SlideShare a Scribd company logo
1 of 38
Download to read offline
SESSION ID:
#RSAC
Bikash Barai
Using Behavioral Psychology and
Science of Habit to Change User
Behavior
HUM-F03
Co-founder (Cigital India)
@bikashbarai1
#RSAC
Is Awareness Enough To Change
Human Behavior?
2
#RSAC
3
Credit: Abd Allah Foteih
#RSAC
Awareness vs Change Of Behavior
4
Example: Continued security training beyond the baseline are unlikely to be effective -
“Modifying Smartphone User Locking Behavior” – by Dirk et al (ACM – 2013)
Awareness
ChangeinBehavior
#RSAC
What Else Do We Need?
5
#RSAC
The Mystery of Eugene Pauly’s Brain ..
6
Dr. Lary R. Squire
University of California, San Diego
Image Source: http://whoville.ucsd.edu/about.html
#RSAC
Goal Directed System (Pre-Frontal Cortex)
Responsible for new or infrequent
behaviors
Guided by attitudes, goals, values,
knowledge
Conscious and deliberate
Slow
Habit System (Basal Ganglia)
Very fast. Does not require thought or
attention
Less conscious. More automatic
Goal Directed and Habit System
7
Credit: Neal et al – The Science of Habit…
#RSAC
40% of our daily actions are driven without thinking
Examples of Habits in action
Changing gears
Getting out of elevator in wrong floor
Tying Shoe knots
Bad habits in action
Checking phone/blackberry during the middle of sleep
Clicking phishing links
Writing down passwords in open
Habits in Action..
8
#RSAC
How To Build A New Habit?
9
#RSAC
Story of Pepsodent ..
10
https://upload.wikimedia.org/wikipedia/en/8/88/Pepsodent-0179c.jpg
#RSAC
Trigger – Routine – Reward ( & Craving )
11
Trigger:
Feel Tooth Film with
tongue
Routine:
Brushing Teeth
Reward:
Great Smile
Crave for
Tingling
Image Credit: Seth LemmonsImage Credit: Wikipediahttps://i.ytimg.com/vi/rf1Bs2XpwFI/maxresdefault.jpg
#RSAC
Step 1: Find a Predictable and Recurring Trigger
Step 2: Devise the new Routine/Habit
Step 3: Find the Reward
Practice, Practice, Practice without exceptions
Steps for Building New Habits
12
#RSAC
How To Change A Habit?
13
#RSAC
14
Old Habits
Never Die
#RSAC
Example – Changing A Habit
15
Trigger:
Boredom
Routine:
Have a Whisky
Reward:
Feel Happy
Image Credit: Wiki
#RSAC
Example – Changing A Habit
16
Trigger:
Boredom
New Routine:
Talk to a friend
Reward:
Feel Happy
Image Credit: Wiki
#RSAC
3 Steps for Changing Old Habits
Identify and Deconstruct the Habit
Find the Trigger
Find the “real hidden reward” – Experiment to discover
Find the Trigger-Routine-Reward-Craving model
Find an alternative routine to satisfy the “real hidden reward”
Practice. Practice. Practice.
#RSAC
“Hard Thing” about “Easy Things”..
18
#RSAC
Understanding Buffer Overflow - Easy
19
Finding A vulnerability - Hard
Writing A “Reliable” Exploit- Very Hard
#RSAC
Coke, McDonalds campaigns..
What is hard about it?
Finding a “Reliable” trigger and reward
Creating craving and making it stick
Hard or Easy?
20
#RSAC
Applying The Science Of Habit
21
In Information Security & Life..
#RSAC
Example 1: Create Habit of Locking Computer
Screen..
Goal: Locking system while leaving desk
Trigger – Getting up from chair/Leaving the system
Routine – Lock your computer
Reward – Feeling of security
