SlideShare a Scribd company logo
1 of 51
How to Incorporate “Psyber Resilience”
into Your Security Strategy
Neal O’Farrell, Founder, The PsyberResilience Project
40 years in global security
and privacy
50 years struggling with
mental illness
30 years struggling with
chronic stress and
eventually burnout
Now focused on mental
health and wellness
Leading the
creation of a
mental health
action cluster to
create standards
for mental health
in future smart
cities
Free mental
health
education
portals for
every city
and county
in America
Jack Daniel,
founder of
B/Sides, speakin
about mental
health concerns
in security in
2012.
Personal Risks
• Mental health – depression, anxiety, worry, anger,
cynicism, despair, suicide
• Physical health – blood pressure, digestive, weight
gain, immune system
• Substance abuse
• Passion for the career
• Relationships
• Seek other employment
• Quit the industry
• Absenteeism and “Presenteeism”
Organizational Risks
Unmanaged stress is known to harm
• Cognitive function
• Attention and focus
• Decision making
• Memory
• Engagement
• You’ll lose your best and brightest!
Adversaries recognize security stress as a
significant vulnerability and opportunity
A DOZEN MAJOR CAUSES OF PSYBER STRESS
1
Unrealistic Expectations
“Unrealistic and unhealthy
expectations about outcomes
and results, expectations set
both by employers and by the
individual defenders.”
2
No Time To Regroup
Little time to pause or
decompress because of the
relentless waves of attacks,
constant training, vendors,
regulations etc.
A DOZEN MAJOR CAUSES OF PSYBER STRESS
2
Simmering Frustrations
Understaffing, insufficient
budgets, employees who
continue to undo and
undermine security efforts,
and a leadership not taking
the threats seriously enough.
A DOZEN MAJOR CAUSES OF PSYBER STRESS
2
Exhausting Schedules
“Always being on the clock, on
the job, at least mentally,
compounded by no real
downtime, long hours, long
weeks, and even long
weekends.”
A DOZEN MAJOR CAUSES OF PSYBER STRESS
2
Change Fatigue
“Trying to keep up with a
constantly changing
environment, from new
threats, tactics, and
technologies, to new laws,
regulations, guidelines,
frameworks, and standards”
A DOZEN MAJOR CAUSES OF PSYBER STRESS
2
Professional Pride
“The constant fear of personal
failure, of being the one who
lets the team and organization
down by missing that one
single threat amongst
thousands”
A DOZEN MAJOR CAUSES OF PSYBER STRESS
2
A Cruel Enemy
“The emotional toll of
constantly fighting and being
exposed to the worst kinds of
criminals, and witnessing the
cruelty they inflict on their
victims”
A DOZEN MAJOR CAUSES OF PSYBER STRESS
2
Growing Cynicism
“An increase in cynicism and a
decrease in trust amongst
security professionals, often
permanent emotional
changes that they bring home
with them”
A DOZEN MAJOR CAUSES OF PSYBER STRESS
2
Not Enough Eyes
“Security teams stretched too
thinly, which results in heavier
workloads, pressure to take
on too many tasks, and not
being allowed to focus on the
most critical or relevant
challenges”
A DOZEN MAJOR CAUSES OF PSYBER STRESS
2
Pre-Existing Conditions
“Many security professionals
come into the industry with
existing mental health issues,
and especially with an
increase in military and law
enforcement dealing with
anxiety and PTSD”
A DOZEN MAJOR CAUSES OF PSYBER STRESS
2
The Exploitation of Stress
“A growing strategy by
attackers to psychologically
wear out the defenders, and
often taunting, threatening,
and even directly targeting
security professionals”
A DOZEN MAJOR CAUSES OF PSYBER STRESS
2
Vendors
Tools
Vendors
Tools
Vendors
Tools
A DOZEN MAJOR CAUSES OF PSYBER STRESS
UNDERSTANDINGStress Stress is little more than the way we process “stressors,”
how our brains process the stressful things around us.
If we can better understand how stress works and how
to manage stressors, we can almost eliminate the impact
of stress.
In other words, it’s all literally in our own
minds.
And it’s often a self-inflicted wound.
But -
If we fail to manage stress, it can severely
harm our health and quality of life.
Stress and Cortisol
A QUICK PRIMER
Cortisol is an essential part of the body’s core
defense system, the “fight or flight” response.
In order not to become toxic, it recedes to
normal levels after the danger has passed.
When Cortisol remains constantly elevated it
becomes toxic:
• Heart and pulmonary
• Digestive
• Immune system
• Cognitive function
• Sleep
• Dementia/Alzheimer’s
• Reproductive
So what keeps Cortisol at toxic elevated levels? STRESS!
“A state of physical or emotional exhaustion
that also involves a sense of reduced
accomplishment and loss of personal
identity.” The Mayo Clinic
Burnout impacts nearly half of all workers, and researchers
at Stanford found that workplace stress costs businesses
nearly $200 billion annually and leads to nearly 120,000
deaths each year.
So where does it come from?
Chronic burnout is usually the end result of years of
unchecked and unmanaged chronic stress.
UNDERSTANDING
Burnout
• Constantly cynical or critical at work
• Having trouble getting up and getting
started
• Irritable or impatient with co-workers,
customers or clients
• Lack the energy to be consistently
productive, or “presenteeism”
• Find it hard to concentrate, focus, engage,
make decisions
SPOTTING THE SIGNS
Of Burnout
• Lack of satisfaction from achievements
• Feeling disillusioned about the job and
mission
• Using food, drugs, or alcohol to feel better
- or to simply not feel
• Changes in sleeping habits
• Unexplained headaches, stomach or bowel
