SlideShare a Scribd company logo
Dr. Margaret Cunningham, Principal Research Scientist
Forcepoint, X-Labs
Weary Warriors:
Reducing the Impact of Wishful
Thinking & Fatigue on Information
Security Decisions
4 June, 2019
Weary Warriors: Reducing the Impact of Wishful Thinking & Fatigue on
Information Security Decisions
Select the option that fits you best:
- I use the exact same password on multiple sites. ¯_(ツ)_/¯
- I change my passwords a little bit—Password1! is different from
Passw0rd, right?
- I never reuse passwords.
- I use a password manager.
Slido Q1
Weary Warriors: Reducing the Impact of Wishful Thinking & Fatigue on
Information Security Decisions
40-50% of users reuse
passwords
Weary Warriors: Reducing the Impact of Wishful Thinking & Fatigue on
Information Security Decisions
46% of organizations don’t
change their security strategy
after an attack!
Weary Warriors: Reducing the Impact of Wishful Thinking & Fatigue on
Information Security Decisions
Definitions & Outcomes
• Motivated Reasoning
• Decision Fatigue
Strategies & Solutions
Overview
Weary Warriors: Reducing the Impact of Wishful
Thinking & Fatigue on Information Security Decisions
• “Wishful Thinking” and self-
deception
• Avoidance of cognitive
dissonance
• Evaluating problems in favor
of preferred outcomes
Motivated Reasoning is…
Weary Warriors: Reducing the Impact of Wishful Thinking & Fatigue on
Information Security Decisions
• Inadequate solutions based
on biased information
• Aversion to change
• Rationalization, and denial,
of poor choices
Impact of Motivated Reasoning
Weary Warriors: Reducing the Impact of Wishful
Thinking & Fatigue on Information Security Decisions
• Decision-making draws on
finite mental resources
• Our capabilities degrade over
the course of each day
• Helped by food, cured by rest
Decision Fatigue is…
Weary Warriors: Reducing the Impact of Wishful Thinking & Fatigue on
Information Security Decisions
• Decision avoidance, relying
on defaults or “status quo”
• Difficulty weighing pros &
cons of multiple options
• Short-term > long-term
• Selecting the least effortful
choice
Impact of Decision Fatigue
Weary Warriors: Reducing the Impact of Wishful Thinking & Fatigue on
Information Security Decisions
• When faced with “facts that don’t fit” we ignore them
• When fatigued, we pick the easy way out – if we make
a choice at all
Motivated Reasoning + Decision Fatigue = Bad Decisions
Weary Warriors: Reducing the Impact of Wishful Thinking & Fatigue on
Information Security Decisions
Strategies & Solutions
1. Recognize the Signs
2. Be Choosy about
Choosing
3. Plan & Prioritize
Weary Warriors: Reducing the Impact of Wishful Thinking & Fatigue on
Information Security Decisions
• Impaired self-control & impulsivity
• Procrastination
• Decision avoidance
• Irritability
• Ignoring contradicting opinions or
facts?
Recognize the Signs
Weary Warriors: Reducing the Impact of Wishful Thinking & Fatigue on
Information Security Decisions
• Cut options
• Concrete examples
• Categorize
• Condition for Complexity
Be Choosy about Choosing1
1 Sheena Iyengar, “The Art of Choosing”
Weary Warriors: Reducing the Impact of Wishful Thinking & Fatigue on
Information Security Decisions
• Plan daily decisions in
advance
• Prioritize important decisions
for the morning
• Sleep on it – when possible
• Use tools & establish
decision-making processes to
support unplanned or late-
day choices
Plan & Prioritize
Weary Warriors: Reducing the Impact of Wishful Thinking & Fatigue on
Information Security Decisions
5 KEY TAKE AWAYS
Weary Warriors: Reducing the Impact of Wishful Thinking & Fatigue on
Information Security Decisions
• Motivated reasoning leads to biased decision making & denial of
alternative solutions that differ from existing practices
• Decision fatigue leads to decision avoidance, or selection of easier,
short-term solutions
• Recognize the signs: procrastination, distraction, impulsivity,
irritability, risk-aversion
• Use choice strategies: cut, categorize, concrete examples, &
conditioning for complexity
• And, when possible, plan and prioritize to optimize decision-making
5 KEY TAKE AWAYS
Weary Warriors: Reducing the Impact of Wishful Thinking & Fatigue on
Information Security Decisions
Follow-up questions or comments?
Margaret.Cunningham@Forcepoint.com
Or, visit my Forcepoint Author Page:
www.forcepoint.com/company/biographies/margaret-cunningham
Recent White Papers:
Exploring the Grey Space of Cybersecurity with
Insights from Cognitive Science
Thinking about Thinking: Exploring Bias in
Cybersecurity with Insights from Cognitive Science

