Title
Safer Data: Awareness and Cybersecurity
Team Members
Nailah Clinton and Lenz Bayas
Short Summary of your improvement idea
Our initiative looks to challenge what constitutes awareness and related action within cybersecurity. Ever-evolving approaches by those seeking to cause data breaches within enterprise security systems are on the rise. We see a need to reconsider existing data breach prevention thinking on the part of companies by challenging the existing paradigm upon which they are built.
Q&A
What is the existing target protocol you are hoping to improve or enhance?
The existing target protocol is data breach prevention. Despite significant investments in network systems infrastructure, key stakeholders can overlook the ever-present human component of security within traditional cybersecurity frameworks.
What is the core idea or insight about potential improvement you want to pursue?
Our idea is centered on the belief that there is much to be gained by developing a framework viewing humans as being both prone to error (i.e. liabilities) as well as sources of safety & protection (i.e. assets) within workplace settings. While the former showcases a bias towards preventing workers from making errors, the latter takes on a more human-centered approach, focused on humans anticipating and building off of success.
What is your discovery methodology for investigating the current state of the target protocol?
We will focus our energies partially on historical data and failure event analysis, paying special attention to the circumstances that surround data breaches as a result of social engineering. We will explore situations that could be termed as “near misses” - instances where a data breach almost occurred, but ultimately didn’t. In the latter case, the thinking is simple here: “What went right?”
In what form will you prototype your improvement idea?
Our prototype will comprise a draft proposal share with experts for feedback. The proposal will take on the form of action research to be used in tandem with other approaches deemed to be complementary.
How will you field-test your improvement idea?
Our field testing will initially take on the form of a workshop inviting participants from a broad cross-section of industries. As the work is centered on building awareness and promoting desired action, we’re curious to what extent adaptation of the protocol would be carried out within different industry settings.
Who will be able to judge the quality of your output?
We are targeting cybersecurity and risk management experts in particular. While we realize and respect the cross-cutting nature of our work, we choose to emphasize enterprises as opposed to, say, law and regulatory bodies…among other actors.
How will you publish and evangelize your improvement idea?
We plan to share our findings in a variety of ways: (1) Submission to an international standards body, and (2) co-authoring and sharing a blog or white paper on our respective company websites.
What is the success vision for your idea?
By reconsidering both awareness and action with a focus on human component, organizations will be better suited to respond to emerging social engineering trends used to commit data breaches in continuously changing work environments.