problems, or other physical complaints
SPOTTING THE SIGNS
Of Burnout
A WORD OF CAUTION!
Symptoms of burnout can often mimic those of serious mental
health issues like depression.
The most important rule of all?
“Recognize that it’s all in your
head. Literally”
Which means you have enormous
control.
Manage it like a threat
Create a list of all the “things” – the
stressors – that are causing your
stress.
Address them individually
“There is no stress in security!”
Understand the difference between
“stressors” and “stress.”
They’re not the same and the difference
is crucial
Apply the BAD system:
Bucketize
And
DAM
Personal Stressors
Work
Stressors
Self
Imposed
Stressors
Healthissues
Relationships
Family drama
Financial
worries
Self image
Purpose
Future
Chaos
Schedule/Hours
Work overload
Resources
Your boss
Your
Training
Fear of failure
Fear of being fired
Disillusionment
Co-workers
Certifications
Compliance
and cynicism
Exhaustion
Highstandards
Intolerant
Perfectionist
”I will not
be the
Taking it too
personally
weak link”
Competitive
Impatient
Taking it home
Mindfulness is proven to be one of the most
powerful stress management tools.
Exercise and fresh air
A better social life/social network
Better eating habits
Teach yourself to be happier
Practice gratitude
Laugh and smile more
Kitty videos are scientifically “great”
Learn To Be A Brain Alchemist
Understand how cortisol, serotonin, and
dopamine work, how they interact with each
other, and how to control them through your
thoughts and actions.
DAM
Dismiss – Not real or
really worth worrying
about.
Accept – Real but you can
deal with them.
Manage – Real,
potentially harmful, and
need to be managed.
CISO, Heal Thyself
Chances are you’re dealing with the same issues,
maybe worse, probably for longer.
Go through your own self-assessment first, identify
the most destructive stressors.
Use what you learn to (a) start healing yourself and
(b) inspire your security team.
Note to self – Your biggest stressors might
come from above, management and board.
So the strategy might be different.
Learn
The differences and the relationships between
stress, burnout, and mental illness:
• Chronic stress = unmanaged long-term stress
• Burnout = unmanaged chronic stress
• Unmanaged stress can become depression
• Or – burnout is unrecognized depression
Caution – you’re in the realm of mental
illness. Always seek professional advice
Know Your Team
“My guys are all OK. I know they’ll tell me if
they’re struggling”
No they won’t. It’s rarely the case.
Spend as much personal time with your team, all of
them. And not isolated.
Talk about these issues all the time. That’s the best
way to build the trust that will free the truth.
Talk to them separately and privately too. It’s a
delicate subject.
Note to self – Your biggest stressors might
come from above, management and board.
So the strategy might be different.
Study The Stressors
The more you understand about what’s stressing
your security team, the easier it will be to manage or
neutralize them. Remember BAD?
Recognize that you might be one or the greatest
sources of stress.
If the pressures on your team are coming from above
you, let them know that, that it’s not because of
your indifference.
Survey your team on stressors.
Mental health is not unlike security. Use the “shared struggle”
to encourage more understanding and empathy
Let Them Speak
Create an anonymous way for your security team to:
• Vent
• Criticize
• Point fingers
• Suggest
A powerful way to gather the most honest and
useful insights
Make sure it’s truly anonymous or you risk additional risks
If you can’t fix...
...at least speak openly about:
• Why you don’t have enough manpower
• Why you don’t have other critical resources
• Why you’re just as frustrated with management
as they are
• Why you’re constantly putting out fires
• Why you’re just as frustrated with vendors, tools
and technologies, compliance, endless new
regulations and frameworks, relentless training,
too many distractions
Give them a break
Work/life balance is critically important in
managing stress and mental health:
• More time off – come in later, leave earlier, longer
breaks, longer weekends
• More downtime with the team
• Longer/more frequent vacations
• “Off” also means off the clock and off the job
• Allow for/encourage more remote work
One Rotten Apple
Toxic/Rockstar personalities can make an entire
workplace toxic:
• The know-all, expert of all experts
• Condescending, arrogant, dismissive, controlling,
attention seeking
• Bullying is increasingly commonplace
• One single toxic personality can cripple an entire
team
• Try to cure rather than amputate
Recognize that toxic behavior might just be poor
coping skills or unaddressed issues
Beyond Stress
The security industry has long attracted those
already struggling with mental illnesses:
• 1 in 5 Americans struggle with mental illness, and
often more than one
• Anxiety and depression are the most common
• Anxiety and depression also come in many
varieties
• Bipolar and Schizophrenia are growing
• PTSD very common amongst transitions from
military and law enforcement
Learn the differences, recognize the signs, know how to approach,
embrace, support, and champion
Create An Escape Room
A comfortable
and nearby
place to escape,
decompress,
disengage,
refresh, vent,
and start all
over
Contact Neal O’Farrell
nealjofarrell@gmail.com
@nealofarrell
https://www.linkedin.com/in/nealofarrell/
Contact i-Sight
j.gerard@i-sight.com
Find more free webinars:
http://www.i-sight.com/resources/webinars
@isightsoftware