Rehearse or Repeat at least 20 times
If you forget then go back to seat and repeat the routine
#RSAC
Example 2: Change the Habit of Writing Down
Password in Open Areas
Goal: Stop the habit of writing down password areas
Trigger – New password setting request
Old Routine – write down the password
New Routine – “write down the clue” or “Use a Scheme to generate new
passwords”
Reward – Feeling of security
Rehearse or Repeat
#RSAC
Example 3: Preventing Phishing
Old Habit
Trigger: Legitimate entity asks for personal details
Routine: Share the details
New Desired Habit
Trigger: Legitimate entity asks for personal details
New Routine: Validate the legitimacy of the entity
Practice. Practice. Practice
24
#RSAC
Example 4: Create Secure Coding Behavior
Goal – Ensuring coders use secure coding functions
Trigger – Typing a function
Old Routine – Type insecure function
New Routine – Use intervention method to prompt secure function
Enough practice
Automatic use of secure function
#RSAC
Habits in Day to Day Life..
Playing/Exercise everyday
Controlling anger outbursts..
#RSAC
Driving organizational change
27
#RSAC
7 Learning for Driving Organizational Change
Augment Awareness with a Habit Strategy
Utilize “Keystone Habit”
Certainty of negative incentive and not Severity has high impact
Group sharing has positive impact
Reduce friction or Create friction based on goals
Leverage a disaster
Start with a why
#RSAC
Current State of Research
29
#RSAC
Research on Habits and Beyond..
Research on Habits
Significant studies in the field of psychology, marketing, sports etc
Little or No research in areas related to IT security
30
#RSAC
References and Other Studies ..
Balleine et al – Goal directed instrumental action: contingency and incentive learning and their cortical
substrates
Kahneman – Thinking fast and slow
Duhigg- The power of habit
Neal et al – The pull of the past when do habits persist despite conflict with motives?
Rothman et al- Reflective and automotive processes in the initiation and maintenance of dietary change
Sheeran et al – Implementation intentions and repeated behavior..
Wood et al – A new look at habits and habit- goal interface
Wood et al- The habitual consumer
Wood et al- Habits in everyday life: thought emotion and action
31
#RSAC
Apply What You Learned..
32
#RSAC
Apply What You Learned
Next Week
Choose 1 habit that you want to change or build
Identify a small group for experiment
Experiment
First 3 months
Find the most important habits to change in your organization
Create an organization wide plan for habit change drills
Make people practice at least 20 to 30 times in a short time frame. (Group
activities, Simulation exercise, Wargames etc)
Measure the success of the program
#RSAC
After 6 months
Assess the success of the program based on the metrics defined
Reassess the risky and secure behavior and create a new program
34
#RSAC
Awareness Is Not Enough
35
Invest In Forming Lasting Habits
#RSAC
Practice Does Not Make Perfect
36
“Perfect Practice” Makes Perfect
#RSAC
Want To Engineer A Habit?
37
Let’s Meet At The Bar ..
#RSAC
Questions please..
bbarai@cigital.com
@bikashbarai1
38
Bikash Barai

