours (49:17) “One of the biggest challenges is to get people to admit we are fallible.” FURTHER STUDY AND RESEARCH Small Change | Money Mishaps and How to Avoid Them, by Dan Ariely Predictably Irrational, by Dan Ariely Bruce Hallas’s blog: Behavioural Economics: When irrationality is the remarkably logical decision MORE ABOUT DAN ARIELY: Website [1] Please subscribe to the podcast in iTunes, and if you enjoyed this interview, please share with your friends and colleagues and leave a 5 star rating and review. Thanks for listening and sharing. Bruce & The Re-thinking the Human Factor Podcast Team
EPISODE 08 SUMMARY - BEN AFIA ———————————————— On this episode of Re-thinking the Human Factor, Ben Afia joins Bruce Hallas in a discussion around “Tone of voice”. Tone of voice deals with the brand and personality of an organization coming through in language, in words, and this personality stems from values, both personal as well as those of a broader organizational culture. Ben is a consultant, writer and speaker on brand strategy, language and change. “We’re talking about how we influence behaviour, especially within organizations with people who can choose to be influenced or not…I don’t think you actually need to be that heavy-handed to achieve the right outcome of protecting an organization.” Join Ben Afia and Bruce Hallas as they discuss: The importance of getting the tone of voice right in relation to the creation and implementation of effective policies within an organization How tone of voice can bring to life an organization’s brand (or hurt their brand) Paradoxically, though tone of voice is largely about one’s brand and organizational personality, it’s also important to understand one’s audience when building and applying tone-of-voice guidelines, because it’s also about them, and it’s about understanding what your audience will be able to actually hear Heavy-handed vs. lighter, more engaging, more human communication methods The importance of having a well-defined brand and well-defined values when coming up with tone-of-voice guidelines The need to get broad stakeholder engagement, not from the very top of the organization, but also all the way down if the goal is organization-wide change “I think that your tone of voice and your values then have to flex depending on the local circumstance.” QUESTIONS FOR FURTHER STUDY AND RESEARCH What is your tone of voice? Does it really reflect your brand? How well do people engage with that? Do your communications have any element of tone of voice or are you just getting your team to write without any direction regarding how you want to appear, to be perceived by your audience when they receive your message? MORE ABOUT BEN AFIA: Website Please subscribe to the podcast in iTunes, and if you enjoyed this interview, please share with your friends and colleagues and leave a 5 star rating and review. Thanks for listening and sharing. Bruce & The Re-thinking the Human Factor Podcast Team
EPISODE 07 SUMMARY - GEORDIE STEWART ———————————————— We’re taking a different approach to our chat in Episode 07 of the Re-thinking the Human Factor podcast. For this episode, we asked one of our listeners to come on the show and share with us the key lessons they’ve learned from the first three episodes of our show: Episode 01 - An Interview with Gregory Michaelidis, former Head Speech Writer for the Secretary of Homeland Security Episode 02 - An Interview with Heather Dahl and Chase Cunningham Episode 03 - A conversation With John Pollack, former Speechwriter to President Bill Clinton Geordie Stewart joins Bruce Hallas in a discussion we hope will help you synthesize the vast amount of information covered in those episodes. Geordie is a CISO who has worked at organisations like of John Lewis, TUI UK & Europe and has most recently taken up residence at the UK’s largest Building Society, the Nationwide. As well as his day job he is an international speaker and keen innovator in the area of technology risk communication. His award winning masters thesis at the Royal Holloway Information Security Group examined information security awareness from a fresh perspective as a marketing and communications challenge. [1] “And in a busy environment with lots of competing messages…, the challenge is, how do we make sure messages of value land in a way that somebody can use and benefit from?…because we are competing with HR, finance, and these other sources of information and guidance within companies.” Join Geordie and Bruce as they give you the hash on: The necessity of understanding your audience and empathizing with them if you hope to effectively raise awareness, influence behaviour, and foster a culture amongst that audience How a lack of feedback loops and accurate metrics has effected the speed at which the security industry has evolved in their communication and training strategies The concept of the captive audience, and how having an audience built into the organizations that security professionals serve has stifled motivation to innovate and improve upon security awareness, behaviour, and culture communication and training The role that brand plays in terms of how it influences the level of engagement you’ll get from people and whether or not people will comply with organizational policies and procedures RESOURCES AND TOPICS FOR FURTHER STUDY The Analogies Project Predictably Irrational by Dan Ariely ISC2 MORE ABOUT GEORDIE STEWART: Website [1] Please subscribe to the podcast in iTunes, and if you enjoyed this interview, please share with your friends and colleagues and leave a 5 star rating and review. Thanks for listening and sharing. Bruce & The Re-thinking the Human Factor Podcast Team
