Rushing Is Insecure

A White Throated Kingfisher with a catch (50955948472)I recently did not take enough time to do something as securely as I should have. I was annoyed with myself when I realized that, not least because I realize that this is a pattern with me and one that I need to break.

When the stakes are lower and time is shorter I sometimes rush to get a task off of my list, an email out of my inbox or a colleague off of my back. And the more I think about it the more I think that rushing is insecure.

It is tempted to copy that file, email that file or hand off that file just to be done with it. It is probably fine.

But I know, deep down, that consistency and care are vital to security. I know that it almost never makes sense to compromise just this once. (This is also a theme of a recent post of Ted's.)

I offer this an answer to the question "what does Pythia Cyber mean by the 'behavioral element of cybersecurity?'" This is an example of human behavior being a critical part of cybersecurity. Cybersecurity is more than a protocol or a procedure because not every action at work is covered by a protocol or a procedure. Sometimes people--annoying people, senior people, people you can't ignore--pressure you to do something a little insecure in the interests of expediency. In that case you need more than protocol or procedure, you need commitment and culture. You need the psychological safety to refuse, or to do it the slower, more annoying and safer way.

Cybersecurity is risk management. Risk management requires trade-offs between safety and utility. Not often but still too often I am tempted to mistake convenience or social pressure for utility. I suspect that everyone has equivalent blind spots. This is what we mean by the behavioral element of cybersecurity. If you have people then you have behavior. If you have behavior then you have the possibility of sub-optimal behavior. Policy and procedure is sometimes not enough. Add behavioral awareness. Ask us how.

Comments