More Related Content

Viewers also liked

Seven Habits of Highly Effective People
Seven Habits of Highly Effective PeopleSeven Habits of Highly Effective People
Seven Habits of Highly Effective People
Tania Aslam
 

Viewers also liked (8)

20 Habits of Happy People
20 Habits of Happy People20 Habits of Happy People
20 Habits of Happy People
 
3 Simple Habits of a Highly Effective Team
3 Simple Habits of a Highly Effective Team 3 Simple Habits of a Highly Effective Team
3 Simple Habits of a Highly Effective Team
 
Simple Weight Loss Tips - Secrets and Strategies of Losing and Maintaining We...
Simple Weight Loss Tips - Secrets and Strategies of Losing and Maintaining We...Simple Weight Loss Tips - Secrets and Strategies of Losing and Maintaining We...
Simple Weight Loss Tips - Secrets and Strategies of Losing and Maintaining We...
 
Seven Habits of Highly Effective Digital Marketers - Tops Tips for 2015!
Seven Habits of Highly Effective Digital Marketers - Tops Tips for 2015!Seven Habits of Highly Effective Digital Marketers - Tops Tips for 2015!
Seven Habits of Highly Effective Digital Marketers - Tops Tips for 2015!
 
How should we measure habit? (And does it matter?)
How should we measure habit? (And does it matter?)How should we measure habit? (And does it matter?)
How should we measure habit? (And does it matter?)
 
Seven Habits of Highly Effective People
Seven Habits of Highly Effective PeopleSeven Habits of Highly Effective People
Seven Habits of Highly Effective People
 
7 habits of highly effective people by stephen r. covey
7 habits of highly effective people by stephen r. covey7 habits of highly effective people by stephen r. covey
7 habits of highly effective people by stephen r. covey
 
Habits at Work - Merci Victoria Grace, Growth, Slack - 2016 Habit Summit
Habits at Work - Merci Victoria Grace, Growth, Slack - 2016 Habit SummitHabits at Work - Merci Victoria Grace, Growth, Slack - 2016 Habit Summit
Habits at Work - Merci Victoria Grace, Growth, Slack - 2016 Habit Summit
 

Similar to Using Behavioral Psychology and Science of Habit to Change User Behavior

Requirement_and_Discovery_JUNE_2011
Requirement_and_Discovery_JUNE_2011Requirement_and_Discovery_JUNE_2011
Requirement_and_Discovery_JUNE_2011
uchitha bandara
 
ORGB 300-005Organizational BehaviorLeBow College of Business.docx
ORGB 300-005Organizational BehaviorLeBow College of Business.docxORGB 300-005Organizational BehaviorLeBow College of Business.docx
ORGB 300-005Organizational BehaviorLeBow College of Business.docx
gerardkortney
 
Unit_-_3_Org._Dcn._making_in_changing_env_.pdf
Unit_-_3_Org._Dcn._making_in_changing_env_.pdfUnit_-_3_Org._Dcn._making_in_changing_env_.pdf
Unit_-_3_Org._Dcn._making_in_changing_env_.pdf
sandhyashakya13
 
Baworld adapting to whats happening
Baworld adapting to whats happeningBaworld adapting to whats happening
Baworld adapting to whats happening
Dave Davis PMP, PgMP, PBA
 

Similar to Using Behavioral Psychology and Science of Habit to Change User Behavior (20)

Keynote Session : Using Behavioral Psychology and Science of Habit to Change ...
Keynote Session : Using Behavioral Psychology and Science of Habit to Change ...Keynote Session : Using Behavioral Psychology and Science of Habit to Change ...
Keynote Session : Using Behavioral Psychology and Science of Habit to Change ...
 
From Human Intelligence to Machine Intelligence
From Human Intelligence to Machine IntelligenceFrom Human Intelligence to Machine Intelligence
From Human Intelligence to Machine Intelligence
 
Qualitative Research Session with Piyul Mukherjee & Pia Mollback Verbic
Qualitative Research Session with Piyul Mukherjee & Pia Mollback VerbicQualitative Research Session with Piyul Mukherjee & Pia Mollback Verbic
Qualitative Research Session with Piyul Mukherjee & Pia Mollback Verbic
 
Requirement_and_Discovery_JUNE_2011
Requirement_and_Discovery_JUNE_2011Requirement_and_Discovery_JUNE_2011
Requirement_and_Discovery_JUNE_2011
 
Add creativity to your decision process
Add creativity to your decision processAdd creativity to your decision process
Add creativity to your decision process
 
How to build a superstar self-organizing team?
How to build a superstar self-organizing team?How to build a superstar self-organizing team?
How to build a superstar self-organizing team?
 
