Advances in security technology have forced cyber attackers to turn to the weakest link in the security chain the human element. With 88 percent of security breaches caused by human error, technology teams across the Federal government are searching for ways to address the human side of cybersecurity to keep networks and systems safe while also meeting Federal security mandates.
MeriTalk recently sat down with Zane Bond, director of product management at Keeper Security, to discuss how user experience plays a role in cybersecurity and can help reduce mistakes that lead to security breaches.
MeriTalk: It seems like every week we learn about another security breach on the news. How often does human behavior play a role in security breaches, and how?
Bond: The way bad actors attack agencies and organizations is constantly evolving. They will always try to find the path of least resistance. Back before there were strong network security protocols, cyber attackers would attack the network directly. So, technology teams locked systems down. Then the attackers moved to the endpoints. So those were locked down. As the easy technology target components were eliminated, attackers turned to human-centric attacks through social engineering methods like phishing. In these types of attacks, employees are tricked into either clicking on a link, opening an attachment, or sharing personal information. When the employee falls for the bait, the attackers can get into the network and do their damage. Unfortunately, in todays world, the human element is the current weak point on the security chain.
MeriTalk: There is a constant battle between technology teams that want to implement strong security protocols and end users who want an easier, better, or simpler user experience. How can agencies create a balance between the two?
Bond: Whenever possible, dont go for balance. If you make a product too complex to use through increased security protocols, users simply wont use it. They will find a workaround to get their jobs done, and that shadow IT leads to significantly increased security risks. Meanwhile, the technology team has a false sense of security because they think employees are using the security tool they implemented. Instead of finding a balance, start with focusing on the user experience technology that will make peoples lives easier. Then, find the security tools to make that happen. Many security products improve the user experience instead of adding additional barriers. With Keeper Security, we looked for user pain points in password security and access. We then built a solution that first improved their experience which meant they were more likely to use the tool and then developed the security on the back end. If you find a tool that makes peoples lives easier that just happens to be more secure you get the best of both worlds.
MeriTalk: How, in fact, can security technology create a better user experience?
Bond: When we implement security, there are mandates and compliance regulations to meet, but if you focus solely on the rules, you may create security features that make tools very difficult to use. When building or implementing any new security technology, its always a good idea to do a sanity check. Run through the security protocols yourself to understand the experience from a user perspective. If its too difficult for you to use, imagine what it will be like for your users who have to go through those protocols several times a day. Mandates, policies, and compliance regulations inform technology teams that they have to secure systems. How they do that is generally up them. If security is approached from a user perspective, technology teams will have more success in meeting the mandates and compliance requirements because their users will actually use the more secure tools.
MeriTalk: Since the release of the Biden administrations Executive Order on Improving the Nations Cybersecurity, agencies across the Federal government are quickly moving to a zero trust architecture to secure Federal systems and networks. Federal CISO Chris DeRusha reported tremendous progress to a House subcommittee. What are the greatest successes you have seen so far, and what pitfalls should technology teams be aware of as they move forward?
Bond: The order and controls around zero trust in the cyber EO really hit the mark. Its refreshing to see. The cyber EO is good for security and its really good policy. Agencies should keep in mind that zero trust is an evolution from previous security practices, which will continue to evolve as technology advances emerge and as bad actors find new ways to breach systems. Zero trust isnt a destination. Technology teams will always have to remain vigilant.
MeriTalk: Password security is a component of a zero-trust architecture. What is human-centric password security, and why is it essential securing Federal networks?
Bond: Verizon recently published its 2022 Data Breach Investigations Report, which showed that 66 percent of breaches were caused by compromised credentials, so password security is extremely important in stopping bad actors from getting into your network. A zero-trust architecture is built on the idea that people need to be authorized and validated whenever they access different areas of the network. Human-centric password security is really about ensuring the zero-trust principle of least privilege by monitoring users and their network activities and intervening before suspicious behavior escalates into a full blown breach. Through constant monitoring, technology teams can get a picture of what is normal and what is suspicious behavior. When they see something suspicious, which is usually flagged through alerts, they can contact the person to see what may be going on. Keeper Security reports on hundreds of event types across our ecosystem to support this effort.
MeriTalk: Most people look to technology teams to improve cybersecurity, but securing agency networks and data is everyones responsibility. What can government leaders do to shift user mindsets and user behaviors among their employees?
Bond: Because there have been so many high-profile breaches recently, awareness is no longer the problem it used to be. People know cyber attackers are trying to break in. Now it really comes down to identifying potential types of attacks, and then educating teams about those attack methods so they can stay vigilant. Security tools can only get you so far. You have to train people on what to look out for to reduce mistakes that lead to breaches.
