Security Psychology – or Risk Gambler?

  The human factor is always underappreciated in helping decide on what can be done with our Computer Security. “Security Mental Model: Cognitive map approach” Tahani Albalawi, Kambiz Ghanzinour and Austin Melton paper: The computer security community has developed formal methods for providing security properties to systems and organizations. However, the human role has often … Read more

Complacency and Cybersecurity Awareness

Are we being too complacent in our feeling of “nothing will happen to us” with regard to Cybersecurity? 2 stories tie this theme together: Phishing awareness training  wears off after a few months Apparently retraining is required after 6 months. Ransomware and Observations from Recent IR investigations Businesses are still getting ransomware, not how it … Read more

Is Psychology of Security Causing Cybersecurity Problems?

What do I mean by Cybersecurity problems?  How about not patching  or upgrading your devices, taking inventory of your devices.  Making changes to the network or systems and not thinking about security. Or just plain old errors, mistakes, issues that arise after something new happens. Why would we not pay attention to these things? What … Read more

Are DeepFakes something to Worry About?

Deepfakes are  computer generated images and footage of real people. I.e. a computer generated images or video from a program (or algorithm).  FireEye has a paper that discusses this phenomenon: https://www.fireeye.com/blog/threat-research/2020/08/repurposing-neural-networks-to-generate-synthetic-media-for-information-operations.html? Instead of talking theory and what happens once the cat is out of the bag, let’s give some good examples: https://www.wsj.com/articles/fraudsters-use-ai-to-mimic-ceos-voice-in-unusual-cybercrime-case-11567157402 “Criminals used artificial … Read more