More Related Content

Similar to Weary Warriors: Reducing the Impact of Wishful Thinking & Fatigue on Information Security Decisions

Presentation2
Presentation2Presentation2
Presentation2
alimohsen08
 
Topic6decisionmaking
Topic6decisionmakingTopic6decisionmaking
Topic6decisionmakingHariz Mustafa
 
Decision Making
Decision MakingDecision Making
Decision Making
ALAN KURIAN SABU
 
MGT 3200 Exam #2
MGT 3200 Exam #2MGT 3200 Exam #2
MGT 3200 Exam #2kgreau1
 
Decision Making & Problem Solving _ Materi Training "LEADERSHIP for Manager &...
Decision Making & Problem Solving _ Materi Training "LEADERSHIP for Manager &...Decision Making & Problem Solving _ Materi Training "LEADERSHIP for Manager &...
Decision Making & Problem Solving _ Materi Training "LEADERSHIP for Manager &...
Kanaidi ken
 
Motivation and Bias: Strategies for Developing Greater Self-Awareness and Obs...
Motivation and Bias: Strategies for Developing Greater Self-Awareness and Obs...Motivation and Bias: Strategies for Developing Greater Self-Awareness and Obs...
Motivation and Bias: Strategies for Developing Greater Self-Awareness and Obs...
MRG (Management Research Group)
 
Fundamentals of Decision Making
Fundamentals of Decision Making Fundamentals of Decision Making
Fundamentals of Decision Making
Andrew Hirst
 
Decision Making 1
Decision Making 1Decision Making 1
Decision Making 1
LyricojaeCassie
 
decision making.pptx
decision making.pptxdecision making.pptx
decision making.pptx
DrManishaPawar2
 
Ob slides - decision making hold(1)
Ob slides  - decision making  hold(1)Ob slides  - decision making  hold(1)
Ob slides - decision making hold(1)stuitstrain2
 
Brian Glass Making Decisions
Brian Glass Making DecisionsBrian Glass Making Decisions
Brian Glass Making Decisionsbrnglass
 
Career decision making
Career decision makingCareer decision making
Career decision makingsdonatel
 
Step Into Security Webinar - Threat Assessments in Schools
Step Into Security Webinar - Threat Assessments in SchoolsStep Into Security Webinar - Threat Assessments in Schools
Step Into Security Webinar - Threat Assessments in Schools
Keith Harris
 
Entrepreneurial Psychology
Entrepreneurial PsychologyEntrepreneurial Psychology
Entrepreneurial Psychology
jericsinger
 
OODA OODA! How Rapid Iteration Can Help Level Up Your Gaming Business
OODA OODA! How Rapid Iteration Can Help Level Up Your Gaming BusinessOODA OODA! How Rapid Iteration Can Help Level Up Your Gaming Business
OODA OODA! How Rapid Iteration Can Help Level Up Your Gaming Business
SeriousGamesAssoc
 
Session 4 - Lectures in Leadership (Relating).pptx
Session 4 - Lectures in Leadership (Relating).pptxSession 4 - Lectures in Leadership (Relating).pptx
Session 4 - Lectures in Leadership (Relating).pptx
ssuserde1c26
 
I am my worst enemy — A first person look at Insider Threat
I am my worst enemy — A first person look at Insider ThreatI am my worst enemy — A first person look at Insider Threat
I am my worst enemy — A first person look at Insider Threat
Ahmed Masud
 