Unit 1.pptx
Unit 1.pptxUnit 1.pptx
Unit 1.pptx
 
People, brain and change in the Manifesto for Agile Software Development
People, brain and change in the Manifesto for Agile Software DevelopmentPeople, brain and change in the Manifesto for Agile Software Development
People, brain and change in the Manifesto for Agile Software Development
 
ORGB 300-005Organizational BehaviorLeBow College of Business.docx
ORGB 300-005Organizational BehaviorLeBow College of Business.docxORGB 300-005Organizational BehaviorLeBow College of Business.docx
ORGB 300-005Organizational BehaviorLeBow College of Business.docx
 
3 classification
3  classification3  classification
3 classification
 
APF orlando diy survey workshop 071114 final
APF orlando diy survey workshop 071114 finalAPF orlando diy survey workshop 071114 final
APF orlando diy survey workshop 071114 final
 
Shaping Tomorrow - Getting Started - Introduction
Shaping Tomorrow - Getting Started - IntroductionShaping Tomorrow - Getting Started - Introduction
Shaping Tomorrow - Getting Started - Introduction
 
Using Problem Solving Skills To Get A Job
Using Problem Solving Skills To Get A JobUsing Problem Solving Skills To Get A Job
Using Problem Solving Skills To Get A Job
 
DTI-Module 4.pptx
DTI-Module 4.pptxDTI-Module 4.pptx
DTI-Module 4.pptx
 
Ch14
Ch14Ch14
Ch14
 
Instructional Design Today: What We Really Need to Know as Practitioners, Res...
Instructional Design Today: What We Really Need to Know as Practitioners, Res...Instructional Design Today: What We Really Need to Know as Practitioners, Res...
Instructional Design Today: What We Really Need to Know as Practitioners, Res...
 
Unit_-_3_Org._Dcn._making_in_changing_env_.pdf
Unit_-_3_Org._Dcn._making_in_changing_env_.pdfUnit_-_3_Org._Dcn._making_in_changing_env_.pdf
Unit_-_3_Org._Dcn._making_in_changing_env_.pdf
 
Baworld adapting to whats happening
Baworld adapting to whats happeningBaworld adapting to whats happening
Baworld adapting to whats happening
 
Seven Habits For Highly Successful Use Of Organization
Seven Habits For Highly Successful Use Of OrganizationSeven Habits For Highly Successful Use Of Organization
Seven Habits For Highly Successful Use Of Organization
 
Kanban India 2022 | Badre Srinivasan | Culture Hack# - Decision Filters
Kanban India 2022 | Badre Srinivasan | Culture Hack# - Decision FiltersKanban India 2022 | Badre Srinivasan | Culture Hack# - Decision Filters
Kanban India 2022 | Badre Srinivasan | Culture Hack# - Decision Filters
 

More from Priyanka Aash

More from Priyanka Aash (20)

Digital Personal Data Protection (DPDP) Practical Approach For CISOs
Digital Personal Data Protection (DPDP) Practical Approach For CISOsDigital Personal Data Protection (DPDP) Practical Approach For CISOs
Digital Personal Data Protection (DPDP) Practical Approach For CISOs
 
Verizon Breach Investigation Report (VBIR).pdf
Verizon Breach Investigation Report (VBIR).pdfVerizon Breach Investigation Report (VBIR).pdf
Verizon Breach Investigation Report (VBIR).pdf
 
Top 10 Security Risks .pptx.pdf
Top 10 Security Risks .pptx.pdfTop 10 Security Risks .pptx.pdf
Top 10 Security Risks .pptx.pdf
 
Simplifying data privacy and protection.pdf
Simplifying data privacy and protection.pdfSimplifying data privacy and protection.pdf
Simplifying data privacy and protection.pdf
 
Generative AI and Security (1).pptx.pdf
Generative AI and Security (1).pptx.pdfGenerative AI and Security (1).pptx.pdf
Generative AI and Security (1).pptx.pdf
 
EVERY ATTACK INVOLVES EXPLOITATION OF A WEAKNESS.pdf
EVERY ATTACK INVOLVES EXPLOITATION OF A WEAKNESS.pdfEVERY ATTACK INVOLVES EXPLOITATION OF A WEAKNESS.pdf
EVERY ATTACK INVOLVES EXPLOITATION OF A WEAKNESS.pdf
 