More Related Content

What's hot

What's hot (20)

Unconscious Bias: Managing Impacts On The Recruitment Process
Unconscious Bias: Managing Impacts On The Recruitment ProcessUnconscious Bias: Managing Impacts On The Recruitment Process
Unconscious Bias: Managing Impacts On The Recruitment Process
 
Introduction to unconscious bias
Introduction to unconscious biasIntroduction to unconscious bias
Introduction to unconscious bias
 
Insider Threat: Cases and Controls to Prevent Internal Fraud and Prevention
Insider Threat: Cases and Controls to Prevent Internal Fraud and PreventionInsider Threat: Cases and Controls to Prevent Internal Fraud and Prevention
Insider Threat: Cases and Controls to Prevent Internal Fraud and Prevention
 
Implicit Bias Training
Implicit Bias TrainingImplicit Bias Training
Implicit Bias Training
 
Bullying at work place
Bullying at work placeBullying at work place
Bullying at work place
 
Workplace Bullying - What, Why and Who?
Workplace Bullying - What, Why and Who? Workplace Bullying - What, Why and Who?
Workplace Bullying - What, Why and Who?
 
Workplace Bullying
Workplace BullyingWorkplace Bullying
Workplace Bullying
 
Workplace bullying
Workplace bullyingWorkplace bullying
Workplace bullying
 
Unconscious bias webinar presentation
Unconscious bias webinar presentationUnconscious bias webinar presentation
Unconscious bias webinar presentation
 
Workplace Bullying Webinar
Workplace Bullying WebinarWorkplace Bullying Webinar
Workplace Bullying Webinar
 
Workplace Bullying & Harassment Ultimate Training Resource
Workplace Bullying & Harassment Ultimate Training ResourceWorkplace Bullying & Harassment Ultimate Training Resource
Workplace Bullying & Harassment Ultimate Training Resource
 
How to Help Managers Counter Unconscious Bias at Work
How to Help Managers Counter Unconscious Bias at WorkHow to Help Managers Counter Unconscious Bias at Work
How to Help Managers Counter Unconscious Bias at Work
 
Workplace Bullying
Workplace BullyingWorkplace Bullying
Workplace Bullying
 
Bullying in the Irish Workplace-How to Deal with Bullying
Bullying in the Irish Workplace-How to Deal with BullyingBullying in the Irish Workplace-How to Deal with Bullying
Bullying in the Irish Workplace-How to Deal with Bullying
 
Medical Whistleblower Canary Notes Newsletter 2 Bullying February 2006...
Medical  Whistleblower  Canary  Notes  Newsletter 2  Bullying  February  2006...Medical  Whistleblower  Canary  Notes  Newsletter 2  Bullying  February  2006...
Medical Whistleblower Canary Notes Newsletter 2 Bullying February 2006...
 