د حاتم البيطار استشاري وجراح الفم والاسنان 01005684344 اتصل للحجز بالعيادة D...
د حاتم البيطار استشاري وجراح الفم والاسنان 01005684344 اتصل للحجز بالعيادة  D...د حاتم البيطار استشاري وجراح الفم والاسنان 01005684344 اتصل للحجز بالعيادة  D...
د حاتم البيطار استشاري وجراح الفم والاسنان 01005684344 اتصل للحجز بالعيادة D...
د حاتم البيطار
 
Decision Making
Decision MakingDecision Making
Decision Making
anisur_rehman
 
Presentation: Avoiding Nonprofit Disasters Through Decision-Making Science
Presentation: Avoiding Nonprofit Disasters Through Decision-Making SciencePresentation: Avoiding Nonprofit Disasters Through Decision-Making Science
Presentation: Avoiding Nonprofit Disasters Through Decision-Making Science
Gleb Tsipursky
 

Similar to Weary Warriors: Reducing the Impact of Wishful Thinking & Fatigue on Information Security Decisions (20)

Presentation2
Presentation2Presentation2
Presentation2
 
Topic6decisionmaking
Topic6decisionmakingTopic6decisionmaking
Topic6decisionmaking
 
Decision Making
Decision MakingDecision Making
Decision Making
 
MGT 3200 Exam #2
MGT 3200 Exam #2MGT 3200 Exam #2
MGT 3200 Exam #2
 
Decision Making & Problem Solving _ Materi Training "LEADERSHIP for Manager &...
Decision Making & Problem Solving _ Materi Training "LEADERSHIP for Manager &...Decision Making & Problem Solving _ Materi Training "LEADERSHIP for Manager &...
Decision Making & Problem Solving _ Materi Training "LEADERSHIP for Manager &...
 
Motivation and Bias: Strategies for Developing Greater Self-Awareness and Obs...
Motivation and Bias: Strategies for Developing Greater Self-Awareness and Obs...Motivation and Bias: Strategies for Developing Greater Self-Awareness and Obs...
Motivation and Bias: Strategies for Developing Greater Self-Awareness and Obs...
 
Fundamentals of Decision Making
Fundamentals of Decision Making Fundamentals of Decision Making
Fundamentals of Decision Making
 
Decision Making 1
Decision Making 1Decision Making 1
Decision Making 1
 
decision making.pptx
decision making.pptxdecision making.pptx
decision making.pptx
 
Ob slides - decision making hold(1)
Ob slides  - decision making  hold(1)Ob slides  - decision making  hold(1)
Ob slides - decision making hold(1)
 
Brian Glass Making Decisions
Brian Glass Making DecisionsBrian Glass Making Decisions
Brian Glass Making Decisions
 
Career decision making
Career decision makingCareer decision making
Career decision making
 
Step Into Security Webinar - Threat Assessments in Schools
Step Into Security Webinar - Threat Assessments in SchoolsStep Into Security Webinar - Threat Assessments in Schools
Step Into Security Webinar - Threat Assessments in Schools
 
Entrepreneurial Psychology
Entrepreneurial PsychologyEntrepreneurial Psychology
Entrepreneurial Psychology
 
OODA OODA! How Rapid Iteration Can Help Level Up Your Gaming Business
OODA OODA! How Rapid Iteration Can Help Level Up Your Gaming BusinessOODA OODA! How Rapid Iteration Can Help Level Up Your Gaming Business
OODA OODA! How Rapid Iteration Can Help Level Up Your Gaming Business
 
Session 4 - Lectures in Leadership (Relating).pptx
Session 4 - Lectures in Leadership (Relating).pptxSession 4 - Lectures in Leadership (Relating).pptx
Session 4 - Lectures in Leadership (Relating).pptx
 
I am my worst enemy — A first person look at Insider Threat
I am my worst enemy — A first person look at Insider ThreatI am my worst enemy — A first person look at Insider Threat
I am my worst enemy — A first person look at Insider Threat
 
د حاتم البيطار استشاري وجراح الفم والاسنان 01005684344 اتصل للحجز بالعيادة D...
د حاتم البيطار استشاري وجراح الفم والاسنان 01005684344 اتصل للحجز بالعيادة  D...د حاتم البيطار استشاري وجراح الفم والاسنان 01005684344 اتصل للحجز بالعيادة  D...
د حاتم البيطار استشاري وجراح الفم والاسنان 01005684344 اتصل للحجز بالعيادة D...
 