DPDP Act 2023.pdf
DPDP Act 2023.pdfDPDP Act 2023.pdf
DPDP Act 2023.pdf
 
Cyber Truths_Are you Prepared version 1.1.pptx.pdf
Cyber Truths_Are you Prepared version 1.1.pptx.pdfCyber Truths_Are you Prepared version 1.1.pptx.pdf
Cyber Truths_Are you Prepared version 1.1.pptx.pdf
 
Cyber Crisis Management.pdf
Cyber Crisis Management.pdfCyber Crisis Management.pdf
Cyber Crisis Management.pdf
 
CISOPlatform journey.pptx.pdf
CISOPlatform journey.pptx.pdfCISOPlatform journey.pptx.pdf
CISOPlatform journey.pptx.pdf
 
Chennai Chapter.pptx.pdf
Chennai Chapter.pptx.pdfChennai Chapter.pptx.pdf
Chennai Chapter.pptx.pdf
 
Cloud attack vectors_Moshe.pdf
Cloud attack vectors_Moshe.pdfCloud attack vectors_Moshe.pdf
Cloud attack vectors_Moshe.pdf
 
Stories From The Web 3 Battlefield
Stories From The Web 3 BattlefieldStories From The Web 3 Battlefield
Stories From The Web 3 Battlefield
 
Lessons Learned From Ransomware Attacks
Lessons Learned From Ransomware AttacksLessons Learned From Ransomware Attacks
Lessons Learned From Ransomware Attacks
 
Emerging New Threats And Top CISO Priorities In 2022 (Chennai)
Emerging New Threats And Top CISO Priorities In 2022 (Chennai)Emerging New Threats And Top CISO Priorities In 2022 (Chennai)
Emerging New Threats And Top CISO Priorities In 2022 (Chennai)
 
Emerging New Threats And Top CISO Priorities In 2022 (Mumbai)
Emerging New Threats And Top CISO Priorities In 2022 (Mumbai)Emerging New Threats And Top CISO Priorities In 2022 (Mumbai)
Emerging New Threats And Top CISO Priorities In 2022 (Mumbai)
 
Emerging New Threats And Top CISO Priorities in 2022 (Bangalore)
Emerging New Threats And Top CISO Priorities in 2022 (Bangalore)Emerging New Threats And Top CISO Priorities in 2022 (Bangalore)
Emerging New Threats And Top CISO Priorities in 2022 (Bangalore)
 
Cloud Security: Limitations of Cloud Security Groups and Flow Logs
Cloud Security: Limitations of Cloud Security Groups and Flow LogsCloud Security: Limitations of Cloud Security Groups and Flow Logs
Cloud Security: Limitations of Cloud Security Groups and Flow Logs
 
Cyber Security Governance
Cyber Security GovernanceCyber Security Governance
Cyber Security Governance
 
Ethical Hacking
Ethical HackingEthical Hacking
Ethical Hacking
 

Recently uploaded

Recently uploaded (20)

Introduction to Multilingual Retrieval Augmented Generation (RAG)
Introduction to Multilingual Retrieval Augmented Generation (RAG)Introduction to Multilingual Retrieval Augmented Generation (RAG)
Introduction to Multilingual Retrieval Augmented Generation (RAG)
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Less Is More: Utilizing Ballerina to Architect a Cloud Data Platform
Less Is More: Utilizing Ballerina to Architect a Cloud Data PlatformLess Is More: Utilizing Ballerina to Architect a Cloud Data Platform
Less Is More: Utilizing Ballerina to Architect a Cloud Data Platform
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
 
Quantum Leap in Next-Generation Computing
Quantum Leap in Next-Generation ComputingQuantum Leap in Next-Generation Computing
Quantum Leap in Next-Generation Computing
 
