Twitter's recipe for security awareness
Security awareness training is an issue that has been and continues to be hotly debated both online and offline.
It is also a topic that seems a little out of place at the Hack in the Box conference in Amsterdam, but Bob Lord, Director of Information Security at Twitter, has raised some interesting points in his Thursday's keynote in which he shared his company's rather successful experiments regarding the matter.
He first pointed out that information security professionals tend to look for perfection, meaning that most often than not they tend to dismiss the whole concept of security awareness training just because a particular implementation of it has proved to be flawed. Secondly, he shared his and Twitter's approach of not concentrating on raising awareness, but changing employee behavior, habits and actions to create a security culture. "How can we make doing things the right way become the default in out company?" they asked themselves.