SlideShare a Scribd company logo
1
Using Behavioral Science
To Secure Your Organization
Masha Sedova
Masha@ElevateSecurity.com
Co-founder, Elevate Security
2
Built and ran
Salesforce trust
engagement team
Passionate about
transforming security
behaviors from “have to”
to “want to”
Co-Founder, building
security behavior
change platform
About Me
Computer security
meets behavioral
science
3
Opinion A: Users Are Dumb
...and will always make mistakes
4
Opinion B: It’s Us, Not Them
“People are the weakest link in
security is a comfortable excuse
to lean on when it should be a
rallying cry to change the status
quo.”
Jessie Irwin, security researcher
5
Historically, the industry
solution has been to insist on
terrible “check the box”
trainings as an employee’s only
defense.
Training Alone Doesn’t Work
15%
Retention
95%
of breaches are
caused by human
factors.
6
Knowing
Isn’t
Enough
7
8
Behavioral Science + Security =
How humans make
(security) decisions
and how security folks
can help.
9
What are your
key behaviors?
10
What Does Security Awareness
Mean To Your Organization?
Make less security
mistakesEmbed security into
everything they do
Have more
security common
sense
Be more vigilant
11
Set Behavior Goals, Not Mindset Goals
Reduction of bugs in
our code base by 30%
over the next quarter.
90% of new process
created by the finance
team have a security
control in place.
Phishing click-through
rates drop by 50%
Reporting rate
increases by 300% in 6
months
12
Behavior
Change
Components
▪ Motivation
▪ Ability
▪ Triggers
13
Behavior Change Model
By Dr. Bj Fogg
14
Ability
15
Behavior Change Model
By Dr. Bj Fogg
16
Security Action Can Be Simplified
Having secure
passwords for all sites
Reporting suspicious
activity
Stop tailgating
Remember 20 unique
characters across 40+ sites
Install a password
manager
Look up correct email,
reporting guidelines &
send
Install a “Report” button
Social Accountability
Install a man-trap or
in/out badging
HARD
EASY
17
Education
Theory:
Improves understanding
of a concept and
therefore increases the
ability to perform that
behavior.
Practice:
Not all education is
created equal.
“In theory there is no
difference between
theory and practice.
In practice there is.”
-Yogi Berra
18
Education Pitfalls
Demand more of your
trainings!
1. Does it have the
intended goal?
2. Relevant and
needed?
3. Timely?
19
Motivation
20
What about things that are hard to do?
By Dr. Bj Fogg
21
When Does Motivation Occur?
Hard things
require high
motivation.
22
Naturally Occurring Motivation
MOTIVATION
TIME
EVENT
MOTIVATION
TIME
EVENT
Predictable Events Unpredictable Events
▪ Audits
▪ Red Team exercises
▪ Breaches
▪ Incidents
▪ News events
23
Good leaders
seizes crises to
remake
organizational
habits.
Charles Duhigg,
The Power Of Habit
24
What Motivates Us?
“People will do things
because they matter,
they are interesting, part
of something more
important. “
Daniel Pink, Drive
Pride
Interest
Achievement
Curiosity
Praise
Punishment
Money
25
5:1Positive to Negative
exchanges
Positive vs Negative Motivation
26
Competition
How to Create Positive Motivation
Altruism Access AchievementStatus
27
Competition
How to Create Positive Motivation: Status
Altruism Access AchievementStatus
Leaderboards
Top performer award
28
Competition
Capture the Flag
Bug Bounties
How to Create Positive Motivation: Competition
Altruism Access AchievementStatus
29
Competition
How to Create Positive Motivation: Altruism
Altruism
Feedback on impact
Champion Programs
Access AchievementStatus
30
Competition
How to Create Positive Motivation: Access
Altruism Access
Awarded points
Access to exclusive swag
AchievementStatus
31
Competition
How to Create Positive Motivation: Achievement
Altruism Access Achievement
Recognition emails
Company-wide shoutouts
Status
32
33
Market Norms
Assigning a monetary value to an exchange
Social Norms
The actions among friends that are not
based on money.
Dan Ariely, PhD
Predictably Irrational
34
Triggers
35
Communications (aka Triggers)
36.5 million adults in the United States currently smoke cigarettes
36
Security Triggers
37
Putting It All
Together
38
Lessons Learned in Changing
Tailgating Behavior
Goal:
To ensure that people wore their badges visibly at all
times while in secured spaces and not allow unbadged
person tailgate behind them.
Assumption:
People didn’t know that this was policy.
Bring “awareness” to them via digital posters
● Passive education
● Very limited results
39
Lessons Learned in Changing
Tailgating Behavior
Root cause analysis of the behavior.
This is what we learned:
○ “I don’t feel comfortable confronting
my peers.”
(Ability + Motivation)
○ “Tailgating isn’t really a big problem,
right?”
(Motivation)
○ “I broke my badge pull reel and don’t
have a replacement, so I keep my
badge in my wallet.”
(Ability)
40
Creating a Phishing & Reporting
Behavior Change Campaign
Goal #1: Reducing the percentage of malicious links that are clicked in
a phishing email campaign to be 12% or less as an average across all
difficulty types of phishing email.
Goal #2: At least 20% of recipients of an attack report it to security,
regardless of the difficulty of the attack.
41
Phishing Campaign Model
● Case studies of phishing related
breaches
● Leaderboard of top reporters
● Thank you emails to employee +
managers
● Kudos of breach-prevention on
company call.
● Reporter button
● Safe sender
● Detection skills
● Phishing practice
42
Takeaways
■ Motivation is required when
something is hard to do.
■ First- make it easy with technology.
Second- rely on motivation.
■ Leverage naturally occurring
events for motivation.
■ Connect intrinsic motivations to
security motivation.
■ Negative feedback should be
balanced with positive motivation.
■ Use triggers in the moment they
are needed.
43
Comments?
Questions?
Let’s stay in touch!
@modMasha
Masha@elevatesecurity.com

