{"id":4270,"date":"2024-07-01T09:00:00","date_gmt":"2024-07-01T14:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/cyber-risk\/thinking-about-security-fast-slow"},"modified":"2024-07-01T09:00:00","modified_gmt":"2024-07-01T14:00:00","slug":"thinking-about-security-fast-slow","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/07\/01\/thinking-about-security-fast-slow\/","title":{"rendered":"Thinking About Security, Fast &amp; Slow"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt225c6a1c061bfc6e\/667f10e5247dd74dbe85ff28\/Slow%281800%29_Shawn_Lee_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/thinking-about-security-fast-slow.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/thinking-about-security-fast-slow.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">COMMENTARY<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Psychology professor <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/kahneman.scholar.princeton.edu\" rel=\"noopener\">Daniel Kahneman<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> recently passed away. His most famous book, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_italic\">Thinking Fast and Slow,<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> discusses how we have two methods of thinking \u2014 one based on immediate reactions and instinct, and another that is slower, more logical and considered. This book can encourage us to look at how we think through our tactics, operations, and strategic plans, and where we can improve them using psychology and human understanding. For example, how can we understand these modes of thinking and use them to achieve our strategic goals <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\" rel=\"noopener\">around managing risk<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">? More importantly, can we change our approaches and get the best of both modes of thinking?<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As chief information security officers (CISOs), we have to have our long-term goals around risk in mind all the time. Keeping our organization secure and company data protected encompasses a range of different skills, forethought, and planning. At the same time, IT security teams face daily changes in the threat landscape, as new issues are discovered, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/fresh-ransomware-gangs-emerge-victims-decline-market-leaders\" rel=\"noopener\">new ransomware gangs launch their activities<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, and older threats rise and fall in importance. Responding to patches needs to be done quickly in order to keep ahead of potential exploitation and weaponization \u2014 according to our <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/blog.qualys.com\/vulnerabilities-threat-research\/2023\/12\/19\/2023-threat-landscape-year-in-review-part-one\" rel=\"noopener\">research<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, the average time to patch is around 30 days.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Weaponization for the biggest vulnerabilities in 2023 had a mean time of 44 days, so in theory, taking a slow approach and getting things right should be the order of the day. However, around a quarter of weaponized threats appeared on the same day that the patch was released. Fast order thinking is therefore necessary to prevent these attacks, yet this can be hard to achieve across large organizations where tasks are distributed across departments.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Managing risk involves long-term planning and short-term response to fast-changing parameters. The biggest mistake is missing where planning ahead is required to make reactions easier and more effective. One CISO mentioned to me that he feels like he is trapped in a hamster wheel, forever running but not getting where he needs to go. Instead, we have to unify our view of risk so that we can make the right decisions in context.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"IT Infrastructure, Fast and Slow\">IT Infrastructure, Fast and Slow<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Enterprises have very different IT platforms in place. Traditional IT assets in data center environments will rub shoulders with new cloud-native applications and containerized systems where the average lifespan for a container is around five minutes. All of these systems will have to be managed and kept secure, but the thinking and processes that take place around them typically call for different mindsets.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Traditional IT assets typically are high-value investments that will not be replaced for years. These systems are often responsible for revenue-generating activities, and businesses will not be willing to take them out of commission for downtime and updates to be applied. These systems have to be protected against threats, yet the threat of them being affected by downtime is seen as an even bigger risk to the business. The theoretical threat of a missed patch has to be compared with the very real risk of lost revenue. In these circumstances, taking that logical and methodical approach to measuring risk will be necessary.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For modern applications, adopting a slower approach will not keep up with the sheer pace of change taking place. Security processes have to respond automatically when required. As any changes take place within our CI\/CD pipelines, our security processes should react in line.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Managing Risk Means Thinking Fast and Slow Together\">Managing Risk Means Thinking Fast and Slow Together<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For CISOs, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/how-can-your-security-team-help-developers-shift-left\" rel=\"noopener\">approaches like shift-left security<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> should allow developers to improve security over their code and their pipelines. Yet these approaches rely on collaboration between security and developer teams to work. Saying that you have shifted security left is one thing; actually making the changes in working practices is another. What looks like a quick win and a way to automate security effectiveness actually relies on slow and methodical thinking around collaboration.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The greatest challenge here is that managing risk demands both fast responses and strategic thinking to be effective. Plans made in the past may have to shift based on new evidence, while the ability to react quickly may depend on decisions around areas like infrastructure taken years before.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">To reduce risks, CISOs have to understand issues in context and score them appropriately. Getting a single score helps categorize risks against each other. You can then solve those issues based on the most effective measure, whether that is fast order responses or more strategic changes over time. You can get off the hamster wheel and concentrate on longer-term results. By looking at security with both a fast and a slow mindset, we can try to achieve the best of both worlds.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyber-risk\/thinking-about-security-fast-slow\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>COMMENTARY Psychology professor Daniel Kahneman recently passed away. His most<\/p>\n","protected":false},"author":12,"featured_media":4271,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4270","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/thinking-about-security-fast-slow.jpg?fit=1801%2C1013&ssl=1",1801,1013,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/thinking-about-security-fast-slow.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/thinking-about-security-fast-slow.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/thinking-about-security-fast-slow.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/thinking-about-security-fast-slow.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/thinking-about-security-fast-slow.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/thinking-about-security-fast-slow.jpg?fit=1801%2C1013&ssl=1",1801,1013,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/thinking-about-security-fast-slow.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/thinking-about-security-fast-slow.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/thinking-about-security-fast-slow.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/thinking-about-security-fast-slow.jpg?fit=1801%2C1013&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4270","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4270"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4270\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4271"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4270"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4270"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4270"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}