MeriTalk: Along those same lines, the Biden administration issued an Executive Order on Transforming the Federal Customer Experience and Service Delivery to Rebuild Trust in Government. While primarily focused on constituent experiences, what elements in that EO can also be applied to government employees to improve their user experience? How can the spirit of the EO be met while also keeping government networks secure?
Bond: To meet the customer experience EO mandates, agencies have to understand service delivery from the customer perspective to learn how to improve it. Implementing security protocols should be handled the same way. Technology teams need to know how easy the tool is to use in practice by testing it out as a user. Understanding how the security tool affects users on a day-to-day basis is really important for the security tool to be effective.
MeriTalk: How does the Keeper Security solution reduce risks associated with the human element of cybersecurity?
Bond: Keeper Security meets stringent zero-trust security protocols on an architectural level its just built in. We address the human element of cybersecurity by making things easier for users. One of our simplest components is logging in and storing credentials. Agencies could have so many security layers that just getting through that front door with your credentials and then accessing the internet to do your job could take a long time. Employees are under deadline, and they just want to get to where they need to go quickly. With Keeper Security, the user simply goes to their vault and chooses what site they want to log into, and we do the rest. Securely stored passwords are auto-filled, making access faster and easier. The user is on their way to a more productive workday. But theres an enormous amount of security stuff that goes on under that, from validating the website, checking cross-site scripting, checking SSL certifications, checking encryption stuff that users and technology teams no longer have to worry about. Agencies can have the best of both worlds with the Keeper Security solution a security tool that improves the user experience.
MeriTalk: How does the Keeper Security platform integrate with other zero-trust security components?
Bond: Integrations are foundational to what we do. We integrate with existing security tools, including single sign-on, Active Directory, multifactor authentication, email verification, and even hardware keys so users can authenticate seamlessly. Through integrations, we are also able to enforce policies that are implemented across the entire environment, helping agencies stay compliant. We like to make things easy for users and also for the tech teams. Because we integrate with tools teams already have in place, there arent a lot of new things to learn. Our integrations also mean that implementation is fast. From a deployment perspective, if an agency has an account, employees literally go to the website, click sign up, and they are done. Team members could be up and running in five minutes. You dont have to install appliances or get special approvals.
MeriTalk: What makes the Keeper Security platform different than other solutions on the market?
Keeper Security is the only password manager that is FedRAMP authorized, making it really simple for agencies across the Federal government to implement. We are Americans with Disabilities Act 508 compliant, so people with disabilities can access their files with screen readers. Beyond that, we include zero knowledge in our zero-trust architecture, which I think will eventually be a recommendation or policy from CISA. With zero knowledge, we as the vendor have no knowledge of what is inside a users vault. We dont know what passwords are stored in there, and we dont know where users are logging in from. If we are ever compromised, user data remains secure. Adding zero knowledge to the zero-trust architecture is really on the forefront of current security thinking. Finally, Keeper Security solutions are just easy to use and easy to deploy.
Here is the original post:
Improving the User Experience to Address the Human Element of Cybersecurity - MeriTalk
- The Smell Of Death Has A Strange Influence On Human Behavior - IFLScience - October 26th, 2024 [October 26th, 2024]
- "WEIRD" in psychology literature oversimplifies the global diversity of human behavior. - Psychology Today - October 2nd, 2024 [October 2nd, 2024]
- Scientists issue warning about increasingly alarming whale behavior due to human activity - Orcasonian - September 23rd, 2024 [September 23rd, 2024]
- Does AI adoption call for a change in human behavior? - Fast Company - July 26th, 2024 [July 26th, 2024]
- Dogs can smell human stress and it alters their own behavior, study reveals - New York Post - July 26th, 2024 [July 26th, 2024]