Decision Making
Decision MakingDecision Making
Decision Making
 
Presentation: Avoiding Nonprofit Disasters Through Decision-Making Science
Presentation: Avoiding Nonprofit Disasters Through Decision-Making SciencePresentation: Avoiding Nonprofit Disasters Through Decision-Making Science
Presentation: Avoiding Nonprofit Disasters Through Decision-Making Science
 

More from Forcepoint LLC

Rethinking the concept of trust (DoDIIS 2019 presentation)
Rethinking the concept of trust (DoDIIS 2019 presentation)Rethinking the concept of trust (DoDIIS 2019 presentation)
Rethinking the concept of trust (DoDIIS 2019 presentation)
Forcepoint LLC
 
Sparking Curiosity to Change Security Behaviors
Sparking Curiosity to Change Security BehaviorsSparking Curiosity to Change Security Behaviors
Sparking Curiosity to Change Security Behaviors
Forcepoint LLC
 
Understanding the "Intelligence" in AI
Understanding the "Intelligence" in AIUnderstanding the "Intelligence" in AI
Understanding the "Intelligence" in AI
Forcepoint LLC
 
AI and ML in Cybersecurity
AI and ML in CybersecurityAI and ML in Cybersecurity
AI and ML in Cybersecurity
Forcepoint LLC
 
Using Language Modeling to Verify User Identities
Using Language Modeling to Verify User IdentitiesUsing Language Modeling to Verify User Identities
Using Language Modeling to Verify User Identities
Forcepoint LLC
 
Driving the successful adoption of Microsoft Office 365
Driving the successful adoption of Microsoft Office 365Driving the successful adoption of Microsoft Office 365
Driving the successful adoption of Microsoft Office 365
Forcepoint LLC
 
Securing Beyond the Cloud Generation
Securing Beyond the Cloud GenerationSecuring Beyond the Cloud Generation
Securing Beyond the Cloud Generation
Forcepoint LLC
 
Forcepoint Advanced Malware Detection
Forcepoint Advanced Malware DetectionForcepoint Advanced Malware Detection
Forcepoint Advanced Malware Detection
Forcepoint LLC
 
Top 5 Information Security Lessons Learned from Transitioning to the Cloud
Top 5 Information Security Lessons Learned from Transitioning to the CloudTop 5 Information Security Lessons Learned from Transitioning to the Cloud
Top 5 Information Security Lessons Learned from Transitioning to the Cloud
Forcepoint LLC
 
CASB: Securing your cloud applications
CASB: Securing your cloud applicationsCASB: Securing your cloud applications
CASB: Securing your cloud applications
Forcepoint LLC
 
One Year After WannaCry - Has Anything Changed? A Root Cause Analysis of Data...
One Year After WannaCry - Has Anything Changed? A Root Cause Analysis of Data...One Year After WannaCry - Has Anything Changed? A Root Cause Analysis of Data...
One Year After WannaCry - Has Anything Changed? A Root Cause Analysis of Data...
Forcepoint LLC
 
GDPR is Here. Now What?
GDPR is Here. Now What?GDPR is Here. Now What?
GDPR is Here. Now What?
Forcepoint LLC
 
Addressing Future Risks and Legal Challenges of Insider Threats
Addressing Future Risks and Legal Challenges of Insider ThreatsAddressing Future Risks and Legal Challenges of Insider Threats
Addressing Future Risks and Legal Challenges of Insider Threats
Forcepoint LLC
 