AI in Action: Real World Use Cases by Anitaraj
AI in Action: Real World Use Cases by AnitarajAI in Action: Real World Use Cases by Anitaraj
AI in Action: Real World Use Cases by Anitaraj
 
Choreo: Empowering the Future of Enterprise Software Engineering
Choreo: Empowering the Future of Enterprise Software EngineeringChoreo: Empowering the Future of Enterprise Software Engineering
Choreo: Empowering the Future of Enterprise Software Engineering
 
JohnPollard-hybrid-app-RailsConf2024.pptx
JohnPollard-hybrid-app-RailsConf2024.pptxJohnPollard-hybrid-app-RailsConf2024.pptx
JohnPollard-hybrid-app-RailsConf2024.pptx
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelMcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
 
Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​
 
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfRising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
 
Six Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal OntologySix Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal Ontology
 
Modernizing Legacy Systems Using Ballerina
Modernizing Legacy Systems Using BallerinaModernizing Legacy Systems Using Ballerina
Modernizing Legacy Systems Using Ballerina
 
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
 
Decarbonising Commercial Real Estate: The Role of Operational Performance
Decarbonising Commercial Real Estate: The Role of Operational PerformanceDecarbonising Commercial Real Estate: The Role of Operational Performance
Decarbonising Commercial Real Estate: The Role of Operational Performance
 

