{"id":4359,"date":"2024-07-08T09:00:00","date_gmt":"2024-07-08T14:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/cybersecurity-operations\/5-ways-to-run-security-as-a-meritocracy"},"modified":"2024-07-08T09:00:00","modified_gmt":"2024-07-08T14:00:00","slug":"5-ways-to-run-security-as-a-meritocracy","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/07\/08\/5-ways-to-run-security-as-a-meritocracy\/","title":{"rendered":"5 Ways to Run Security as a Meritocracy"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltd6965c6649c777c8\/667f37713e9e356f7c11964c\/missioncontrol%281800%29-Science_History_Images-alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/5-ways-to-run-security-as-a-meritocracy.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/5-ways-to-run-security-as-a-meritocracy.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">I remember watching the space shuttle Challenger launch as a child. The launch was highly anticipated, and my fellow classmates and I gathered in the school cafeteria to watch the one television that had been placed there and connected to broadcast signals. In 73 seconds, wonder turned to amazement, which turned to confusion, which turned to horror. I will never forget it.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">According to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/en.wikipedia.org\/wiki\/Space_Shuttle_Challenger\" rel=\"noopener\">Wikipedia<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, &#8220;The cause of the disaster was the failure of the primary and secondary redundant O-ring seals in a joint in the shuttle&#8217;s right solid rocket booster (SRB).&#8221; Then-President Ronald Reagan subsequently appointed the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/en.wikipedia.org\/wiki\/Rogers_Commission_Report\" rel=\"noopener\">Rogers Commission<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> to investigate what went wrong.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As Wikipedia explains, the commission&#8217;s report &#8220;criticized NASA&#8217;s organizational culture and decision-making processes that had contributed to the accident.&#8221; Despite knowing about a flaw in the O-rings since 1977, &#8220;neither NASA nor SRB manufacturer Morton Thiokol had addressed this known defect. NASA managers also disregarded engineers&#8217; warnings about the dangers of launching in cold temperatures and did not report these technical concerns to their superiors.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In other words, the culture at NASA was plagued by groupthink. Concerns of those on the ground were routinely ignored. People were encouraged to go along with the prevailing winds, rather than stay true to what the data showed. NASA was not a meritocracy, where <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-careers\/to-narrow-the-cyber-skills-gap-with-attackers-cut-the-red-tape\" rel=\"noopener\">advancement is based on achievement<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, creating a very dangerous situation that cost seven people their lives.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">At this point, you might be asking yourself what the Challenger has to do with our field. It is my belief that security, as is the case with many fields, should be a meritocracy. I&#8217;d like to share five ways in which security teams can encourage a security meritocracy to thrive.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"1. Stress the Importance of Actions\">1. Stress the Importance of Actions<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Each of us should be evaluated by what we&#8217;ve done, rather than what we&#8217;ve said. Indeed, it is easy to talk the talk, but far fewer have walked the walk. Solutions, approaches, and ideas that have proved effective should be given more weight than those that sound good in a speech or look good on paper but are untested or ineffective. This should be the case no matter who is speaking \u2014 however popular, charismatic, and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-careers\/5-tips-for-protecting-your-career-against-a-narcissist\" rel=\"noopener\">convincing<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> they may be.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"2. Leave Out Politics\">2. Leave Out Politics<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Politics, by its very nature, divides people, including security teams. I firmly believe that politics has no place in security, particularly when the spectrum of accepted political views seems to narrows with each passing day. The best option is for us as a community is to focus on the strategic, operational, and tactical issues and challenges we face on an ongoing basis, with no mention of politics at all. If, for some reason, politics should find its way into a discussion, it should be pushed aside. If you discover you don&#8217;t like someone&#8217;s politics, get over it \u2014 don&#8217;t let it cloud your judgment when it comes to the ideas they present.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"3. Avoid Groupthink\">3. Avoid Groupthink<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">There is no shortage of historical examples where millions of people thought that an idea was good, only to have history judge otherwise. Mob mentality and groupthink are extremely dangerous. They can lead to poor and biased decisions that harm the security posture of an organization and introduce risk and vulnerabilities. On the flip side, a security program driven by data, logic, and reason will be far more effective and produce far better results.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"4. Ignore Shiny Objects\">4. Ignore Shiny Objects<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">No matter how shiny a new idea may appear, its merits need to speak for themselves, not its hype or who is hyping it. As we know, people can get emotionally invested in and irrationally caught up in the trend du jour. They can also have conflicts of interest. Before considering any new solution, approach, or idea, be sure to validate it. There should be an objective, unbiased way to test its merits before being required to jump in.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"5. Encourage the Right Culture\">5. Encourage the Right Culture<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Staff should feel comfortable suggesting new ideas, different ways of thinking, and novel approaches without fear that they will be ridiculed, mocked, or worse. Otherwise, many people will simply remain quiet, which will cause the organization to miss out on what could be <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/being-flexible-can-improve-your-security-posture\" rel=\"noopener\">great ideas, thoughts, and approaches<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. This is a huge loss for any security team, and with the pace at which the threat landscape evolves, no team can afford it.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Cream Rises to the Top\">Cream Rises to the Top<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Culture influences the effectiveness and success of any organization, including that of a security organization. By <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/training-to-beat-a-bad-cybersecurity-culture\" rel=\"noopener\">creating a culture<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> that is based on a meritocracy, organizations can ensure that they foster an environment where people aren&#8217;t afraid to speak up, ask hard questions, or try different approaches. When people are empowered to do so, everyone benefits, and the pitfalls of groupthink and biased thinking are avoided. This, in turn, leads to a better overall security posture.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/5-ways-to-run-security-as-a-meritocracy\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>I remember watching the space shuttle Challenger launch as a<\/p>\n","protected":false},"author":12,"featured_media":4360,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4359","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/5-ways-to-run-security-as-a-meritocracy.jpg?fit=1800%2C1013&ssl=1",1800,1013,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/5-ways-to-run-security-as-a-meritocracy.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/5-ways-to-run-security-as-a-meritocracy.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/5-ways-to-run-security-as-a-meritocracy.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/5-ways-to-run-security-as-a-meritocracy.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/5-ways-to-run-security-as-a-meritocracy.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/5-ways-to-run-security-as-a-meritocracy.jpg?fit=1800%2C1013&ssl=1",1800,1013,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/5-ways-to-run-security-as-a-meritocracy.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/5-ways-to-run-security-as-a-meritocracy.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/5-ways-to-run-security-as-a-meritocracy.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/5-ways-to-run-security-as-a-meritocracy.jpg?fit=1800%2C1013&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4359","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4359"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4359\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4360"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4359"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4359"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4359"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}