EPISODE 06 SUMMARY - GERT JAN HOFSTEDE Associate Professor at the Information Technology Group at Wageningen University & Research // Population biologist and social scientist in information management and social simulation // Interested in the interplay of the contrasting forces of cultural evolution, societal change and cultural stability ———————————————— Dr. Gert Jan Hofstede joins Bruce Hallas in Episode 6 of the Re-thinking the Human Factor podcast. Gert Jan is a population biologist and social scientist hailing from the Netherlands whose research and publications have provided many with deeper understanding in the areas of cultural evolution, societal change, cultural stability, and how those forces interact with and have influence upon one another. He is also known for his work in social simulation as well as for a number of books he has co-written with his father, Geert Hofstede. In this episode, Bruce and Gert Jan discuss a wide variety of organization and culture-related topics that have important implications for the Cyber Security industry. “It is as if you were a fish and they asked you to describe the air… If you’ve always lived in one place in the world, then it’s very hard for you to see that behaviors from another place that seem strange, illegal, ridiculous… that those behaviors can make sense, but within a larger [cultural] system.” Join Bruce and Gert Jan in this episode of Re-thinking the Human Factor as they explore: How awareness of cultural differences (or lack thereof) can be an opportunity for greater collaboration between groups, or greater friction, and how this awareness contributes to one’s ability to understand and effectively communicate cross-culturally The need for organizations to achieve a sense of mutual cultural understanding as the starting place for implementing organizational change rather than striving to achieve cultural homogenization as the means for implementing that change Different perceptions of what culture differences mean to an organization (barrier to progress, catalyst for breakthrough, etc.), and the importance of realizing that these differences do exist so that one can begin to try and understand them as a means of navigating the challenges and growth potential afforded by these differences The importance that “cultural ambassadors” within an organization be, first and foremost, acceptable to cultural audience whom they seek to address 4 helpful cultural metaphors to help with navigating cross-cultural organizational communication: The Family (Asia and Africa) The Machine (Germanic/Northern Italy type of region) The Market (Anglo-saxon, the UK and North America) The Pyramid (Mediterranean and Slavic countries)
MORE ABOUT GERT JAN HOFSTEDE, HIS BOOKS, AND HIS RESEARCH: Gertjanhofstede.com Please subscribe to the podcast in iTunes, and if you enjoyed this interview, please share with your friends and colleagues and leave a 5 star rating and review. Thanks for listening and sharing. Bruce & The Re-thinking the Human Factor Podcast Team
EPISODE 05 SUMMARY - CIARAN MCMAHON Director at Institute of Cyber Security // Research and Development Coordinator, CyberPsychology Research Centre // Ph.D., History and Philosophy of Psychology ———————————————— Award-winning academic psychologist Ciaran McMahon joins Bruce Hallas in episode 5 of Re-thinking the Human Factor. Hailing from the Republic of Ireland, Ciaran comes from a psychology background and has extensively studied how advancements in technology, throughout human history to the present day, have affected societal behaviours. He shares our belief that understanding the human side of things is necessary to effectively influence information security behaviours within an organisation, and he is eager to bring his psychological insights to the problems we face in cyber security awareness, behaviour, and culture. “It’s unlikely that we can use all of this technology and not be changed in some way…” Join Bruce and Ciaran in this episode as they explore: The impact on people’s behaviour of changes in technology and what that means for designing security environments and choices in cyber security awareness and policy implementation How people justify their behaviour and choices not to comply with security best practise including: deterrence, punishment vs reward, neutralization, the defence of necessity, and others. People’s innate understanding of right and wrong and the issue of justice and fairness in relation to security behaviours. SUBJECTS AND RESOURCES MENTIONED: ISC2 The Information Security Forum Infosec Europe Behavioural Economics Choice architecture FOR FURTHER RESEARCH: Choice Architecture Defence of Necessity MORE ABOUT CIARAN: Website Please subscribe to the podcast in iTunes, and if you enjoyed this interview, please share with your friends and colleagues and leave a 5 star rating and review. Thanks for listening and sharing. Bruce & The Re-thinking the Human Factor Podcast Team
EPISODE 04 SUMMARY - ROBERT MADELIN Chairman, Fipra International // Director General for Communications Networks, Content and Technology (CONNECT) // Director General for Health and Consumer Policy (SANCO) // A negotiator in international trade and investment, first for the UK, and then for the EU // Served in the Cabinet of European Commission Vice-President Leon Brittan. ———————————————— Robert Madelin brings a distinguished career and experience to the conversation in Episode 4 of Re-Thinking the Human Factor. Robert has been focused throughout his career on policy generation, awareness and education, and as part of that, designing policy so the odds are stacked in favor of those who comply with that policy. Join Bruce and Robert in this episode as they each draw from a well of extensive experience to converse around: Fast and slow thinking and how each influences how we behave in society The importance of integrating behavioural economics and psychology and choice-architecture when it comes to the design of EFFECTIVE education and awareness strategies and programs The “uncomfortable truth” that people do not respond rationally when given data and how recognizing that truth is key to guiding policy creation and choice architecture efforts How cultural differences in the cyber security space have more to do with digital literacy, age, principles and values rather than one’s passport, or “passport culture”, as Robert refers to it The role of culture, or the context within people live their lives, and how that may have an effect upon: A) the policy itself B) how you raise aware within institutions or even nation-states, as in Robert’s experience
