Cyber-preparedness: Try the Five Minute Micro-Exercise

Cyber-preparedness: Try the Five Minute Micro-Exercise

Cybersecurity continues to be an evolving threat to the public and to our nation.

Micro-exercising is a concept in physical fitness where people engage in a short, targeted workout or slightly increase the intensity of a normal activity in whatever location or during whatever time they have available – think taking the stairs versus the elevator, or working while standing up instead of sitting at your desk. In the same vein, we can apply a similar approach to cyber-preparedness, as we recognize the number of vulnerabilities created through users’ behavior, activities, or other human errors.

Protecting networks and critical infrastructure from malicious attacks, equipment failure, human errors, and honest mistakes involves applying overlapping security controls in the context of strategies that may be opaque or seem incredibly complex to an authorized system user. When that happens, people may become less conscious of their activities as they are either overwhelmed with information or they think, “Someone else is taking care of this.” While that is often true and even as cybersecurity techniques evolve with proactive technologies to remove vulnerabilities or stem an attack before it happens, we still find that we often react to cyber incidents after the fact.

Enter the micro-exercise. Cybersecurity exercises that receive the most publicity are national in scale and have a broad scope intended to test, validate, or identify weaknesses in large-scale cybersecurity strategy. Beyond that, I often wonder how many system users actually get to participate in any cyber-exercise. I suspect it is not very many and, therefore, people may not have had the opportunity to reflect or understand cybersecurity best practices or response methods.

Managers have an opportunity, and potentially a responsibility to their organization, to provide that opportunity by starting with a simple question: “What would you do if you receive an email with an attachment from someone you don’t know?”  Or, “You see an antivirus alert on your computer, so you…?”  Or, “You are unexpectedly prompted to enter your user ID and password. Should you do that? Should you report it?”

It does not take a full-scale exercise to keep a network healthy. 

Ask the question in a staff meeting and have a five-minute conversation about what should happen next. If people don’t know the answer, rather than being “wrong”, it may mean that there is an opportunity to direct them to an authoritative source, to some awareness materials, or that there is a gap in policy, procedure, or awareness that can be addressed with the IT organization. When this is the case, they will be glad you asked.

Blog Cybersecurity

Contributors

* Arc Aspicio |

Arc Aspicio enhances the future of our nation by creating bold ideas and bringing them to life. A consulting and solutions company, Arc Aspicio solves problems by applying our integrated capabilities in strategy, design, data, human capital, behavioral science, and technology. The company passionately pursues our vision to be the hub of creativity where people take action to change the world. To do this, employees collaborate with clients and partners to create solutions using a human-centered approach. Innovation is not possible without action. The company focuses on strategy first, then takes a hands-on approach implementing ideas to achieve results. Join Arc Aspicio and our Strategy Innovation Lab (SILab) by creating and sharing ideas to inspire people to change the world. Follow us on Twitter @ArcAspicio @SILabDC and, #welovedogs!

Running IT Like a Business: How Technology Business Management is Shaping the Future of Federal Agencies

Running IT Like a Business: How Technology Business Management is Shaping the Future of Federal Agencies

As the Government continually looks for ways to increase efficiency and encourage innovation, Information Technology (IT) is emerging as a solution to these needs. Recent Federal guidance mandates all agencies to adopt a new framework for better understanding IT costs. Technology Business Management (TBM) is a framework that incorporates IT departments into the overall business network, shifting away from treating IT as an independent unit. This provides a clear way to evaluate and manage IT, running IT as a business and communicating the value of new IT investments.

Behavioral Science – Using Behavioral Science to Affect Action

Behavioral Science – Using Behavioral Science to Affect Action

How do organizations encourage behavior change in their customers? Increasingly, they focus on customer experience, and as a consequence employ behavioral science methodologies. At the heart of behavioral science is the consideration of how an organization can make small investments that generate incremental savings/returns while considering both customers and organizational benefits. One example is Transportation Security Administration’s (TSA) Pre✓® and U.C. Customs and Border Protection’s Global Entry programs.