5 Benefits of Using Reciprocity in Investigation Interviews
5 Benefits of Using Reciprocity in Investigation Interviews5 Benefits of Using Reciprocity in Investigation Interviews
5 Benefits of Using Reciprocity in Investigation Interviews
 
Defend Yourself Against Bad Decisions
Defend Yourself Against Bad DecisionsDefend Yourself Against Bad Decisions
Defend Yourself Against Bad Decisions
 
Why (and How) Diversity Matters Now
Why (and How) Diversity Matters NowWhy (and How) Diversity Matters Now
Why (and How) Diversity Matters Now
 
Unconscious bias training
Unconscious bias trainingUnconscious bias training
Unconscious bias training
 
How Should We Address Bulling In The Workplace Medical Whistleblower
How  Should  We  Address  Bulling In The  Workplace    Medical  WhistleblowerHow  Should  We  Address  Bulling In The  Workplace    Medical  Whistleblower
How Should We Address Bulling In The Workplace Medical Whistleblower
 

Similar to How to Incorporate "Psyber Resilience" into Your Security Strategy

C Fconcepts.C Hpowerpoint
C Fconcepts.C HpowerpointC Fconcepts.C Hpowerpoint
C Fconcepts.C Hpowerpoint
Tracy Wharton
 
75717863 stress-management
75717863 stress-management75717863 stress-management
75717863 stress-management
shilpabhagat512
 
ESA Presentation - Shifting Perceptions (April 4th)
ESA Presentation - Shifting Perceptions (April 4th)ESA Presentation - Shifting Perceptions (April 4th)
ESA Presentation - Shifting Perceptions (April 4th)
lawrencepeddie
 
[Behav. sci] stress management presentation
[Behav. sci] stress management presentation[Behav. sci] stress management presentation
[Behav. sci] stress management presentation
Muhammad Ahmad
 
Early Intervention: Changing Lives, Saving Lives
Early Intervention: Changing Lives, Saving LivesEarly Intervention: Changing Lives, Saving Lives
Early Intervention: Changing Lives, Saving Lives
commteam
 

Similar to How to Incorporate "Psyber Resilience" into Your Security Strategy (20)

JAIME VINCK - COMPASSION FATIGUE AND PROVIDER RESILIENCE
JAIME VINCK - COMPASSION FATIGUE AND PROVIDER RESILIENCEJAIME VINCK - COMPASSION FATIGUE AND PROVIDER RESILIENCE
JAIME VINCK - COMPASSION FATIGUE AND PROVIDER RESILIENCE
 
Preventing-Burnout-Presentation-okoboji.pptx
Preventing-Burnout-Presentation-okoboji.pptxPreventing-Burnout-Presentation-okoboji.pptx
Preventing-Burnout-Presentation-okoboji.pptx
 
stress-teach.ppt
stress-teach.pptstress-teach.ppt
stress-teach.ppt
 
C Fconcepts.C Hpowerpoint
C Fconcepts.C HpowerpointC Fconcepts.C Hpowerpoint
C Fconcepts.C Hpowerpoint
 
Depression Spirituality & Recovery
Depression Spirituality & RecoveryDepression Spirituality & Recovery
Depression Spirituality & Recovery
 
Missing Piece
Missing PieceMissing Piece
Missing Piece
 
Stress Help
Stress HelpStress Help
Stress Help
 
75717863 stress-management
75717863 stress-management75717863 stress-management
75717863 stress-management
 
DE-STRESSING SELF AND SOCIETY.pptx
DE-STRESSING SELF AND SOCIETY.pptxDE-STRESSING SELF AND SOCIETY.pptx
DE-STRESSING SELF AND SOCIETY.pptx
 
Smart program
 Smart  program Smart  program
Smart program
 
Mental Health Awareness
Mental Health Awareness Mental Health Awareness
Mental Health Awareness
 
ESA Presentation - Shifting Perceptions (April 4th)
ESA Presentation - Shifting Perceptions (April 4th)ESA Presentation - Shifting Perceptions (April 4th)
ESA Presentation - Shifting Perceptions (April 4th)
 
[Behav. sci] stress management presentation
[Behav. sci] stress management presentation[Behav. sci] stress management presentation
[Behav. sci] stress management presentation
 
[Behav. sci] stress management presentation by SIMS Lahore
[Behav. sci] stress management presentation by SIMS Lahore[Behav. sci] stress management presentation by SIMS Lahore
[Behav. sci] stress management presentation by SIMS Lahore
 
anxiety_depression_stress.pptx
anxiety_depression_stress.pptxanxiety_depression_stress.pptx
anxiety_depression_stress.pptx
 
stress at work
stress at workstress at work
stress at work
 
Stress Mgmt for Lawyers
Stress Mgmt for LawyersStress Mgmt for Lawyers
Stress Mgmt for Lawyers
 
stress management....stress can be the spice of life.......or it can be the ...
stress management....stress can be the spice of life.......or it can be the  ...stress management....stress can be the spice of life.......or it can be the  ...
stress management....stress can be the spice of life.......or it can be the ...
 
