Fresh Thoughts #63: The Power of Experiences

    Newsletter
Soldering Iron

The Power of Experiences

Many years ago, I had a colleague while studying Electronic Engineering at university. He was proud that he had never used a soldering iron - in four years of study.

He claimed he didn't need to, as he was looking forward to a career in consulting.
"Telling. Not doing."

But in the final hours of a group project competition, I utter the fateful words...
"Please, can you pass me that soldering iron?".
He picked up the wrong end.

At that moment, I recognised the difference between book knowledge and experience.

This incident shaped my early career.
It was not enough to learn from a book. It was essential to do.
And that's why I worked in cyber operations in those early years.

I still have scars on my hands from sharp edges in computer cases. And see the value in the emotional experience of a situation as much as the problem described with words on a page.

Simulated Experiences

It's impossible to have the time to experience all critical situations organically. And that's why simulations are so helpful for learning.

They create experiences similar to those from an actual situation but without the consequences.

Over the years, I've been through media training simulations that included "tough questioning" from retired journalists. And I'm glad I didn't experience that live on air.

Similarly, clicking on a phishing simulation drives the adrenaline of - "Damn. I got caught out." without the weeks of clean-up that come from it.

And I've talked previously about the first time I thought I had been hacked.

But what about when things go wrong?

Crisis Simulations & Congressional Hearings

As a business leader, understanding what the situation will entail can be challenging.

Crisis management simulations and incident response tabletop exercises are crucial to mature cybersecurity programmes. But what if your business isn't mature enough to run these annually?

Learn from others.
And practice your responses to their situation.

On Friday, I saw a clip of a US Congressional committee questioning an executive about a data breach. It gave a fantastic insight into the intensity and type of questions asked after a breach.

Imagine you've just lost over 56,000 sets of sensitive personal data. How would you respond to these 10 questions?

  1. Is this a password issue with authentication on the server? What actually happened?
  2. How long was the server misconfigured?
  3. So the server was exposed starting in 2018?
  4. Had it changed at all in that timeframe?
  5. Up to how many people could potentially have been exposed then from this breach?
  6. Are employees required to use a quote "strong password" when creating authentication within the programs you all use?
  7. Is it required, or is it just encouraged?
  8. As a matter of company policy, do you require two-factor authentication for company passwords used by employees or contractors?
  9. How long has that been going on?
  10. Will you fire the contractor or employee who created this breach issue? Will they be fired?


Here's how Mila Kofman - the witness - responded.

On balance, I think she answered and deflected the questions reasonably well.
But I am surprised that 6 weeks after the discovery, the answers weren't based on more known facts.

...and yes, deflection and bridging are crucial to answering these questions in public.

April 25, 2023
3 Minutes Read

Related Reads

father helping son observe

Fresh Thoughts #49: How Do You Respond? OODA

This is the model I use to respond to all types of cybersecurity and business situations... OODA.

Fresh Thoughts to Your Inbox

Fresh perspectives on cybersecurity every Tuesday. Real stories, analytical insights, and a slash through buzzwords.

We'll never share your email.

Subscribe to Fresh Thoughts

Our weekly newsletter brings you cybersecurity stories and insights. The insights that help you cut through the bull.

We'll never share your email.

Resources

Fresh Security Support

Your Questions

Blog

Fresh Sec Limited

Call: +44 (0)203 9255868