7 Ways To Avoid Poor Decisions In Cybersecurity
In the field of cybersecurity, the ability to think critically and make informed and effective decisions is crucial. However, this is often easier said than done, especially when some situations involve varying levels of stress or pressure. Our brains can take cognitive shortcuts known as 'mental heuristics'.
Though useful in everyday situations, these heuristics can sometimes lead us astray. In a complex field like cybersecurity, our decisions and actions are only as good as the information and knowledge available to us. However, in some cases, we don’t have the luxury of seeing the complete picture, and this is where we often try to leverage a ‘cognitive shortcut’ to help us solve the puzzle or determine the root cause of a problem.
In this article, I will explore seven mental heuristics and how they apply to cybersecurity, providing insights into making better decisions.
1. Anchoring Bias
What is it? Anchoring occurs when individuals rely too heavily on the first piece of information they receive. In decision-making, this initial information sets the tone for everything that follows.
Real-World Example: The Equifax breach in 2017 serves as a classic case. Equifax relied heavily on a legacy vulnerability scanning tool. Despite emerging vulnerabilities and threats, their anchoring to this initial security measure likely contributed to the oversight of the critical Apache Struts vulnerability, leading to the massive breach.
2. Confirmation Bias
What is it? This is the tendency to search for, interpret, and remember information in a way that confirms one's preconceptions.
Real-World Example: In the Sony Pictures hack of 2014, there was an apparent dismissal of the increasing signs of network infiltration and data exfiltration. The belief in their cybersecurity effectiveness might have led to underestimating or disregarding the clear signs of a looming breach.
3. Representativeness Heuristic
What is it? The Representativeness Heuristic is where people estimate the likelihood of an event by comparing it to an existing prototype in their minds. This means judging situations based on their similarity to the stereotypical case, often overlooking other relevant information.
Real-World Example: A notable example (and a personal favourite) is the Stuxnet worm incident. Stuxnet, a sophisticated cyber weapon, was initially underestimated by many cybersecurity experts because it didn't fit the typical profile of malware seen at that time. It was specifically designed to target industrial control systems, particularly those in Iran's nuclear facilities, which was highly unusual.
The novelty of Stuxnet's design and target meant that it didn't match the 'representative' malware usually encountered. This led to its initial undervaluation and allowed it to inflict significant damage before being fully understood and mitigated.
4. Availability Heuristic
What is it? This heuristic involves making decisions based on readily available information or highly publicised events rather than all the necessary data.
Real-World Example: In the wake of the high-profile Target breach in 2013, many companies focused intensely on point-of-sale (POS) security because the POS systems were instrumental in storing credit/debit card information in memory and posed the greatest concern once exposed.
The widespread industry and media focus on retail POS security came potentially at the expense of other areas like email phishing defence, third-party access management or employee awareness training, which are equally important but were less sensationalised in mainstream media then.
5. Bandwagon Effect
What is it? The tendency to do or believe things because they are popular or many other people do or believe the same.
Real-World Example: The rush to adopt cloud services without fully understanding their security implications. Following major players in the industry, smaller companies hastily moved to the cloud, often resulting in data breaches due to misconfigured cloud storage and inadequate security policies.
6. Sunk Cost Fallacy
What is it? Continuing a venture because of previously invested resources (time, money, effort) rather than current rational analysis.
Real-World Example: The Marriott International breach in 2018 can be partly attributed to the sunk cost fallacy. Marriott continued using Starwood’s previously compromised reservation system post-acquisition, potentially due to significant investments in it, leading to one of the largest data breaches at that time.
7. Groupthink
What is it? The practice of thinking or making decisions as a group in a way that discourages creativity or individual responsibility.
Real-World Example: Groupthink is a subtle beast. I could argue that groupthink potentially played a role in any of the above examples to some degree. It is not uncommon for cybersecurity teams to collectively underestimate the likelihood or impact of what they perceive as low-probability threats.
Additionally, there’s a tendency in some organisations to focus more on meeting compliance standards rather than genuinely securing systems. This groupthink approach prioritises checking boxes over assessing real-world vulnerabilities and can lead to a false sense of security.
Conclusion
Recognising these mental heuristics is the first step toward making better decisions in cybersecurity. By being aware of these cognitive shortcuts, cybersecurity professionals can take a more comprehensive and adaptive approach to protecting people and organisations from malicious activity.
The key lies in continuous learning, open-mindedness, and the willingness to challenge our assumptions, ensuring our decisions are as robust and forward-thinking as the technologies we aim to protect.