THESIS
THESISTHESIS
THESIS
 
Early Intervention: Changing Lives, Saving Lives
Early Intervention: Changing Lives, Saving LivesEarly Intervention: Changing Lives, Saving Lives
Early Intervention: Changing Lives, Saving Lives
 

More from Case IQ

More from Case IQ (20)

How Best Practices in Triage Protocol Can Boost Compliance and Reduce Risk
How Best Practices in Triage Protocol Can Boost Compliance and Reduce RiskHow Best Practices in Triage Protocol Can Boost Compliance and Reduce Risk
How Best Practices in Triage Protocol Can Boost Compliance and Reduce Risk
 
How to Drive Efficiency and Reduce Risk with Investigative Case Management So...
How to Drive Efficiency and Reduce Risk with Investigative Case Management So...How to Drive Efficiency and Reduce Risk with Investigative Case Management So...
How to Drive Efficiency and Reduce Risk with Investigative Case Management So...
 
Who's Lying? Using the Cognitive Interview to Assess Credibility in Workplace...
Who's Lying? Using the Cognitive Interview to Assess Credibility in Workplace...Who's Lying? Using the Cognitive Interview to Assess Credibility in Workplace...
Who's Lying? Using the Cognitive Interview to Assess Credibility in Workplace...
 
Protecting the Mental Wellbeing of Corporate Investigators
Protecting the Mental Wellbeing of Corporate InvestigatorsProtecting the Mental Wellbeing of Corporate Investigators
Protecting the Mental Wellbeing of Corporate Investigators
 
Meric Bloc_Webinar Nov22.pptx
Meric Bloc_Webinar Nov22.pptxMeric Bloc_Webinar Nov22.pptx
Meric Bloc_Webinar Nov22.pptx
 
5 Steps to Creating an Ethical Work Culture
5 Steps to Creating an Ethical Work Culture5 Steps to Creating an Ethical Work Culture
5 Steps to Creating an Ethical Work Culture
 
How to Assess, Level Up, and Leverage Your Culture of Compliance
How to Assess, Level Up, and Leverage Your Culture of ComplianceHow to Assess, Level Up, and Leverage Your Culture of Compliance
How to Assess, Level Up, and Leverage Your Culture of Compliance
 
Everything You Need to Get E&C Investigations Right (According to the DOJ)
Everything You Need to Get E&C Investigations Right (According to the DOJ)Everything You Need to Get E&C Investigations Right (According to the DOJ)
Everything You Need to Get E&C Investigations Right (According to the DOJ)
 
5 Ways to Build Employee Trust for Less Turnover and Fewer Incidents
5 Ways to Build Employee Trust for Less Turnover and Fewer Incidents5 Ways to Build Employee Trust for Less Turnover and Fewer Incidents
5 Ways to Build Employee Trust for Less Turnover and Fewer Incidents
 
Hybrid Workplace Harassment: Are You Protecting Your Company from Hidden Thre...
Hybrid Workplace Harassment: Are You Protecting Your Company from Hidden Thre...Hybrid Workplace Harassment: Are You Protecting Your Company from Hidden Thre...
Hybrid Workplace Harassment: Are You Protecting Your Company from Hidden Thre...
 
Finding Value Before a Crisis: How Workplace DEI Drives Revenue and Prevents ...
Finding Value Before a Crisis: How Workplace DEI Drives Revenue and Prevents ...Finding Value Before a Crisis: How Workplace DEI Drives Revenue and Prevents ...
Finding Value Before a Crisis: How Workplace DEI Drives Revenue and Prevents ...
 
How Not to Get Called Out on TikTok: Improving Your Brand Through Employer/Em...
How Not to Get Called Out on TikTok: Improving Your Brand Through Employer/Em...How Not to Get Called Out on TikTok: Improving Your Brand Through Employer/Em...
How Not to Get Called Out on TikTok: Improving Your Brand Through Employer/Em...
 
Misconduct or Missed Conduct? Ensuring Consistent SAR Reporting of Internal M...
Misconduct or Missed Conduct? Ensuring Consistent SAR Reporting of Internal M...Misconduct or Missed Conduct? Ensuring Consistent SAR Reporting of Internal M...
Misconduct or Missed Conduct? Ensuring Consistent SAR Reporting of Internal M...
 
Building Effective Sexual Harassment Prevention Policies and Training
Building Effective Sexual Harassment Prevention Policies and TrainingBuilding Effective Sexual Harassment Prevention Policies and Training
Building Effective Sexual Harassment Prevention Policies and Training
 
Search Engine Skills for Workplace Investigators
Search Engine Skills for Workplace InvestigatorsSearch Engine Skills for Workplace Investigators
Search Engine Skills for Workplace Investigators
 
Under the Table: Combatting Bribery and Corruption Through Analysis and Preve...
Under the Table: Combatting Bribery and Corruption Through Analysis and Preve...Under the Table: Combatting Bribery and Corruption Through Analysis and Preve...
Under the Table: Combatting Bribery and Corruption Through Analysis and Preve...
 