Launching into #Action Through Strategy

Launching into #Action Through Strategy

As a new employee, your first company-wide meeting can make you nervous. This was how I felt.

Arc Aspicio’s recent Strategy Launch Day was so well planned and it involved participants so that I learned that I had nothing to worry about! The company treats each employee equally and equips even the newest joiners with the information and skills they need to have a meaningful experience

What Being a Consultant Means to Me

What Being a Consultant Means to Me

As a Consulting Associate at Arc Aspicio, I provide expertise and insight to help clients solve difficult problems. To be successful, a consultant does not need only to be a subject matter expert on their client’s industry and needs - though this often ends up happening over time.

Captivate Your Audience Through Design+Data

Captivate Your Audience Through Design+Data

So often, senior leaders must communicate their strategic and simple vision in a world of growing complexity. They must make decisions – and frequently explain them – based on an enterprise view of their data. It’s getting easier to do this these days through data visualizations and infographics that speak to specific employee and stakeholder audiences. Design+Data is what we call it at Arc Aspicio.

Chief Data Officers: Six Steps to Manage Data as an Enterprise Asset

Chief Data Officers: Six Steps to Manage Data as an Enterprise Asset

With an exponential increase in the types and quantities of data, organizations need defined strategies and techniques to manage data as an enterprise asset. To create enterprise-wide use of data, a Chief Data Officer (CDO) needs a clear data agenda for leadership and the whole organization to address current and future needs. CDOs should follow this six-part data plan to achieve short term capability gains and plot a path to greater enterprise data maturity.

Securing Cyberspace: Agile Strategy to Counter Changing Threats

Securing Cyberspace: Agile Strategy to Counter Changing Threats

Cybersecurity, managing and protecting computer systems from attacks, is evolving just as quickly as the techniques hackers use to cause damage. Historically, the public and private sectors believed that stronger technology and more advanced computer systems alone were enough to prevent attacks. As new trends emerge and the technologies used to both conduct and prevent hackings improve, cybersecurity strategies must remain agile, trying new tactics to counter changing threats.

Hacking Back – Do the Benefits Outweigh the Risks?

Hacking Back – Do the Benefits Outweigh the Risks?

With the increased frequency and sophistication of cyber-attacks worldwide, companies and executives are becoming frustrated with a traditional focus on defensive tactics. As a result, some private sector actors are taking a more active role in cybersecurity by “hacking back” – hacking against the very groups that are attacking their systems in retaliation or to retrieve stolen data. As hacking back rises in popularity, it is important to consider a number of political and legal issues and the risks to counter-terrorism efforts.

LeadersNest Names Lynn Ann Casey a FedFem Award Honoree

LeadersNest Names Lynn Ann Casey a FedFem Award Honoree

Washington, DC, October 19, 2018 — LeadersNest named Arc Aspicio CEO Lynn Ann Casey a FedFem Award Honoree. The FedFem awards salute high-impact women executives and leaders of the government contracting community. FedFem Award Honorees blend their entrepreneurial courage and Federal government support that effectively impacts the industry, national economy, and the local marketplace. 

Boosting the Mission: Developing Acquisition Requirements Guidance

Boosting the Mission: Developing Acquisition Requirements Guidance

To keep up with the fast pace of change in the field of Government acquisitions, Department of Homeland Security (DHS) components are developing their own acquisition requirements (AR) policies. However, without specific timeframes to finalize these policies, DHS agencies often lack guidance on how to develop ARs. Among DHS agencies, the U.S. Coast Guard is leading the way with their own formal policy to describe this process. To compliment the U.S. Coast Guard’s policy, DHS created the Joint Requirements Integration and Management System (JRIMS) to offer direction for agencies—to review, validate, and suggest solutions for capability gaps and requirements.