SHARE
Facebook X Pinterest WhatsApp

Adding a Human Element to Cybersecurity

The Challenges of Gaining Useful Insight into Data I read an article this morning that discussed how little most companies trust friendly hackers when they discover vulnerabilities. According to the San Francisco Chronicle article, while some larger tech companies are willing to listen to these outside sources, the majority are leery of them [registration required]. […]

Written By
SP
Sue Poremba
Nov 23, 2015
Slide Show

The Challenges of Gaining Useful Insight into Data

I read an article this morning that discussed how little most companies trust friendly hackers when they discover vulnerabilities. According to the San Francisco Chronicle article, while some larger tech companies are willing to listen to these outside sources, the majority are leery of them [registration required].

This might not be great news for information-sharing laws, but I do wonder if there is a role for friendly hackers in behavior analytics, which relies on human and attacker behaviors. A new report from Rapid 7 points out how important the role of behavior analytics is in today’s threat detection and prevention. As the report states:

Vulnerabilities and exploits grab headlines and the attention of the world’s security community . . . However, penetration testers and criminal intruders agree: Compromised credentials are what makes the job of hacking possible and profitable for intruders on a daily basis.

Robert Abel, writing for SC Magazine, adds:

Researchers said that by monitoring user accounts, cloud usage, location of mobile BYOD (bring your own device) use, and lateral movement of information within their systems, enterprises can gain insight into how employees use information to better detect abnormalities.

Unfortunately, only a small number of companies rely on behavior analysis right now, according to a recent SANS survey on analytics, so already companies aren’t doing as much as they can to take advantage of what we know (and can continue to learn) about human behavior. At the same time, can behavior analysis be enhanced by friendly hackers?

In a Dark Reading article, Rapid7’s Tod Beardsley, security research manager, and Roy Hodgman, data scientist, point out that analysts have to understand what normal behavior is for the accounts used by real people as opposed to machine-based accounts with automatic activity. They also have to learn how humans are interacting with the cloud and with mobile. As the article states:

User behavior analytics can offer a ton of value on a number of fronts. Not only do these metrics offer visibility into potential insider threats, but they can also show early red flags for when accounts have been compromised by external attackers.

Security

So my question is, if friendly hackers discovered vulnerabilities, how does that information mesh with behavior analytics as a way to add another layer to security detection and prevention?

It’s so easy to get caught up on the machine, software and tech side of security that we often forget the human element, both for good and for bad. We know humans are the ones developing the mechanisms of cybercrime, so now we need to figure out how humans can play a bigger role in preventing it.

Sue Marquette Poremba has been writing about network security since 2008. In addition to her coverage of security issues for IT Business Edge, her security articles have been published at various sites such as Forbes, Midsize Insider and Tom’s Guide. You can reach Sue via Twitter: @sueporemba

SP

Sue Poremba is freelance writer based on Central PA. She's been writing about cybersecurity and technology trends since 2008.

Recommended for you...

Observability: Why It’s a Red Hot Tech Term
Tom Taulli
Jul 19, 2022
Top GRC Platforms & Tools in 2022
Jira vs. ServiceNow: Features, Pricing, and Comparison
Surajdeep Singh
Jun 17, 2022
IT Business Edge Logo

The go-to resource for IT professionals from all corners of the tech world looking for cutting edge technology solutions that solve their unique business challenges. We aim to help these professionals grow their knowledge base and authority in their field with the top news and trends in the technology space.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.