Using Behavioral Psychology and Science of Habit to Change User Behavior

  • 1. SESSION ID: #RSAC Bikash Barai Using Behavioral Psychology and Science of Habit to Change User Behavior HUM-F03 Co-founder (Cigital India) @bikashbarai1
  • 2. #RSAC Is Awareness Enough To Change Human Behavior? 2
  • 4. #RSAC Awareness vs Change Of Behavior 4 Example: Continued security training beyond the baseline are unlikely to be effective - “Modifying Smartphone User Locking Behavior” – by Dirk et al (ACM – 2013) Awareness ChangeinBehavior
  • 5. #RSAC What Else Do We Need? 5
  • 6. #RSAC The Mystery of Eugene Pauly’s Brain .. 6 Dr. Lary R. Squire University of California, San Diego Image Source: http://whoville.ucsd.edu/about.html
  • 7. #RSAC Goal Directed System (Pre-Frontal Cortex) Responsible for new or infrequent behaviors Guided by attitudes, goals, values, knowledge Conscious and deliberate Slow Habit System (Basal Ganglia) Very fast. Does not require thought or attention Less conscious. More automatic Goal Directed and Habit System 7 Credit: Neal et al – The Science of Habit…
  • 8. #RSAC 40% of our daily actions are driven without thinking Examples of Habits in action Changing gears Getting out of elevator in wrong floor Tying Shoe knots Bad habits in action Checking phone/blackberry during the middle of sleep Clicking phishing links Writing down passwords in open Habits in Action.. 8
  • 9. #RSAC How To Build A New Habit? 9
  • 10. #RSAC Story of Pepsodent .. 10 https://upload.wikimedia.org/wikipedia/en/8/88/Pepsodent-0179c.jpg
  • 11. #RSAC Trigger – Routine – Reward ( & Craving ) 11 Trigger: Feel Tooth Film with tongue Routine: Brushing Teeth Reward: Great Smile Crave for Tingling Image Credit: Seth LemmonsImage Credit: Wikipediahttps://i.ytimg.com/vi/rf1Bs2XpwFI/maxresdefault.jpg
  • 12. #RSAC Step 1: Find a Predictable and Recurring Trigger Step 2: Devise the new Routine/Habit Step 3: Find the Reward Practice, Practice, Practice without exceptions Steps for Building New Habits 12
  • 13. #RSAC How To Change A Habit? 13
  • 15. #RSAC Example – Changing A Habit 15 Trigger: Boredom Routine: Have a Whisky Reward: Feel Happy Image Credit: Wiki
  • 16. #RSAC Example – Changing A Habit 16 Trigger: Boredom New Routine: Talk to a friend Reward: Feel Happy Image Credit: Wiki
  • 17. #RSAC 3 Steps for Changing Old Habits Identify and Deconstruct the Habit Find the Trigger Find the “real hidden reward” – Experiment to discover Find the Trigger-Routine-Reward-Craving model Find an alternative routine to satisfy the “real hidden reward” Practice. Practice. Practice.
  • 18. #RSAC “Hard Thing” about “Easy Things”.. 18
  • 19. #RSAC Understanding Buffer Overflow - Easy 19 Finding A vulnerability - Hard Writing A “Reliable” Exploit- Very Hard
  • 20. #RSAC Coke, McDonalds campaigns.. What is hard about it? Finding a “Reliable” trigger and reward Creating craving and making it stick Hard or Easy? 20
  • 21. #RSAC Applying The Science Of Habit 21 In Information Security & Life..
  • 22. #RSAC Example 1: Create Habit of Locking Computer Screen.. Goal: Locking system while leaving desk Trigger – Getting up from chair/Leaving the system Routine – Lock your computer Reward – Feeling of security Rehearse or Repeat at least 20 times If you forget then go back to seat and repeat the routine
  • 23. #RSAC Example 2: Change the Habit of Writing Down Password in Open Areas Goal: Stop the habit of writing down password areas Trigger – New password setting request Old Routine – write down the password New Routine – “write down the clue” or “Use a Scheme to generate new passwords” Reward – Feeling of security Rehearse or Repeat
  • 24. #RSAC Example 3: Preventing Phishing Old Habit Trigger: Legitimate entity asks for personal details Routine: Share the details New Desired Habit Trigger: Legitimate entity asks for personal details New Routine: Validate the legitimacy of the entity Practice. Practice. Practice 24
  • 25. #RSAC Example 4: Create Secure Coding Behavior Goal – Ensuring coders use secure coding functions Trigger – Typing a function Old Routine – Type insecure function New Routine – Use intervention method to prompt secure function Enough practice Automatic use of secure function
  • 26. #RSAC Habits in Day to Day Life.. Playing/Exercise everyday Controlling anger outbursts..
  • 28. #RSAC 7 Learning for Driving Organizational Change Augment Awareness with a Habit Strategy Utilize “Keystone Habit” Certainty of negative incentive and not Severity has high impact Group sharing has positive impact Reduce friction or Create friction based on goals Leverage a disaster Start with a why
  • 29. #RSAC Current State of Research 29
  • 30. #RSAC Research on Habits and Beyond.. Research on Habits Significant studies in the field of psychology, marketing, sports etc Little or No research in areas related to IT security 30
  • 31. #RSAC References and Other Studies .. Balleine et al – Goal directed instrumental action: contingency and incentive learning and their cortical substrates Kahneman – Thinking fast and slow Duhigg- The power of habit Neal et al – The pull of the past when do habits persist despite conflict with motives? Rothman et al- Reflective and automotive processes in the initiation and maintenance of dietary change Sheeran et al – Implementation intentions and repeated behavior.. Wood et al – A new look at habits and habit- goal interface Wood et al- The habitual consumer Wood et al- Habits in everyday life: thought emotion and action 31
  • 32. #RSAC Apply What You Learned.. 32
  • 33. #RSAC Apply What You Learned Next Week Choose 1 habit that you want to change or build Identify a small group for experiment Experiment First 3 months Find the most important habits to change in your organization Create an organization wide plan for habit change drills Make people practice at least 20 to 30 times in a short time frame. (Group activities, Simulation exercise, Wargames etc) Measure the success of the program
  • 34. #RSAC After 6 months Assess the success of the program based on the metrics defined Reassess the risky and secure behavior and create a new program 34
  • 35. #RSAC Awareness Is Not Enough 35 Invest In Forming Lasting Habits
  • 36. #RSAC Practice Does Not Make Perfect 36 “Perfect Practice” Makes Perfect
  • 37. #RSAC Want To Engineer A Habit? 37 Let’s Meet At The Bar ..