More Related Content

What's hot (19)

PPTX
Change, transformation and improvement: where's it going and what's love got ...
Helen Bevan
 
PDF
#1NLab15: Being the Dave Matthews Band, Not Dave Matthews
One North
 
PPT
Leadership In The 21st Century2
Margarita Quihuis
 
PDF
How to incorporate psychology into your comms strategy | Psychology of commu...
CharityComms
 
PPTX
Skills & Mindsets for the future
Catalyst Consulting South Africa
 
PPTX
Breaking down hierarchical barriers
Helen Bevan
 
PPT
HIMSS Workshop - Emotional Intelligence, The Key to Leadership, Success and C...
HIMSS
 
PPTX
Patient advisors as change agents
Marlies van Dijk
 
PPTX
World at Work Total Rewards 2017 presentation - lantern group - behavioral sc...
Kurt Nelson, PhD
 
PPT
New Lens on Change in Healthcare
Marlies van Dijk
 
PDF
Graeme Cowan's Speakers Kit - Personal and Team Resilience
Graeme Cowan Enterprises
 
PPTX
Leaders as change agents
Marlies van Dijk
 
PPTX
“Where social movements meets co-design”
NHS Horizons
 
PPTX
Summitup - Powerful beyond imagination
David Bowman
 
PPTX
AQuA Leading Transformational Change programme: masterclass with Helen Bevan
NHS Improving Quality
 
PPTX
8 capabilities for the future
Catalyst Consulting South Africa
 
PPTX
The 21st Century Movement - Charlie Kim and Meghan Messenger
Next Jump
 
PDF
Creating psychological safety in the workplace a. edmondson
Didoy Fullon
 
PPTX
How to be a brilliant change agent
Helen Bevan
 
Change, transformation and improvement: where's it going and what's love got ...
Helen Bevan
 
#1NLab15: Being the Dave Matthews Band, Not Dave Matthews
One North
 
Leadership In The 21st Century2
Margarita Quihuis
 
How to incorporate psychology into your comms strategy | Psychology of commu...
CharityComms
 
Skills & Mindsets for the future
Catalyst Consulting South Africa
 
Breaking down hierarchical barriers
Helen Bevan
 
HIMSS Workshop - Emotional Intelligence, The Key to Leadership, Success and C...
HIMSS
 
Patient advisors as change agents
Marlies van Dijk
 
World at Work Total Rewards 2017 presentation - lantern group - behavioral sc...
Kurt Nelson, PhD
 
New Lens on Change in Healthcare
Marlies van Dijk
 
Graeme Cowan's Speakers Kit - Personal and Team Resilience
Graeme Cowan Enterprises
 
