Protection of Data: CIA-triad
- confidentiality
- integrity
- availability
People are the weakest link → only amateurs attack machines: professionals target people
→ It is becoming increasingly apparent that humans are a major cause of computer security
failures
Introduction to behavioral change
If people were rational
→ improving security behaviour by:
- providing information
- providing arguments
- “increasing awareness”
→ no one would use the same password twice
→ never a successful phishing scam
→ no ransomware attacks
→ awareness campaigns
However: “It would be easy to give the public information and hope that they change
behaviour but we all know that doesn’t work very satisfactorily. Otherwise none of us would
be obese, none of us would smoke, and none of us would drive like lunatics.” (Potter, 2007)
Principles of psychology
- why we do what we do
- why we think what we think
- why we feel what we feel
→ trying to make sense of human behaviour
→ black swan approach philpsophy and psychology (= a strategy of acknowledging that
highly improbable, unforeseen events (black swans) can have a massive impact and
preparing for their consequences)
→ behavioural change mostly focuses on ‘doing’ and ‘thinking’
- why do we use the same password on various websites? & why do we think we won’t
be victims of phishing attacks?
Social psychology and behavioural change
- took flight after WWII
- attempted to answer questions like: what made the holocaust possible? why did no
one stop them sooner? etc.
- initial studies on authority as a way to influence behaviour
Milgram’s obedience to authority (...)
The asch experiment → Asch's conformity experiments are a series of experiments in the
field of normative social influence, within social psychology, which demonstrated the extent
to which people's opinions are determined by the majority in a group (conformism).
,Social influence
→ behaviour does not occur in a vacuum
→ people are affected by their social situation
- others
- situation
- physical environment
→ fundamental attribution error
- who cares about the situation>
Cialdini: six weapons of influence (reframed as 7)
→ data driven approach
→ how do companies persuade consumers?
- telemarketing
- car salesmen
- etc.
1. Authority
→ formal or informal authority?
→ mostly a matter of perception
→ standalone technique or prerequisite?
Authority in cybersecurity:
- bring in the experts!
- but who is considered and expert?
- system updates on windows/macos?
- social engineering & scams
2. social proof: normative influence:
→ herd behaviour/followng the majority
→ edition X is the most popular among customers
→ 80% of people who stayed in this hotel room reused their towels
Social proof in cyber security:
- facebook stdy with 50.000 participants
- different security messages: “keep your account safe”
- measurement: do people explore security options more when presented with social
proof?
- answer: yes , 37% more explorers
3. Liking
→ the more we like someone the more “likely” we are to act
→ ways of influencing through liking:
- be friendly
- similarity (e.g. birthdate)
- mimicry (e.g. posture, verbal)
Liking in cybersecurity
- stories from people who are similar to you
- able to identify yourself with others
- e.g. stories from CSM students who were victims of a phishing scam, rather than
physics students at a US uni
, 4. Scarcity
→ restricting access increases wanting
→ FOMO
→ time limits
→ stock limits
Scarcity in cybersecurity
→ limit free resources (at first)
→ often used in scams
→ more research is needed!
5. COmmitment and consistency
→ people dislike being inconsistent
→ once people commit, they are more likely to act
→ public commitment → e.g. signing up to things (smoking posters)
→ foot in the door technique (billboards, turfmarkt)
COmmitment and consistency in cybersecurity
→ Don’t expect people to do everything at once.
→ Let them (publicly) commit to cyber security.
→ Make it easy to be consistent. (Streamline processes)
→ Sign up to something, then commit to broader policy
6. Reciprocity
→ tit for tat
→ we reciprocate favours, gifts, other niceties
→ waiters in restaurants → receiving chocolate increases tipping behavior
→ “that’s not all” technique → additional efforts is reciprocated in increased likelihood
of sale
Reciprocity in cybersecurity
→ What can you give people in return for good cyber behavior?
- better services, CIA-triad, other rewards?
- message framing when IT services need people to update/install/change settings
, Lecture 2 - The PATHS Model
→ Current situation
- So you know a lot about behavioral change? You see, I’ve got this problem with a
client/employee/friend/relative…”
• Big focus on solution
• Three requirements:
- Solution that works for everyone, all the time.
- Behavioural change is cheap? We want it to cost €0,-
- You’ve got five minutes.
• We need a transition from solution to understanding
PATHS Model
→ problem = from a problem to a problem definition
→ analysis = from a problem definition to analysis and explanation
→ testing = from explanations to a process model
→ help = from a process model to intervention
→ success = did it work?
Problem
→ so what is the problem exactly?
→ Find out by answering six questions:
- what is the problem?
- why is it a problem?
- for whom is it a problem?
- what causes the problem?
- what is the target group?
- What are keys aspects of the problem?
→ based on these 6 questions, you can decide what your focus will be
→ what is the end goal? changing attitude, intentions, behaviour?
→ what behaviour should you focus on changing?
Analysis
→ do science!
→ link the findings of the problem-stage to scientific literature
→ what are the relevant theories?
→ which human factors do you need to take into consideration?
→ what about possible situational factors?
→ why does it happen?
→ can we understand the mechanics of it?
→ there is no need to reinvent the wheel: what has been written about your problem?
→ which concepts are related to the problem?
Testing
→ is there research on possible causes?
→ how are the relevant concepts/causes related?
→ can you find interventions that were effective? (slightly different target groups/related
behaviours) → if so, what did they target?
→ knowing the relevant aspects, can we create a process model?