Make your users work for you

Your users are not your enemy. They’re your greatest asset! While you have “eyes-on-glass” they’re eyes on the world. They’re everywhere. They know everything. They know everyone. And they know when something isn’t right. Help them help you.

Joe got phished and you’re mad. He should be fired! He’s a bad employee! No. Stop that. Joe just learned a lesson, one that is expensive to teach.

Mary let a non-employee through the door without a badge! She should be fired! She’s a bad employee! No. Stop that. Mary is now the most security savvy person at your company, including you.

I’m driving down the road at 85 miles per hour, like I always do. Nothing happens. Tomorrow, I’m driving down the road at 85 mph. Nothing happens. This continues for weeks, until one day I see flashing lights in my mirror. Dang. A quick $175 ticket later, my cruise control is set at 70. I’ve learned my lesson (at least for a while).

I’m zipping in and out of traffic. I’ve done this forever, it’s a quick way to get ahead of everyone else! Except I forgot to check my mirror… boom. That’s a few thousand in damage repairing my fender, and a few thousand more for the car I just hit. But now I might leave home a few minutes earlier and drive a bit slower.

There’s a lesson to be learned in every mistake. If you’re not jumping on those teachable moments, they’re going to waste! And they’re going to happen again. If Joe gets phished and nothing happens, nothing happens. Joe will keep getting phished. If Mary lets in a tailgater and never learns the consequences, she will continue politely destroying your company.

You probably have a security education program. Every quarter, every year maybe, you have your employees watch some video and click a few buttons to there is the checkbox. Security is solved for the next few months and everyone gets back to gossiping about their weekends. But it’s not a big stretch to say this isn’t effective. And maybe there is an untapped resource here…

People like to gossip. And a lot of times, people like to share embarrassing stories about themselves, as long as nothing seriously bad happened. So set up those moments to work for you! There are services out there that will perform phishing tests for you. Use them! They’re super affordable. Because you know what happens when those go out? If Joe catches the phish, he brags. “Hey look at this email, stupid spammers almost got me! Haha” and they laugh and continue on. If he doesn’t catch it, he warns everyone else. “Hey Mary, there’s a stupid email going around, you gotta keep an eye out!” And now it’s not security that’s doing the education. They’re learning from each other.

Now here’s one that is a bit more off-the-wall: hire people to do physical pen-testing. “Freehunter,” you might say, “that’s not off-the-wall, that exists!”. I’m not talking about that. Hire your friends. Hire your family. Hire grandma. Because pentesters are good at their job. They’re there to make sure you know the gaps in your already-security environment which you likely don’t have. But grandma, or uncle Pete, or your college buddy Mike could use some beer (or yarn) money on their day off, and they don’t know jack. That’s a good thing. Because you don’t want someone sneaky, that’s a pentest. You want someone to walk in behind your employees and say “excuse me, where’s the CIO’s office?” You want someone to stand outside a locked door asking passers-by to open it for them. You want someone to ask the security guards if they can borrow their keys. You want someone who obviously does not belong. Who obviously is not authorized to have the information they’re asking for. And you want someone who will work for $50.

Because the point of this exercise is for your pentest to fail. You don’t want them to succeed, you want to shake up your users, to make them understand that attacks can and do happen. You want the employee to say “Hey are you allowed to be here? Do you have a badge?” You want them to call the security guard. And you want your security guards to care. And when the employee successfully stops your pentest, reward them. Recognition, maybe a candy bar or a gift card to Subway, a nice pat on the back. They did good and they learned a lesson and now your users are working for you instead of working against you.

That’s security education.

(Oh I should point out, if you’re doing this… give your makeshift pentester a letter of authorization signed by your boss with your phone number on it. Better yet, stand there and watch the “attack” happen so you can keep the security guard from calling the police and arresting them. And if they’re questioned, they should immediately stop the “attack” and admit this was a test by the security team and call you. You don’t want to bail grandma out of jail!)