Leaders as change agents
Marlies van Dijk
 
“Where social movements meets co-design”
NHS Horizons
 
Summitup - Powerful beyond imagination
David Bowman
 
AQuA Leading Transformational Change programme: masterclass with Helen Bevan
NHS Improving Quality
 
8 capabilities for the future
Catalyst Consulting South Africa
 
The 21st Century Movement - Charlie Kim and Meghan Messenger
Next Jump
 
Creating psychological safety in the workplace a. edmondson
Didoy Fullon
 
How to be a brilliant change agent
Helen Bevan
 

Similar to Using Behavioral Science to Secure Your Organization (20)

PPTX
Carrots not sticks- Using Gamification to Transform Security Mindset of an Or...
Salesforce Engineering
 
PPTX
171212_find_your_passion
Ryosuke Ishii
 
PDF
DAMA Webinar: Influencing with Data – Facts Don’t Matter Much!
DATAVERSITY
 
PPTX
Designing Learning Solutions for Results (Cammy Bean & Ashley Reardon) #DevLearn
Cammy Bean
 
PDF
Safety Journey to Human_and_Organizational_Performance_(HOP)-Presentacion-32 ...
JOSE_ROSAS1810
 
PDF
ALEX Con 2015 -- Jellyvision
Stephen Wendel
 
PPTX
How to improve employee performance orlando fpa
The Renaissance Group
 
PPTX
Employee performance enhancement by tasvir a r chowdhury
Tasvir A R Chowdhury
 
PPTX
Reverse Engineering the Wetware: Understanding Human Behavior to Improve Info...
Alexandre Sieira
 
PPTX
Reverse Engineering the Wetware: Understanding Human Behavior to Improve Info...
Matt Hathaway
 
PPTX
Training for Results Webinar 2016
KineoPacific
 
PPT
Behaviour
doyourbest
 
PPT
Behavior Based Safety
Surendra Marchande
 
PDF
Agile Network India | Psychological safety for teams in VUCA world | Abhinav ...
AgileNetwork
 
PPT
Business & Psychology Principles applied to Security Mgt.
Richard Garrity
 
PDF
C4O Leadership Briefs Improved Behavioral Skills = Improved Corporate Perfo...
Center for Organizational Success, Inc. (C4OS)
 
PDF
Design for Behavior Change
Julie Dirksen
 
PDF
10 Tips to Overcome the Training Usage Dip | Webinar 01.08.15
BizLibrary
 
PDF
Фишинг — проклятие или возможность для ИБ?
Positive Hack Days
 
PDF
Awareness is only the first step
Hewlett Packard Enterprise Business Value Exchange
 
Carrots not sticks- Using Gamification to Transform Security Mindset of an Or...
Salesforce Engineering
 
171212_find_your_passion
Ryosuke Ishii
 
DAMA Webinar: Influencing with Data – Facts Don’t Matter Much!
DATAVERSITY
 
Designing Learning Solutions for Results (Cammy Bean & Ashley Reardon) #DevLearn
Cammy Bean
 
Safety Journey to Human_and_Organizational_Performance_(HOP)-Presentacion-32 ...
JOSE_ROSAS1810
 
ALEX Con 2015 -- Jellyvision
Stephen Wendel
 
How to improve employee performance orlando fpa
The Renaissance Group
 
Employee performance enhancement by tasvir a r chowdhury
Tasvir A R Chowdhury
 
Reverse Engineering the Wetware: Understanding Human Behavior to Improve Info...
Alexandre Sieira
 
Reverse Engineering the Wetware: Understanding Human Behavior to Improve Info...
Matt Hathaway
 
Training for Results Webinar 2016
KineoPacific
 
Behaviour
doyourbest
 
Behavior Based Safety
Surendra Marchande
 
Agile Network India | Psychological safety for teams in VUCA world | Abhinav ...
AgileNetwork
 
Business & Psychology Principles applied to Security Mgt.
Richard Garrity
 
C4O Leadership Briefs Improved Behavioral Skills = Improved Corporate Perfo...
Center for Organizational Success, Inc. (C4OS)
 
Design for Behavior Change
Julie Dirksen
 
10 Tips to Overcome the Training Usage Dip | Webinar 01.08.15
BizLibrary
 
Фишинг — проклятие или возможность для ИБ?
Positive Hack Days
 
Awareness is only the first step
Hewlett Packard Enterprise Business Value Exchange
 
