{"id":6037,"date":"2024-10-23T20:53:28","date_gmt":"2024-10-24T01:53:28","guid":{"rendered":"https:\/\/www.darkreading.com\/threat-intelligence\/the-overlooked-importance-of-identifying-riskiest-users"},"modified":"2024-10-23T20:53:28","modified_gmt":"2024-10-24T01:53:28","slug":"the-overlooked-importance-of-identifying-riskiest-users","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/10\/23\/the-overlooked-importance-of-identifying-riskiest-users\/","title":{"rendered":"The Overlooked Importance of Identifying Riskiest Users"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt7bfcab458b58ba4e\/6719ae978793692183bb0cd3\/gators-Ben3images-alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/the-overlooked-importance-of-identifying-riskiest-users.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/the-overlooked-importance-of-identifying-riskiest-users.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">COMMENTARY<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In healthcare, the &#8220;see one, teach one, do one&#8221; model refers to an incremental learning process: Trainees first observe a procedure, then learn to teach it to others, then perform it themselves. This framework can be applied to cybersecurity by encouraging employees, especially those identified as high-risk users, to progress through a similar cycle of observation and education, followed by a combination of tool implementation and practice. This approach fosters a deep understanding of cybersecurity risks, increases tool efficiency, and empowers users to mitigate risks actively.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As organizations accumulate a growing array of cybersecurity tools, many fail to consider that their riskiest users can be the weakest link in their defenses. Reach Security&#8217;s analysis reveals that 80% to 90% of threats relate to just 3% to 5% of the organization&#8217;s user population. This is further complicated if you consider that roughly 20% of the users in a company&#8217;s most attacked group change monthly.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">These users, whether high-profile executives, employees with privileged access, or those who engage in risky behavior, have the potential to cause significant damage, either through negligence or intentional actions.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">By focusing on high-risk individuals, organizations can address the root causes of many cybersecurity threats, allowing them to allocate resources more effectively and reduce reliance on sprawling security tools that attempt to protect everyone equally.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">When it comes to managing the riskiest users, the &#8220;see one, teach one, do one&#8221; methodology can guide a more <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/human-centric-security-model-meets-people-where-they-are\" rel=\"noopener\">human-centered approach to cybersecurity<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. This model can be applied to not only help users understand the risks they face but also enable them to become advocates for cybersecurity within the organization. It also it reduces overall risk and tool sprawl.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"See One: Observation and Awareness\">See One: Observation and Awareness<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The first stage of the process is to identify the most attacked people (MAP), which can be done using a solution that provides visibility into the data that teams already have in place. For instance, syncing the central record of identity (e.g. Active Directory, Azure Active Directory, Google Workspace, Okta) can uncover high-risk user data.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Once these high-risk users \u2014 such as CEOs, senior executives, and IT personnel with elevated privileges \u2014 are identified, security teams can provide personalized demonstrations of how they might be targeted, showcasing real-world examples, such as phishing emails tailored to executives or potential data breaches from insecure networks. In addition, executives can observe how inadequate use of multifactor authentication (MFA) or improper handling of sensitive data can increase their exposure to threats.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The &#8220;see one&#8221; stage is crucial for both identifying the MAP and helping those users gain a baseline awareness of the specific threats they face.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Teach One: Educating Others\">Teach One: Educating Others<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In the second phase, high-risk users transition from observers to educators. The &#8220;teach one&#8221; phase helps break down silos within an organization by fostering a shared responsibility for cybersecurity. For instance, an executive who has learned the dangers of targeted phishing can then relay that information to their team, strengthening collective awareness.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Teaching cybersecurity concepts to others creates a ripple effect, reducing the reliance on technical tools by embedding good security practices into the organization&#8217;s daily behavior.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Do One: Practice and Implementation\">Do One: Practice and Implementation<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Finally, the &#8220;do one&#8221; phase focuses on real-world application. Organizations face the dual challenge of pinpointing high-risk users and integrating data from multiple security tools to monitor these risks over time. This can be further complicated by the necessity to continuously update and enhance security measures across the enterprise to stay ahead of evolving threats. With <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/unprecedented-cloud-giants-feds-team-unified-security-intelligence\" rel=\"noopener\">continuous monitoring<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, teams can better identify and track shifts in the threat landscape, ensuring that those in the MAP are always under watch. Finally, putting forth a holistic security strategy that is both user- and device-aware will ensure that protective measures are as personalized and effective as possible.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Knowing where risk lives introduces an ability to focus. An ability to focus allows teams to see the biggest impact on the smallest number of folks. From there that focus group learns and teaches. Once they have knowledge, they&#8217;re open to ways in which they can be protected \u2014 and can use the security controls in the most efficient ways possible.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"A Different Approach to Risk-Based Management\">A Different Approach to Risk-Based Management<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Managing human-based cybersecurity risk requires a shift toward a more focused strategy that considers the riskiest users in your organizations. By identifying and supporting the riskiest users with the &#8220;see one, teach one, do one&#8221; model, organizations can reduce vulnerabilities where they matter most.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/the-overlooked-importance-of-identifying-riskiest-users\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>COMMENTARY In healthcare, the &#8220;see one, teach one, do one&#8221;<\/p>\n","protected":false},"author":12,"featured_media":6038,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-6037","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/the-overlooked-importance-of-identifying-riskiest-users.jpg?fit=1800%2C1013&ssl=1",1800,1013,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/the-overlooked-importance-of-identifying-riskiest-users.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/the-overlooked-importance-of-identifying-riskiest-users.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/the-overlooked-importance-of-identifying-riskiest-users.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/the-overlooked-importance-of-identifying-riskiest-users.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/the-overlooked-importance-of-identifying-riskiest-users.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/the-overlooked-importance-of-identifying-riskiest-users.jpg?fit=1800%2C1013&ssl=1",1800,1013,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/the-overlooked-importance-of-identifying-riskiest-users.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/the-overlooked-importance-of-identifying-riskiest-users.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/the-overlooked-importance-of-identifying-riskiest-users.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/the-overlooked-importance-of-identifying-riskiest-users.jpg?fit=1800%2C1013&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/6037","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=6037"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/6037\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/6038"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=6037"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=6037"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=6037"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}