The importance of international cooperation in efforts to raise awareness and influence behaviour "It's the human factor that makes us vulnerable." RESOURCES AND SUBJECTS MENTIONED: World Economic Forum: GLOBAL RISKS REPORT DG CONNECT (Communication Networks, Content, and Technology) EU Health and Food Safety (SANCO) FOR FURTHER RESEARCH: Daniel Kahneman Thinking, Fast and Slow (by Daniel Kahneman)
Behavioural Economics and Psychology Choice Architecture CONNECT WITH ROBERT: LinkedIn Please subscribe to the podcast in iTunes, and if you enjoyed this interview, please share with your friends and colleagues and leave a 5 star rating and review. Thanks for listening. Bruce & The Re-thinking the Human Factor Podcast Team
EPISODE 04 SUMMARY - ROBERT MADELIN Chairman, Fipra International // Ex European Commission Director General for Communications Networks, Content and Technology (DG CONNECT) // Ex European Commission Director General for Health and Consumer Policy (SANCO) // A negotiator in international trade and investment, for the UK, and then for the EU // Served in the Cabinet of European Commission Vice-President Leon Brittan. ———————————————— Robert Madelin brings a distinguished career and range of experience to the conversation in Episode 4 of Re-Thinking the Human Factor. Robert has been focused throughout his career on the development of public policy and embedding this across nation states. The universal challenges of awareness, behaviour and culture have been a consistent through out his career. Join Bruce and Robert in this episode as they each draw on their experience to talk about insights into the universal challenge of awareness, behaviour and culture including: Fast and slow thinking and how each influences how we behave in society The importance of integrating behavioural economics and psychology and choice-architecture when it comes to the design of EFFECTIVE education and awareness strategies and programs The “uncomfortable truth” that people do not respond rationally when given data and how recognizing that truth is key to guiding policy creation and choice architecture efforts How cultural differences in the cyber security space have more to do with digital literacy, age, principles and values rather than one’s passport, or “passport culture”, as Robert refers to it The role of culture, or the context within which people live their lives, and how that may have an effect upon: A) the policy itself B) how you raise aware within institutions or even nation-states, as in Robert’s experience
The importance of international cooperation in efforts to raise awareness and influence behaviour "It's the human factor that makes us vulnerable."
EPISODE 03 SUMMARY - JOHN POLLACK Author // Consultant // Speechwriter // Journalist // Reporter ———————————————— What is needed within cyber security industry communications to generate the kind of awareness and training materials that enable governments, businesses, and the general public to protect themselves against cyber security threats? We want people to hear our message and act in accordance with responsible security behaviours, but what changes do we as an industry need to make in order to accomplish this goal? Join Bruce and John as they converse around these questions and unpack topics such as: John was a strolling violinist at a restaurant where the head chef taught him that people eat twice, once with their eyes and once with their stomach, and that good communication relies on a combination of a sensory stimuli. Building a relationship with an audience, fostering trust, requires communicators to listen as much, if not more, than communicate.
Communication needs to come from a place of empathy and this is often missing.
The importance of authenticity and credibility in developing and delivering effective communication that supports change in behaviour. "Washington is where good words go to die" comment illustrating the impact of internal corporate communication guidelines on the effectiveness of communications designed to raise awareness and influence behaviour. “…We ought keep our eye out for ways to capture people’s attention because capturing people’s attention, and holding it, is the essence of communication…” PROJECTS AND RESOURCES MENTIONED: The Analogies Project Shortcut (by John Pollack) CONNECT WITH JOHN: Website Thank you for listening! Please subscribe to the podcast in iTunes, and if you enjoyed this interview, please share with your friends and colleagues and leave a 5 star rating and review. Thanks for listening. Bruce & The Re-thinking the Human Factor Podcast Team
EPISODE 03 SUMMARY - JOHN POLLACK Author // Consultant // Speechwriter // Journalist // Reporter ———————————————— What is needed within cyber security industry communications to generate the kind of awareness and training materials that enable governments, businesses, and the general public to protect themselves against cyber security threats? We want people to hear our message and act in accordance with responsible security behaviours, but what changes do we as an industry need to make in order to accomplish this goal? Join Bruce and John as they converse around these questions and unpack topics such as: John was a strolling violinist at a restaurant where the head chef taught him that people eat twice, once with their eyes and once with their stomach, and that good communication relies on a combination of a sensory stimuli. Building a relationship with an audience, fostering trust, requires communicators to listen as much, if not more, than communicate.
Communication needs to come from a place of empathy and this is often missing.
The importance of authenticity and credibility in developing and delivering effective communication that supports change in behaviour. “Washington is where good words go to die “ comment illustrating the impact of internal corporate communication guidelines on the effectiveness of communications designed to raise awareness and influence behaviour. “…We ought keep our eye out for ways to capture people’s attention because capturing people’s attention, and holding it, is the essence of communication…”