- Trajectories of brain and behaviour development in the womb, at birth and through infancy - Nature.com - June 18th, 2024 [June 18th, 2024]
- AI model predicts human behavior from our poor decision-making - Big Think - June 18th, 2024 [June 18th, 2024]
- ZkSync defends Sybil measures as Binance offers own ZK token airdrop - TradingView - June 18th, 2024 [June 18th, 2024]
- On TikTok, Goldendoodles Are People Trapped in Dog Bodies - The New York Times - June 18th, 2024 [June 18th, 2024]
- 10 things only introverts find irritating, according to psychology - Hack Spirit - June 18th, 2024 [June 18th, 2024]
- 32 animals that act weirdly human sometimes - Livescience.com - May 24th, 2024 [May 24th, 2024]
- NBC Is Using Animals To Push The LGBT Agenda. Here Are 5 Abhorrent Animal Behaviors Humans Shouldn't Emulate - The Daily Wire - May 24th, 2024 [May 24th, 2024]
- New study examines the dynamics of adaptive autonomy in human volition and behavior - PsyPost - May 24th, 2024 [May 24th, 2024]
- 30000 years of history reveals that hard times boost human societies' resilience - Livescience.com - May 12th, 2024 [May 12th, 2024]
- Kingdom of the Planet of the Apes Actors Had Trouble Reverting Back to Human - CBR - May 12th, 2024 [May 12th, 2024]
- The need to feel safe is a core driver of human behavior. - Psychology Today - April 15th, 2024 [April 15th, 2024]
- AI learned how to sway humans by watching a cooperative cooking game - Science News Magazine - March 29th, 2024 [March 29th, 2024]
- We can't combat climate change without changing minds. This psychology class explores how. - Northeastern University - March 11th, 2024 [March 11th, 2024]
- Bees Reveal a Human-Like Collective Intelligence We Never Knew Existed - ScienceAlert - March 11th, 2024 [March 11th, 2024]
- Franciscan AI expert warns of technology becoming a 'pseudo-religion' - Detroit Catholic - March 11th, 2024 [March 11th, 2024]
- Freshwater resources at risk thanks to human behavior - messenger-inquirer - March 11th, 2024 [March 11th, 2024]
- Astrocytes Play Critical Role in Regulating Behavior - Neuroscience News - March 11th, 2024 [March 11th, 2024]
- Freshwater resources at risk thanks to human behavior - Sunnyside Sun - March 11th, 2024 [March 11th, 2024]
- Freshwater resources at risk thanks to human behavior - Blue Mountain Eagle - March 11th, 2024 [March 11th, 2024]
- 7 Books on Human Behavior - Times Now - March 11th, 2024 [March 11th, 2024]
- Euphemisms increasingly used to soften behavior that would be questionable in direct language - Norfolk Daily News - February 29th, 2024 [February 29th, 2024]
- Linking environmental influences, genetic research to address concerns of genetic determinism of human behavior - Phys.org - February 29th, 2024 [February 29th, 2024]
- Emerson's Insight: Navigating the Three Fundamental Desires of Human Nature - The Good Men Project - February 29th, 2024 [February 29th, 2024]
- Dogs can recognize a bad person and there's science to prove it. - GOOD - February 29th, 2024 [February 29th, 2024]
- What Is Organizational Behavior? Everything You Need To Know - MarketWatch - February 4th, 2024 [February 4th, 2024]
- Overcoming 'Otherness' in Scientific Research Commentary in Nature Human Behavior USA - English - USA - PR Newswire - February 4th, 2024 [February 4th, 2024]
- "Reichman University's behavioral economics program: Navigating human be - The Jerusalem Post - January 19th, 2024 [January 19th, 2024]
- Of trees, symbols of humankind, on Tu BShevat - The Jewish Star - January 19th, 2024 [January 19th, 2024]
- Tapping Into The Power Of Positive Psychology With Acclaimed Expert Niyc Pidgeon - GirlTalkHQ - January 19th, 2024 [January 19th, 2024]
- Don't just make resolutions, 'be the architect of your future self,' says Stanford-trained human behavior expert - CNBC - December 31st, 2023 [December 31st, 2023]
- Never happy? Humans tend to imagine how life could be better : Short Wave - NPR - December 31st, 2023 [December 31st, 2023]
- People who feel unhappy but hide it well usually exhibit these 9 behaviors - Hack Spirit - December 31st, 2023 [December 31st, 2023]
- If you display these 9 behaviors, you're being passive aggressive without realizing it - Hack Spirit - December 31st, 2023 [December 31st, 2023]
- Men who are relationship-oriented by nature usually display these 9 behaviors - Hack Spirit - December 31st, 2023 [December 31st, 2023]
- A look at the curious 'winter break' behavior of ChatGPT-4 - ReadWrite - December 14th, 2023 [December 14th, 2023]
- Neuroscience and Behavior Major (B.S.) | College of Liberal Arts - UNH's College of Liberal Arts - December 14th, 2023 [December 14th, 2023]