Tips, Templates and Best Practices for Conducting Investigations Remotely
Tips, Templates and Best Practices for Conducting Investigations Remotely Tips, Templates and Best Practices for Conducting Investigations Remotely
Tips, Templates and Best Practices for Conducting Investigations Remotely
 
Social Media Risks in the Workplace
Social Media Risks in the Workplace Social Media Risks in the Workplace
Social Media Risks in the Workplace
 
“New” Misconduct Challenges and Solutions for Investigating as We Move to a ...
“New” Misconduct Challenges and Solutions for Investigating as We Move to a ...“New” Misconduct Challenges and Solutions for Investigating as We Move to a ...
“New” Misconduct Challenges and Solutions for Investigating as We Move to a ...
 
Post Interview Report Writing: How to Document Your Investigation Interview
Post Interview Report Writing: How to Document Your Investigation InterviewPost Interview Report Writing: How to Document Your Investigation Interview
Post Interview Report Writing: How to Document Your Investigation Interview
 

Recently uploaded

Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
WSO2
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Victor Rentea
 

Recently uploaded (20)

Less Is More: Utilizing Ballerina to Architect a Cloud Data Platform
Less Is More: Utilizing Ballerina to Architect a Cloud Data PlatformLess Is More: Utilizing Ballerina to Architect a Cloud Data Platform
Less Is More: Utilizing Ballerina to Architect a Cloud Data Platform
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
Modernizing Legacy Systems Using Ballerina
Modernizing Legacy Systems Using BallerinaModernizing Legacy Systems Using Ballerina
Modernizing Legacy Systems Using Ballerina
 
API Governance and Monetization - The evolution of API governance
API Governance and Monetization -  The evolution of API governanceAPI Governance and Monetization -  The evolution of API governance
API Governance and Monetization - The evolution of API governance
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
Platformless Horizons for Digital Adaptability
Platformless Horizons for Digital AdaptabilityPlatformless Horizons for Digital Adaptability
Platformless Horizons for Digital Adaptability
 
Decarbonising Commercial Real Estate: The Role of Operational Performance
Decarbonising Commercial Real Estate: The Role of Operational PerformanceDecarbonising Commercial Real Estate: The Role of Operational Performance
Decarbonising Commercial Real Estate: The Role of Operational Performance
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
 
Navigating Identity and Access Management in the Modern Enterprise
Navigating Identity and Access Management in the Modern EnterpriseNavigating Identity and Access Management in the Modern Enterprise
Navigating Identity and Access Management in the Modern Enterprise
 
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfRising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistan
 
Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​
 
WSO2 Micro Integrator for Enterprise Integration in a Decentralized, Microser...
WSO2 Micro Integrator for Enterprise Integration in a Decentralized, Microser...WSO2 Micro Integrator for Enterprise Integration in a Decentralized, Microser...
WSO2 Micro Integrator for Enterprise Integration in a Decentralized, Microser...
 
Vector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptxVector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptx
 
Stronger Together: Developing an Organizational Strategy for Accessible Desig...
Stronger Together: Developing an Organizational Strategy for Accessible Desig...Stronger Together: Developing an Organizational Strategy for Accessible Desig...
Stronger Together: Developing an Organizational Strategy for Accessible Desig...
 
AI in Action: Real World Use Cases by Anitaraj
AI in Action: Real World Use Cases by AnitarajAI in Action: Real World Use Cases by Anitaraj
AI in Action: Real World Use Cases by Anitaraj
 