A Predictive “Precrime” Approach Requires a Human Focus
A Predictive “Precrime” Approach Requires a Human FocusA Predictive “Precrime” Approach Requires a Human Focus
A Predictive “Precrime” Approach Requires a Human Focus
Forcepoint LLC
 
Cyber Convergence, Warfare and You
Cyber Convergence, Warfare and YouCyber Convergence, Warfare and You
Cyber Convergence, Warfare and You
Forcepoint LLC
 
Securing the Global Mission: Enabling Effective Information Sharing (DoD MPE-IS)
Securing the Global Mission: Enabling Effective Information Sharing (DoD MPE-IS)Securing the Global Mission: Enabling Effective Information Sharing (DoD MPE-IS)
Securing the Global Mission: Enabling Effective Information Sharing (DoD MPE-IS)
Forcepoint LLC
 
Security Insights for Mission-Critical Networks
Security Insights for Mission-Critical NetworksSecurity Insights for Mission-Critical Networks
Security Insights for Mission-Critical Networks
Forcepoint LLC
 
Maintaining Visibility and Control as Workers and Apps Scatter
Maintaining Visibility and Control as Workers and Apps ScatterMaintaining Visibility and Control as Workers and Apps Scatter
Maintaining Visibility and Control as Workers and Apps Scatter
Forcepoint LLC
 
Embracing the Millennial Tsunami
Embracing the Millennial TsunamiEmbracing the Millennial Tsunami
Embracing the Millennial Tsunami
Forcepoint LLC
 
Shift the Burden
Shift the BurdenShift the Burden
Shift the Burden
Forcepoint LLC
 

More from Forcepoint LLC (20)

Rethinking the concept of trust (DoDIIS 2019 presentation)
Rethinking the concept of trust (DoDIIS 2019 presentation)Rethinking the concept of trust (DoDIIS 2019 presentation)
Rethinking the concept of trust (DoDIIS 2019 presentation)
 
Sparking Curiosity to Change Security Behaviors
Sparking Curiosity to Change Security BehaviorsSparking Curiosity to Change Security Behaviors
Sparking Curiosity to Change Security Behaviors
 
Understanding the "Intelligence" in AI
Understanding the "Intelligence" in AIUnderstanding the "Intelligence" in AI
Understanding the "Intelligence" in AI
 
AI and ML in Cybersecurity
AI and ML in CybersecurityAI and ML in Cybersecurity
AI and ML in Cybersecurity
 
Using Language Modeling to Verify User Identities
Using Language Modeling to Verify User IdentitiesUsing Language Modeling to Verify User Identities
Using Language Modeling to Verify User Identities
 
Driving the successful adoption of Microsoft Office 365
Driving the successful adoption of Microsoft Office 365Driving the successful adoption of Microsoft Office 365
Driving the successful adoption of Microsoft Office 365
 
Securing Beyond the Cloud Generation
Securing Beyond the Cloud GenerationSecuring Beyond the Cloud Generation
Securing Beyond the Cloud Generation
 
Forcepoint Advanced Malware Detection
Forcepoint Advanced Malware DetectionForcepoint Advanced Malware Detection
Forcepoint Advanced Malware Detection
 
Top 5 Information Security Lessons Learned from Transitioning to the Cloud
Top 5 Information Security Lessons Learned from Transitioning to the CloudTop 5 Information Security Lessons Learned from Transitioning to the Cloud
Top 5 Information Security Lessons Learned from Transitioning to the Cloud
 
CASB: Securing your cloud applications
CASB: Securing your cloud applicationsCASB: Securing your cloud applications
CASB: Securing your cloud applications
 
One Year After WannaCry - Has Anything Changed? A Root Cause Analysis of Data...
One Year After WannaCry - Has Anything Changed? A Root Cause Analysis of Data...One Year After WannaCry - Has Anything Changed? A Root Cause Analysis of Data...
One Year After WannaCry - Has Anything Changed? A Root Cause Analysis of Data...
 
GDPR is Here. Now What?
GDPR is Here. Now What?GDPR is Here. Now What?
GDPR is Here. Now What?
 