Ad

Recently uploaded (20)

PDF
SFWelly Summer 25 Release Highlights July 2025
Anna Loughnan Colquhoun
 
PDF
Persuasive AI: risks and opportunities in the age of digital debate
Speck&Tech
 
PPTX
✨Unleashing Collaboration: Salesforce Channels & Community Power in Patna!✨
SanjeetMishra29
 
PDF
SWEBOK Guide and Software Services Engineering Education
Hironori Washizaki
 
PPTX
WooCommerce Workshop: Bring Your Laptop
Laura Hartwig
 
PDF
Complete Network Protection with Real-Time Security
L4RGINDIA
 
PDF
HCIP-Data Center Facility Deployment V2.0 Training Material (Without Remarks ...
mcastillo49
 
PDF
Wojciech Ciemski for Top Cyber News MAGAZINE. June 2025
Dr. Ludmila Morozova-Buss
 
PDF
Transcript: New from BookNet Canada for 2025: BNC BiblioShare - Tech Forum 2025
BookNet Canada
 
PDF
Why Orbit Edge Tech is a Top Next JS Development Company in 2025
mahendraalaska08
 
PDF
Complete JavaScript Notes: From Basics to Advanced Concepts.pdf
haydendavispro
 
PDF
DevBcn - Building 10x Organizations Using Modern Productivity Metrics
Justin Reock
 
PDF
NewMind AI Journal - Weekly Chronicles - July'25 Week II
NewMind AI
 
PDF
Building Real-Time Digital Twins with IBM Maximo & ArcGIS Indoors
Safe Software
 
PDF
Windsurf Meetup Ottawa 2025-07-12 - Planning Mode at Reliza.pdf
Pavel Shukhman
 
PDF
HubSpot Main Hub: A Unified Growth Platform
Jaswinder Singh
 
PDF
Smart Air Quality Monitoring with Serrax AQM190 LITE
SERRAX TECHNOLOGIES LLP
 
PDF
Achieving Consistent and Reliable AI Code Generation - Medusa AI
medusaaico
 
PPTX
Building a Production-Ready Barts Health Secure Data Environment Tooling, Acc...
Barts Health
 
PDF
New from BookNet Canada for 2025: BNC BiblioShare - Tech Forum 2025
BookNet Canada
 
SFWelly Summer 25 Release Highlights July 2025
Anna Loughnan Colquhoun
 
Persuasive AI: risks and opportunities in the age of digital debate
Speck&Tech
 
✨Unleashing Collaboration: Salesforce Channels & Community Power in Patna!✨
SanjeetMishra29
 
SWEBOK Guide and Software Services Engineering Education
Hironori Washizaki
 
WooCommerce Workshop: Bring Your Laptop
Laura Hartwig
 
Complete Network Protection with Real-Time Security
L4RGINDIA
 
HCIP-Data Center Facility Deployment V2.0 Training Material (Without Remarks ...
mcastillo49
 
Wojciech Ciemski for Top Cyber News MAGAZINE. June 2025
Dr. Ludmila Morozova-Buss
 
Transcript: New from BookNet Canada for 2025: BNC BiblioShare - Tech Forum 2025
BookNet Canada
 
Why Orbit Edge Tech is a Top Next JS Development Company in 2025
mahendraalaska08
 
Complete JavaScript Notes: From Basics to Advanced Concepts.pdf
haydendavispro
 
DevBcn - Building 10x Organizations Using Modern Productivity Metrics
Justin Reock
 
NewMind AI Journal - Weekly Chronicles - July'25 Week II
NewMind AI
 
Building Real-Time Digital Twins with IBM Maximo & ArcGIS Indoors
Safe Software
 
Windsurf Meetup Ottawa 2025-07-12 - Planning Mode at Reliza.pdf
Pavel Shukhman
 
HubSpot Main Hub: A Unified Growth Platform
Jaswinder Singh
 
Smart Air Quality Monitoring with Serrax AQM190 LITE
SERRAX TECHNOLOGIES LLP
 
Achieving Consistent and Reliable AI Code Generation - Medusa AI
medusaaico
 
Building a Production-Ready Barts Health Secure Data Environment Tooling, Acc...
Barts Health
 
New from BookNet Canada for 2025: BNC BiblioShare - Tech Forum 2025
BookNet Canada
 
Ad

Using Behavioral Science to Secure Your Organization