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
 

How to Incorporate "Psyber Resilience" into Your Security Strategy

  • 1. How to Incorporate “Psyber Resilience” into Your Security Strategy Neal O’Farrell, Founder, The PsyberResilience Project
  • 2. 40 years in global security and privacy 50 years struggling with mental illness 30 years struggling with chronic stress and eventually burnout Now focused on mental health and wellness
  • 3. Leading the creation of a mental health action cluster to create standards for mental health in future smart cities
  • 5.
  • 6. Jack Daniel, founder of B/Sides, speakin about mental health concerns in security in 2012.
  • 7.
  • 8.
  • 9.
  • 10. Personal Risks • Mental health – depression, anxiety, worry, anger, cynicism, despair, suicide • Physical health – blood pressure, digestive, weight gain, immune system • Substance abuse • Passion for the career • Relationships • Seek other employment • Quit the industry • Absenteeism and “Presenteeism”
  • 11. Organizational Risks Unmanaged stress is known to harm • Cognitive function • Attention and focus • Decision making • Memory • Engagement • You’ll lose your best and brightest! Adversaries recognize security stress as a significant vulnerability and opportunity
  • 12. A DOZEN MAJOR CAUSES OF PSYBER STRESS 1 Unrealistic Expectations “Unrealistic and unhealthy expectations about outcomes and results, expectations set both by employers and by the individual defenders.”
  • 13. 2 No Time To Regroup Little time to pause or decompress because of the relentless waves of attacks, constant training, vendors, regulations etc. A DOZEN MAJOR CAUSES OF PSYBER STRESS
  • 14. 2 Simmering Frustrations Understaffing, insufficient budgets, employees who continue to undo and undermine security efforts, and a leadership not taking the threats seriously enough. A DOZEN MAJOR CAUSES OF PSYBER STRESS
  • 15. 2 Exhausting Schedules “Always being on the clock, on the job, at least mentally, compounded by no real downtime, long hours, long weeks, and even long weekends.” A DOZEN MAJOR CAUSES OF PSYBER STRESS
  • 16. 2 Change Fatigue “Trying to keep up with a constantly changing environment, from new threats, tactics, and technologies, to new laws, regulations, guidelines, frameworks, and standards” A DOZEN MAJOR CAUSES OF PSYBER STRESS
  • 17. 2 Professional Pride “The constant fear of personal failure, of being the one who lets the team and organization down by missing that one single threat amongst thousands” A DOZEN MAJOR CAUSES OF PSYBER STRESS
  • 18. 2 A Cruel Enemy “The emotional toll of constantly fighting and being exposed to the worst kinds of criminals, and witnessing the cruelty they inflict on their victims” A DOZEN MAJOR CAUSES OF PSYBER STRESS
  • 19. 2 Growing Cynicism “An increase in cynicism and a decrease in trust amongst security professionals, often permanent emotional changes that they bring home with them” A DOZEN MAJOR CAUSES OF PSYBER STRESS
  • 20. 2 Not Enough Eyes “Security teams stretched too thinly, which results in heavier workloads, pressure to take on too many tasks, and not being allowed to focus on the most critical or relevant challenges” A DOZEN MAJOR CAUSES OF PSYBER STRESS
  • 21. 2 Pre-Existing Conditions “Many security professionals come into the industry with existing mental health issues, and especially with an increase in military and law enforcement dealing with anxiety and PTSD” A DOZEN MAJOR CAUSES OF PSYBER STRESS
  • 22. 2 The Exploitation of Stress “A growing strategy by attackers to psychologically wear out the defenders, and often taunting, threatening, and even directly targeting security professionals” A DOZEN MAJOR CAUSES OF PSYBER STRESS
  • 24. UNDERSTANDINGStress Stress is little more than the way we process “stressors,” how our brains process the stressful things around us. If we can better understand how stress works and how to manage stressors, we can almost eliminate the impact of stress. In other words, it’s all literally in our own minds. And it’s often a self-inflicted wound. But - If we fail to manage stress, it can severely harm our health and quality of life.
  • 25. Stress and Cortisol A QUICK PRIMER Cortisol is an essential part of the body’s core defense system, the “fight or flight” response. In order not to become toxic, it recedes to normal levels after the danger has passed. When Cortisol remains constantly elevated it becomes toxic: • Heart and pulmonary • Digestive • Immune system • Cognitive function • Sleep • Dementia/Alzheimer’s • Reproductive So what keeps Cortisol at toxic elevated levels? STRESS!
  • 26. “A state of physical or emotional exhaustion that also involves a sense of reduced accomplishment and loss of personal identity.” The Mayo Clinic Burnout impacts nearly half of all workers, and researchers at Stanford found that workplace stress costs businesses nearly $200 billion annually and leads to nearly 120,000 deaths each year. So where does it come from? Chronic burnout is usually the end result of years of unchecked and unmanaged chronic stress. UNDERSTANDING Burnout
  • 27. • Constantly cynical or critical at work • Having trouble getting up and getting started • Irritable or impatient with co-workers, customers or clients • Lack the energy to be consistently productive, or “presenteeism” • Find it hard to concentrate, focus, engage, make decisions SPOTTING THE SIGNS Of Burnout
