session
Fiesta 5
1:40 pm - 2:30 pm, Monday, September 25
Why CISO’s Make Bad Decisions: How Bias and Influence Skew Information Security Risk Determination
Human Factors
About

Session Abstract: Why are so many organizations over-reliant on anti-virus while ignoring patching critical servers? Why do some enforce their generic awareness training while happily accepting flat, open networks and shared administrative passwords? Although there is a growing body of scientific research on how bias impacts our ability to accurately assess risk, bias factors remain largely absent from our risk assessment programs. This talk explores the various ways in which bias, cognitive heuristics, and influence affect our perception of risk and its impact on our decision-making as security professionals. Dozens of biases will be presented along with their impact on decision-making.Summary: This talk explores the various ways in which bias, cognitive heuristics, and influence affect our perception of risk and its impact on our decision-making as security professionals, reviewing dozens of biases and providing ways to identify and protect our decision-making.Additional Information: This talk provides engaging examples that facilitate insight into how we, as security professionals, assess risk. This will NOT be a talk where the speaker just reads a list of biases and blames the attendees for being biased. I believe that this talk is a great new way of viewing risk, fitting very nicely in to this year's theme "Reimagining Risk and Resilience"

Get in touch
Get in touch
Customer Service
For any and all inquiries please click the button below
Speaking Opportunities

Tim Garon
Director, Event Content and Strategy

Stay Informed
Join our mailing list for the latest news on InfoSec World 2023.