Perry Carpenter from KnowBe4 and Dr. Jessica Barker from Cygenta discuss human risk, relationship scams, social engineering, Phorpiex botnet distributing LockBit 3.0 ransomware, and the story of Paul Raffile getting fired from Facebook before starting. The episode covers email warnings, account security, scams targeting young men, security coaches, human-centric cybersecurity, and empowering individuals for effective cybersecurity.
Understanding the human side of cybersecurity is crucial for addressing breaches and cyber attacks.
Empathy and trust are key in promoting cybersecurity awareness and incident reporting.
Raising awareness at the board level is essential for addressing human-related cybersecurity risks.
Deep dives
The Importance of Understanding the Human Side of Cybersecurity
Understanding the human side of cybersecurity is crucial as people are targeted in cyber attacks, making up 70-90% of breaches. Historically, the focus has been more on technology, but the shift is happening towards recognizing the significance of human behavior in cybersecurity. It is essential to empower individuals, raise self-efficacy, and create a safe space for reporting incidents.
Empathy and Building Relationships in Cybersecurity
Empathy plays a key role in cybersecurity, fostering an environment where individuals can openly report incidents without fear of judgment. Building relationships and establishing trust are essential in promoting cybersecurity awareness. Providing guidance and support enables individuals to feel safe and confident in their cybersecurity practices.
Mitigating Cybersecurity Risks at the Board Level
Raising awareness about cybersecurity at the board level is critical to addressing human-related cybersecurity risks. Cultivating a just culture and emphasizing psychological safety encourage individuals to report incidents and seek support. By understanding the root causes of security incidents, organizations can enhance their resilience.
Fostering Confidence and Self-Efficacy in Cybersecurity
Promoting confidence and self-efficacy in cybersecurity practices is essential for empowering individuals to protect themselves. Building cybersecurity muscle through practice and developing a proactive response to threats enhances security. Encouraging individuals to take ownership of their cybersecurity hygiene leads to a more resilient security culture.
Educating and Encouraging Family Members in Cybersecurity Practices
Empowering family members with cybersecurity knowledge requires effective communication and an understanding of their perspectives. Encouraging open dialogue, providing practical advice, and ensuring that individuals feel supported in their cybersecurity efforts are essential. Implementing secure practices, such as password managers, and creating a safe reporting environment enhance cybersecurity awareness and readiness within families.
This week, we are joined by host of 8th Layer Insights, Perry Carpenter from KnowBe4 and Dr. Jessica Barker from Cygenta to discuss human risk: awareness, behavior and beyond. Joe and Dave share some listener follow up, the first being from Richard, who writes in to share some tips and tricks regarding relationship scams mentioned in a previous show. The second is from Michael, who writes in with some thoughts on social engineering to compromise open source projects from episode 288. Dave shares a story on researchers observing millions of daily emails from "Jenny Green," facilitated by the Phorpiex botnet, distributing LockBit 3.0 ransomware that has affected millions of people. Joe share's Paul Raffile's story, a gentleman who got fired from Facebook before he even started. Our catch of the day comes from listener Gordy who shared an email with us regarding his "McAfee security."
Please take a moment to fill out an audience survey! Let us know how we are doing!