Addressing Future Risks and Legal Challenges of Insider Threats
Addressing Future Risks and Legal Challenges of Insider ThreatsAddressing Future Risks and Legal Challenges of Insider Threats
Addressing Future Risks and Legal Challenges of Insider Threats
 
A Predictive “Precrime” Approach Requires a Human Focus
A Predictive “Precrime” Approach Requires a Human FocusA Predictive “Precrime” Approach Requires a Human Focus
A Predictive “Precrime” Approach Requires a Human Focus
 
Cyber Convergence, Warfare and You
Cyber Convergence, Warfare and YouCyber Convergence, Warfare and You
Cyber Convergence, Warfare and You
 
Securing the Global Mission: Enabling Effective Information Sharing (DoD MPE-IS)
Securing the Global Mission: Enabling Effective Information Sharing (DoD MPE-IS)Securing the Global Mission: Enabling Effective Information Sharing (DoD MPE-IS)
Securing the Global Mission: Enabling Effective Information Sharing (DoD MPE-IS)
 
Security Insights for Mission-Critical Networks
Security Insights for Mission-Critical NetworksSecurity Insights for Mission-Critical Networks
Security Insights for Mission-Critical Networks
 
Maintaining Visibility and Control as Workers and Apps Scatter
Maintaining Visibility and Control as Workers and Apps ScatterMaintaining Visibility and Control as Workers and Apps Scatter
Maintaining Visibility and Control as Workers and Apps Scatter
 
Embracing the Millennial Tsunami
Embracing the Millennial TsunamiEmbracing the Millennial Tsunami
Embracing the Millennial Tsunami
 
Shift the Burden
Shift the BurdenShift the Burden
Shift the Burden
 

Recently uploaded

JMeter webinar - integration with InfluxDB and Grafana
JMeter webinar - integration with InfluxDB and GrafanaJMeter webinar - integration with InfluxDB and Grafana
JMeter webinar - integration with InfluxDB and Grafana
RTTS
 
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Jeffrey Haguewood
 
To Graph or Not to Graph Knowledge Graph Architectures and LLMs
To Graph or Not to Graph Knowledge Graph Architectures and LLMsTo Graph or Not to Graph Knowledge Graph Architectures and LLMs
To Graph or Not to Graph Knowledge Graph Architectures and LLMs
Paul Groth
 
UiPath Test Automation using UiPath Test Suite series, part 3
UiPath Test Automation using UiPath Test Suite series, part 3UiPath Test Automation using UiPath Test Suite series, part 3
UiPath Test Automation using UiPath Test Suite series, part 3
DianaGray10
 
Key Trends Shaping the Future of Infrastructure.pdf
Key Trends Shaping the Future of Infrastructure.pdfKey Trends Shaping the Future of Infrastructure.pdf
Key Trends Shaping the Future of Infrastructure.pdf
Cheryl Hung
 
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
DanBrown980551
 
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdf
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdfSmart TV Buyer Insights Survey 2024 by 91mobiles.pdf
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdf
91mobiles
 
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
Product School
 
Search and Society: Reimagining Information Access for Radical Futures
Search and Society: Reimagining Information Access for Radical FuturesSearch and Society: Reimagining Information Access for Radical Futures
Search and Society: Reimagining Information Access for Radical Futures
Bhaskar Mitra
 
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
BookNet Canada
 
ODC, Data Fabric and Architecture User Group
ODC, Data Fabric and Architecture User GroupODC, Data Fabric and Architecture User Group
ODC, Data Fabric and Architecture User Group
CatarinaPereira64715
 
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Thierry Lestable
 
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdfFIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance
 
The Art of the Pitch: WordPress Relationships and Sales
The Art of the Pitch: WordPress Relationships and SalesThe Art of the Pitch: WordPress Relationships and Sales
The Art of the Pitch: WordPress Relationships and Sales
Laura Byrne
 
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered QualitySoftware Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Inflectra
 
When stars align: studies in data quality, knowledge graphs, and machine lear...
When stars align: studies in data quality, knowledge graphs, and machine lear...When stars align: studies in data quality, knowledge graphs, and machine lear...
When stars align: studies in data quality, knowledge graphs, and machine lear...
Elena Simperl
 
