Sarah Aalborg on Secure by Choice

Sarah Aalborg on Secure by Choice

What do people have to do with cybersecurity? A lot. As with other fields of human risk, it’s people that are typically the root cause of problems in the cybersecurity world. Which is where my guest’s expertise in behavioural design comes into play.

On this episode, I’m speaking with Sarah Aalborg, a cybersecurity and behavioural design expert who’s on a mission to change how organisations approach IT security.

Rather than focusing on firewalls and tech solutions, Sarah examines the human behaviours that can undermine even the best-designed security systems.

Her new book, Secure by Choice, challenges conventional security thinking by exploring how cognitive biases affect security professionals and how to use behavioural design to reshape security culture.

We discuss the pitfalls of traditional security training – particularly those phishing tests that feel more like traps than training – and how to flip the script by focusing on what we want people to do rather than what we want them to avoid.

Sarah shares practical strategies for using positive reinforcement, creating engaging training experiences, and making security less about fear and more about action.

By applying principles of behavioural science and risk-based thinking, Sarah explains how we can bridge the gap between security policies and everyday human behaviour.

Guest Biography
Sarah Aalborg is a cybersecurity expert and behavioural design advocate, focusing on how cognitive biases impact IT security professionals and their decision-making processes.

She is the author of Secure by Choice, a book that challenges conventional approaches to cybersecurity training by applying principles of behavioural science to security culture.

With a background in IT security spanning over two decades, Sarah speaks at major security events and consults with organisations on how to create more effective, engaging, and human-centric security programs.

AI-Generated Timestamped Summary
[00:00:00] Introduction

[00:01:00] Meet Sarah Aalborg – Why she wrote Secure by Choice and her journey into behavioural design.

[00:03:00] The '20-centimetre above the keyboard' exercise – How human inaction impacts tech security.

[00:05:00] Why phishing tests feel like entrapment – and how to flip the script.

[00:08:00] Turning phishing tests into positive reinforcement opportunities.

[00:10:00] How a simple 'Report Suspicious Email' button can change behaviours.

[00:12:00] The problem with fear-based messaging in cybersecurity.

[00:14:00] Why telling people what NOT to do isn’t effective.

[00:15:00] Sarah’s four-step framework for creating risk-aware security cultures.

[00:17:00] Why most security training is designed to address the wrong problem.

[00:20:00] The McDonald's kiosk example – What we can learn from other industries.

[00:25:00] The importance of actionable examples in security training.

[00:30:00] The generative AI paradox – When tech meets human bias.

[00:35:00] Why AI is the ultimate behavioural science challenge.

[00:40:00] The 'Operating System' analogy – Why the human brain is still running Stone Age software.

[00:50:00] Why cyber professionals need to look outside their own industry for inspiration.

[00:55:00] The role of curiosity and exploration in designing effective security programs.

Links:Sarah’s website: https://securebychoice.com/
Sarah on LinkedIn: https://www.linkedin.com/in/sarah-aalborg-bb348a1/
Secure by Choice:https://securityblendbooks.com/products/secure-by-choice?

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(368)

Luca Dellanna on the Coronavirus and Multiplicative Dynamics

Luca Dellanna on the Coronavirus and Multiplicative Dynamics

On this episode of the Human Risk podcast, I speak to Luca Dellanna about COVID-19. He explains why he thinks governments aren't doing nearly enough to contain the spread of the virus. We also explo...

27 Helmi 202054min

Jacinthe Galpin on Risktory: how the past can teach us about risk

Jacinthe Galpin on Risktory: how the past can teach us about risk

What can we learn about managing risk from famous moments & people from history?In this episode, I speak with Jacinthe Galpin who is both a podcaster and an experienced risk professional. Jacinthe is...

20 Helmi 202042min

Tom & Christian's 4th Human Risk Talk

Tom & Christian's 4th Human Risk Talk

In this episode, co-host Tom Hardin and I talk about more stories from the news that fascinated us from a Human Risk perspective. We begin by talking about the Luanda Leaks, then explore the recent s...

13 Helmi 202051min

Alex Sidorenko on Risk Management

Alex Sidorenko on Risk Management

In this episode, I speak to Alex Sidorenko, the founder of Risk Academy. When it comes to thinking innovatively about risk, Alex has some fascinating thoughts, that we can deploy in the management of...

3 Helmi 202033min

Tim Houlihan and Dr Kurt Nelson on Behavioral Grooves

Tim Houlihan and Dr Kurt Nelson on Behavioral Grooves

In this episode, I welcome two of my favourite podcasters onto the show. Tim Houlihan and Kurt Nelson are the hosts of the fabulous Behavioral Grooves podcast, which you'll find wherever you get your ...

28 Tammi 20201h 5min

Kelly Paxton on Pink Collar Crime

Kelly Paxton on Pink Collar Crime

In this episode, I speak to Kelly Paxton who is a specialist in Pink Collar Crime which is a type of Human Risk. Kelly explains what Pink Collar Crime entails, why it is more significant than we migh...

18 Tammi 202045min

Dr Roger Dooley on Friction

Dr Roger Dooley on Friction

Roger Dooley describes himself as a "Friction Hunter". In this episode, I speak to him about his study of Friction; what I think of as "the things that stop us doing what we want or need to do". We ...

5 Tammi 202030min

Tom & Christian's 3rd Human Risk Talk

Tom & Christian's 3rd Human Risk Talk

In this extended episode, I'm joined again by co-host Tom Hardin. Together we explore Human Risk related stories we've come across that we think are worth diving into in more detail.You can hear Tom's...

22 Joulu 201956min

Suosittua kategoriassa Tiede

rss-poliisin-mieli
tiedekulma-podcast
rss-mita-tulisi-tietaa
docemilia
filocast-filosofian-perusteet
menologeja-tutkimusmatka-vaihdevuosiin
rss-duodecim-lehti
rss-tiedetta-vai-tarinaa
sotataidon-ytimessa
rss-lapsuuden-rakentajat-podcast
rss-lihavuudesta-podcast
utelias-mieli
radio-antro
rss-bios-podcast
rss-metsantuntijat-podcast
rss-luontopodi-samuel-glassar-tutkii-luonnon-ihmeita
rss-sosiopodi