  • 28. • Lack of satisfaction from achievements • Feeling disillusioned about the job and mission • Using food, drugs, or alcohol to feel better - or to simply not feel • Changes in sleeping habits • Unexplained headaches, stomach or bowel problems, or other physical complaints SPOTTING THE SIGNS Of Burnout A WORD OF CAUTION! Symptoms of burnout can often mimic those of serious mental health issues like depression.
  • 29. The most important rule of all? “Recognize that it’s all in your head. Literally” Which means you have enormous control.
  • 30. Manage it like a threat Create a list of all the “things” – the stressors – that are causing your stress. Address them individually
  • 31. “There is no stress in security!” Understand the difference between “stressors” and “stress.” They’re not the same and the difference is crucial
  • 32. Apply the BAD system: Bucketize And DAM
  • 35. Schedule/Hours Work overload Resources Your boss Your Training Fear of failure Fear of being fired Disillusionment Co-workers Certifications Compliance and cynicism Exhaustion
  • 36. Highstandards Intolerant Perfectionist ”I will not be the Taking it too personally weak link” Competitive Impatient Taking it home
  • 37. Mindfulness is proven to be one of the most powerful stress management tools. Exercise and fresh air A better social life/social network Better eating habits
  • 38. Teach yourself to be happier Practice gratitude Laugh and smile more Kitty videos are scientifically “great”
  • 39. Learn To Be A Brain Alchemist Understand how cortisol, serotonin, and dopamine work, how they interact with each other, and how to control them through your thoughts and actions.
  • 40. DAM Dismiss – Not real or really worth worrying about. Accept – Real but you can deal with them. Manage – Real, potentially harmful, and need to be managed.
  • 41. CISO, Heal Thyself Chances are you’re dealing with the same issues, maybe worse, probably for longer. Go through your own self-assessment first, identify the most destructive stressors. Use what you learn to (a) start healing yourself and (b) inspire your security team. Note to self – Your biggest stressors might come from above, management and board. So the strategy might be different.
  • 42. Learn The differences and the relationships between stress, burnout, and mental illness: • Chronic stress = unmanaged long-term stress • Burnout = unmanaged chronic stress • Unmanaged stress can become depression • Or – burnout is unrecognized depression Caution – you’re in the realm of mental illness. Always seek professional advice
  • 43. Know Your Team “My guys are all OK. I know they’ll tell me if they’re struggling” No they won’t. It’s rarely the case. Spend as much personal time with your team, all of them. And not isolated. Talk about these issues all the time. That’s the best way to build the trust that will free the truth. Talk to them separately and privately too. It’s a delicate subject. Note to self – Your biggest stressors might come from above, management and board. So the strategy might be different.
  • 44. Study The Stressors The more you understand about what’s stressing your security team, the easier it will be to manage or neutralize them. Remember BAD? Recognize that you might be one or the greatest sources of stress. If the pressures on your team are coming from above you, let them know that, that it’s not because of your indifference. Survey your team on stressors. Mental health is not unlike security. Use the “shared struggle” to encourage more understanding and empathy
  • 45. Let Them Speak Create an anonymous way for your security team to: • Vent • Criticize • Point fingers • Suggest A powerful way to gather the most honest and useful insights Make sure it’s truly anonymous or you risk additional risks
  • 46. If you can’t fix... ...at least speak openly about: • Why you don’t have enough manpower • Why you don’t have other critical resources • Why you’re just as frustrated with management as they are • Why you’re constantly putting out fires • Why you’re just as frustrated with vendors, tools and technologies, compliance, endless new regulations and frameworks, relentless training, too many distractions
  • 47. Give them a break Work/life balance is critically important in managing stress and mental health: • More time off – come in later, leave earlier, longer breaks, longer weekends • More downtime with the team • Longer/more frequent vacations • “Off” also means off the clock and off the job • Allow for/encourage more remote work
  • 48. One Rotten Apple Toxic/Rockstar personalities can make an entire workplace toxic: • The know-all, expert of all experts • Condescending, arrogant, dismissive, controlling, attention seeking • Bullying is increasingly commonplace • One single toxic personality can cripple an entire team • Try to cure rather than amputate Recognize that toxic behavior might just be poor coping skills or unaddressed issues
  • 49. Beyond Stress The security industry has long attracted those already struggling with mental illnesses: • 1 in 5 Americans struggle with mental illness, and often more than one • Anxiety and depression are the most common • Anxiety and depression also come in many varieties • Bipolar and Schizophrenia are growing • PTSD very common amongst transitions from military and law enforcement Learn the differences, recognize the signs, know how to approach, embrace, support, and champion
  • 50. Create An Escape Room A comfortable and nearby place to escape, decompress, disengage, refresh, vent, and start all over
  • 51. Contact Neal O’Farrell nealjofarrell@gmail.com @nealofarrell https://www.linkedin.com/in/nealofarrell/ Contact i-Sight j.gerard@i-sight.com Find more free webinars: http://www.i-sight.com/resources/webinars @isightsoftware