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
UiPathCommunity
 
Designing Great Products: The Power of Design and Leadership by Chief Designe...
Designing Great Products: The Power of Design and Leadership by Chief Designe...Designing Great Products: The Power of Design and Leadership by Chief Designe...
Designing Great Products: The Power of Design and Leadership by Chief Designe...
Product School
 
Accelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish CachingAccelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish Caching
Thijs Feryn
 
The Future of Platform Engineering
The Future of Platform EngineeringThe Future of Platform Engineering
The Future of Platform Engineering
Jemma Hussein Allen
 

Recently uploaded (20)

JMeter webinar - integration with InfluxDB and Grafana
JMeter webinar - integration with InfluxDB and GrafanaJMeter webinar - integration with InfluxDB and Grafana
JMeter webinar - integration with InfluxDB and Grafana
 
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
 
To Graph or Not to Graph Knowledge Graph Architectures and LLMs
To Graph or Not to Graph Knowledge Graph Architectures and LLMsTo Graph or Not to Graph Knowledge Graph Architectures and LLMs
To Graph or Not to Graph Knowledge Graph Architectures and LLMs
 
UiPath Test Automation using UiPath Test Suite series, part 3
UiPath Test Automation using UiPath Test Suite series, part 3UiPath Test Automation using UiPath Test Suite series, part 3
UiPath Test Automation using UiPath Test Suite series, part 3
 
Key Trends Shaping the Future of Infrastructure.pdf
Key Trends Shaping the Future of Infrastructure.pdfKey Trends Shaping the Future of Infrastructure.pdf
Key Trends Shaping the Future of Infrastructure.pdf
 
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
 
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdf
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdfSmart TV Buyer Insights Survey 2024 by 91mobiles.pdf
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdf
 
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
 
Search and Society: Reimagining Information Access for Radical Futures
Search and Society: Reimagining Information Access for Radical FuturesSearch and Society: Reimagining Information Access for Radical Futures
Search and Society: Reimagining Information Access for Radical Futures
 
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
 
ODC, Data Fabric and Architecture User Group
ODC, Data Fabric and Architecture User GroupODC, Data Fabric and Architecture User Group
ODC, Data Fabric and Architecture User Group
 
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
 
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdfFIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
 
The Art of the Pitch: WordPress Relationships and Sales
The Art of the Pitch: WordPress Relationships and SalesThe Art of the Pitch: WordPress Relationships and Sales
The Art of the Pitch: WordPress Relationships and Sales
 
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered QualitySoftware Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
 
When stars align: studies in data quality, knowledge graphs, and machine lear...
When stars align: studies in data quality, knowledge graphs, and machine lear...When stars align: studies in data quality, knowledge graphs, and machine lear...
When stars align: studies in data quality, knowledge graphs, and machine lear...
 
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
 
Designing Great Products: The Power of Design and Leadership by Chief Designe...
Designing Great Products: The Power of Design and Leadership by Chief Designe...Designing Great Products: The Power of Design and Leadership by Chief Designe...
Designing Great Products: The Power of Design and Leadership by Chief Designe...
 
Accelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish CachingAccelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish Caching
 
The Future of Platform Engineering
The Future of Platform EngineeringThe Future of Platform Engineering
The Future of Platform Engineering
 

Weary Warriors: Reducing the Impact of Wishful Thinking & Fatigue on Information Security Decisions

