Why bring in problems when you can be the solution – turning security monologue into Security Dialogue

Why bring in problems when you can be the solution – turning security monologue into Security Dialogue

Suvi Kaartinen |

In an era of increasingly sophisticated phishing campaigns, security awareness is becoming crucial. Security practitioners are putting effort into creating impressive presentations and e-learning experiences with interaction to tackle this problem. However, many people are still reluctant to change their behaviour. They tend to think that security is an IT thing and that it’s fixed by proper malware protection. But it is not!

I think the main reason for the failure of traditional awareness methods is the direction of the information flow. It’s us, the “wise security folks”, telling the “lesser” end-users what they need to do and how they need to behave before first trying to get them to understand WHY it is important for THEM.

Security Dialogue turns this lonely monologue into true interaction. It is a simple concept based on the well-known “me-we-us” facilitation method, as presented in the following picture:

I have participated in dozens of Security Dialogues, and in my experience, the key benefits are:

  1. It activates everyone to think about security issues/incidents from their own perspective.
  2. It provides an opportunity to talk about security with your colleagues.
  3. It turns the traditional paradigm around – instead of us telling them – they are asking for help from us in solving real problems that are relevant to them.

I encourage everyone to try Security Dialogues. One session takes less than 1 hour, and it can be organized in Teams (with breakout rooms) or face-to-face. The recommended group size (in addition to the facilitator) is 6-16 people with similar interests, e.g., top management, customer interface, product development, etc. If you think people need more time to prepare, you can send the first question beforehand. Alternatively, you can just send the invitations and see what happens. You might be surprised by the information people already know, and if you identify gaps, it’s easier to provide solutions than problems. Here is one success story:

“As part of Valmet Automation awareness program, we held Security Dialogues for all personnel within our ISO27001 certification scope. It helped to increase personal commitment towards cybersecurity and gave dozens of improvement ideas. Generic feedback from the participants was that dialogues were way more useful than traditional one-way campaigns and e-learnings.”

Markku Tyynelä, Security Manager, Valmet Automation

Is your company the next one to bring security awareness to the next level? We have compiled an easy-to-use starter kit for arranging Security Dialogues which you are free to use – it is licensed under the Creative Commons Attribution-ShareAlike 4.0 International license. Start the journey today and download the kit!