- The positive health effects of prosocial behaviors | News | Harvard ... - HSPH News - October 27th, 2023 [October 27th, 2023]
- The valuable link between succession planning and skills - Human Resource Executive - October 27th, 2023 [October 27th, 2023]
- Okinawa's ants show reduced seasonal behavior in areas with more human development - Phys.org - October 27th, 2023 [October 27th, 2023]
- How humans use their sense of smell to find their way | Penn Today - Penn Today - October 27th, 2023 [October 27th, 2023]
- Wrestling With Evil in the World, or Is It Something Else? - Psychiatric Times - October 27th, 2023 [October 27th, 2023]
- Shimmying like electric fish is a universal movement across species - Earth.com - October 27th, 2023 [October 27th, 2023]
- Why do dogs get the zoomies? - Care.com - October 27th, 2023 [October 27th, 2023]
- How Stuart Robinson's misconduct went overlooked for years - Washington Square News - October 27th, 2023 [October 27th, 2023]
- Whatchamacolumn: Homeless camps back in the news - News-Register - October 27th, 2023 [October 27th, 2023]
- Stunted Growth in Infants Reshapes Brain Function and Cognitive ... - Neuroscience News - October 27th, 2023 [October 27th, 2023]
- Social medias role in modeling human behavior, societies - kuwaittimes - October 27th, 2023 [October 27th, 2023]
- The gift of reformation - Living Lutheran - October 27th, 2023 [October 27th, 2023]
- After pandemic, birds are surprisingly becoming less fearful of humans - Study Finds - October 27th, 2023 [October 27th, 2023]
- Nick Treglia: The trouble with fairness and the search for truth - 1819 News - October 27th, 2023 [October 27th, 2023]
- Science has an answer for why people still wave on Zoom - Press Herald - October 27th, 2023 [October 27th, 2023]
- Orcas are learning terrifying new behaviors. Are they getting smarter? - Livescience.com - October 27th, 2023 [October 27th, 2023]
- Augmenting the Regulatory Worker: Are We Making Them Better or ... - BioSpace - October 27th, 2023 [October 27th, 2023]
- What "The Creator", a film about the future, tells us about the present - InCyber - October 27th, 2023 [October 27th, 2023]
- WashU Expert: Some parasites turn hosts into 'zombies' - The ... - Washington University in St. Louis - October 27th, 2023 [October 27th, 2023]
- Is secondhand smoke from vapes less toxic than from traditional ... - Missouri S&T News and Research - October 27th, 2023 [October 27th, 2023]
- How apocalyptic cults use psychological tricks to brainwash their ... - Big Think - October 27th, 2023 [October 27th, 2023]
- Human action pushing the world closer to environmental tipping ... - Morung Express - October 27th, 2023 [October 27th, 2023]
- What We Get When We Give | Harvard Medicine Magazine - Harvard University - October 27th, 2023 [October 27th, 2023]
- Psychological Anime: 12 Series You Should Watch - But Why Tho? - October 27th, 2023 [October 27th, 2023]
- Roosters May Recognize Their Reflections in Mirrors, Study Suggests - Smithsonian Magazine - October 27th, 2023 [October 27th, 2023]
- June 30 Zodiac: Sign, Traits, Compatibility and More - AZ Animals - May 13th, 2023 [May 13th, 2023]
- Indiana's Funding Ban for Kinsey Sex-Research Institute Threatens ... - The Chronicle of Higher Education - May 13th, 2023 [May 13th, 2023]
- Have AI Chatbots Developed Theory of Mind? What We Do and Do ... - The New York Times - March 31st, 2023 [March 31st, 2023]
- Scoop: Coming Up on a New Episode of HOUSEBROKEN on FOX ... - Broadway World - March 31st, 2023 [March 31st, 2023]
- Here's five fall 2023 classes to fire up your bookbag - Duke Chronicle - March 31st, 2023 [March 31st, 2023]
- McDonald: Aspen's like living in a 'Pullman town' - The Aspen Times - March 31st, 2023 [March 31st, 2023]
- Children Who Are Exposed to Awe-Inspiring Art Are More Likely to Become Generous, Empathic Adults, a New Study Says - artnet News - March 31st, 2023 [March 31st, 2023]
- DataDome Raises Another $42M to Prevent Bot Attacks in Real ... - AlleyWatch - March 31st, 2023 [March 31st, 2023]
- Observing group-living animals with drones may help us understand ... - Innovation Origins - March 31st, 2023 [March 31st, 2023]
- Mann named director of School of Public and Population Health - Boise State University - March 31st, 2023 [March 31st, 2023]
- Irina Solomonova's bad behavior is the star of Love Is Blind - My Imperfect Life - March 31st, 2023 [March 31st, 2023]
- Health quotes Dill in article about rise of Babesiosis - UMaine News ... - University of Maine - March 31st, 2023 [March 31st, 2023]
- There's still time for the planet, Goodall says, if we stay hopeful - University of Wisconsin-Madison - March 31st, 2023 [March 31st, 2023]
- Relationship between chronotypes and aggression in adolescents ... - BMC Psychiatry - March 31st, 2023 [March 31st, 2023]