  • 1. Dr. Margaret Cunningham, Principal Research Scientist Forcepoint, X-Labs Weary Warriors: Reducing the Impact of Wishful Thinking & Fatigue on Information Security Decisions 4 June, 2019
  • 2. Weary Warriors: Reducing the Impact of Wishful Thinking & Fatigue on Information Security Decisions Select the option that fits you best: - I use the exact same password on multiple sites. ¯_(ツ)_/¯ - I change my passwords a little bit—Password1! is different from Passw0rd, right? - I never reuse passwords. - I use a password manager. Slido Q1
  • 3. Weary Warriors: Reducing the Impact of Wishful Thinking & Fatigue on Information Security Decisions 40-50% of users reuse passwords
  • 4. Weary Warriors: Reducing the Impact of Wishful Thinking & Fatigue on Information Security Decisions 46% of organizations don’t change their security strategy after an attack!
  • 5. Weary Warriors: Reducing the Impact of Wishful Thinking & Fatigue on Information Security Decisions Definitions & Outcomes • Motivated Reasoning • Decision Fatigue Strategies & Solutions Overview
  • 6. Weary Warriors: Reducing the Impact of Wishful Thinking & Fatigue on Information Security Decisions • “Wishful Thinking” and self- deception • Avoidance of cognitive dissonance • Evaluating problems in favor of preferred outcomes Motivated Reasoning is…
  • 7. Weary Warriors: Reducing the Impact of Wishful Thinking & Fatigue on Information Security Decisions • Inadequate solutions based on biased information • Aversion to change • Rationalization, and denial, of poor choices Impact of Motivated Reasoning
  • 8. Weary Warriors: Reducing the Impact of Wishful Thinking & Fatigue on Information Security Decisions • Decision-making draws on finite mental resources • Our capabilities degrade over the course of each day • Helped by food, cured by rest Decision Fatigue is…
  • 9. Weary Warriors: Reducing the Impact of Wishful Thinking & Fatigue on Information Security Decisions • Decision avoidance, relying on defaults or “status quo” • Difficulty weighing pros & cons of multiple options • Short-term > long-term • Selecting the least effortful choice Impact of Decision Fatigue
  • 10. Weary Warriors: Reducing the Impact of Wishful Thinking & Fatigue on Information Security Decisions • When faced with “facts that don’t fit” we ignore them • When fatigued, we pick the easy way out – if we make a choice at all Motivated Reasoning + Decision Fatigue = Bad Decisions
  • 11. Weary Warriors: Reducing the Impact of Wishful Thinking & Fatigue on Information Security Decisions Strategies & Solutions 1. Recognize the Signs 2. Be Choosy about Choosing 3. Plan & Prioritize
  • 12. Weary Warriors: Reducing the Impact of Wishful Thinking & Fatigue on Information Security Decisions • Impaired self-control & impulsivity • Procrastination • Decision avoidance • Irritability • Ignoring contradicting opinions or facts? Recognize the Signs
  • 13. Weary Warriors: Reducing the Impact of Wishful Thinking & Fatigue on Information Security Decisions • Cut options • Concrete examples • Categorize • Condition for Complexity Be Choosy about Choosing1 1 Sheena Iyengar, “The Art of Choosing”
  • 14. Weary Warriors: Reducing the Impact of Wishful Thinking & Fatigue on Information Security Decisions • Plan daily decisions in advance • Prioritize important decisions for the morning • Sleep on it – when possible • Use tools & establish decision-making processes to support unplanned or late- day choices Plan & Prioritize
  • 15. Weary Warriors: Reducing the Impact of Wishful Thinking & Fatigue on Information Security Decisions 5 KEY TAKE AWAYS
  • 16. Weary Warriors: Reducing the Impact of Wishful Thinking & Fatigue on Information Security Decisions • Motivated reasoning leads to biased decision making & denial of alternative solutions that differ from existing practices • Decision fatigue leads to decision avoidance, or selection of easier, short-term solutions • Recognize the signs: procrastination, distraction, impulsivity, irritability, risk-aversion • Use choice strategies: cut, categorize, concrete examples, & conditioning for complexity • And, when possible, plan and prioritize to optimize decision-making 5 KEY TAKE AWAYS
  • 17. Weary Warriors: Reducing the Impact of Wishful Thinking & Fatigue on Information Security Decisions Follow-up questions or comments? Margaret.Cunningham@Forcepoint.com Or, visit my Forcepoint Author Page: www.forcepoint.com/company/biographies/margaret-cunningham Recent White Papers: Exploring the Grey Space of Cybersecurity with Insights from Cognitive Science Thinking about Thinking: Exploring Bias in Cybersecurity with Insights from Cognitive Science