Before I say something about my talk, let me first start with the US Consulate itself. This was a very nice and new experience for me, especially from a Security perspective because it has airport-tight Security levels. First of all, I needed to get a personal invite the Commercial Specialist of the US Commercial Service of the consulate itself (besides the invite by ION-IP and WhiteHat Security). No invite from the consulate itself means no access. For obvious reasons I had to show my passport (driver’s license was also possible) and had to turn over all my electronic devices.
|US Consulate in Amsterdam - Source: Wikipedia|
My talk was about Security Awareness and why we should stop it, or at least have the ambition to make it obsolete. This is obviously a statement to make the audience think about the value of Security Awareness and when and when not to invest in it. When looking to the organization I work for I see that the most value comes from Security Awareness on the level where change is done. Whether it is IT, HR or the Legal department, everywhere there can be made a change there can be made a difference. Obviously the Security Awareness in every department is for the most part completely different.
I ended with my talk with an advice that Security Awareness for IT departments should focus on automation. The more you automate, the more predictable and agile you will become. And when you are agile, you can even become anti-fragile. Every time an IT-department consider training users on Security, we should first ask ourselves if we can make our technology better. If not, then we need to question if we can make our policies, procedures and baselines better. And then, and only then, we can start training users. Because leaning on awareness for security, is leaning on the weakest link in the chain of security, the humans.
And again, for Security Awareness in general, focus it at the places where changes are done in order to really make a difference!
If you want to read more about my point-of-view concerning awareness, read these posts of mine.
If you have questions or want to debate or challenge my point-of-view! Please do so! Sharing opinions is creating knowledge and knowledge leads to wisdom! So feel free to comment below.