Sarah Aalborg on Secure by Choice

Sarah Aalborg on Secure by Choice

What do people have to do with cybersecurity? A lot. As with other fields of human risk, it’s people that are typically the root cause of problems in the cybersecurity world. Which is where my guest’s expertise in behavioural design comes into play.

On this episode, I’m speaking with Sarah Aalborg, a cybersecurity and behavioural design expert who’s on a mission to change how organisations approach IT security.

Rather than focusing on firewalls and tech solutions, Sarah examines the human behaviours that can undermine even the best-designed security systems.

Her new book, Secure by Choice, challenges conventional security thinking by exploring how cognitive biases affect security professionals and how to use behavioural design to reshape security culture.

We discuss the pitfalls of traditional security training – particularly those phishing tests that feel more like traps than training – and how to flip the script by focusing on what we want people to do rather than what we want them to avoid.

Sarah shares practical strategies for using positive reinforcement, creating engaging training experiences, and making security less about fear and more about action.

By applying principles of behavioural science and risk-based thinking, Sarah explains how we can bridge the gap between security policies and everyday human behaviour.

Guest Biography
Sarah Aalborg is a cybersecurity expert and behavioural design advocate, focusing on how cognitive biases impact IT security professionals and their decision-making processes.

She is the author of Secure by Choice, a book that challenges conventional approaches to cybersecurity training by applying principles of behavioural science to security culture.

With a background in IT security spanning over two decades, Sarah speaks at major security events and consults with organisations on how to create more effective, engaging, and human-centric security programs.

AI-Generated Timestamped Summary
[00:00:00] Introduction

[00:01:00] Meet Sarah Aalborg – Why she wrote Secure by Choice and her journey into behavioural design.

[00:03:00] The '20-centimetre above the keyboard' exercise – How human inaction impacts tech security.

[00:05:00] Why phishing tests feel like entrapment – and how to flip the script.

[00:08:00] Turning phishing tests into positive reinforcement opportunities.

[00:10:00] How a simple 'Report Suspicious Email' button can change behaviours.

[00:12:00] The problem with fear-based messaging in cybersecurity.

[00:14:00] Why telling people what NOT to do isn’t effective.

[00:15:00] Sarah’s four-step framework for creating risk-aware security cultures.

[00:17:00] Why most security training is designed to address the wrong problem.

[00:20:00] The McDonald's kiosk example – What we can learn from other industries.

[00:25:00] The importance of actionable examples in security training.

[00:30:00] The generative AI paradox – When tech meets human bias.

[00:35:00] Why AI is the ultimate behavioural science challenge.

[00:40:00] The 'Operating System' analogy – Why the human brain is still running Stone Age software.

[00:50:00] Why cyber professionals need to look outside their own industry for inspiration.

[00:55:00] The role of curiosity and exploration in designing effective security programs.

Links:Sarah’s website: https://securebychoice.com/
Sarah on LinkedIn: https://www.linkedin.com/in/sarah-aalborg-bb348a1/
Secure by Choice:https://securityblendbooks.com/products/secure-by-choice?

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(368)

Ella Jenkins & Pete Dyson on Why Do Cyclists Run Red Lights?

Ella Jenkins & Pete Dyson on Why Do Cyclists Run Red Lights?

Why do cyclists in London run red lights? It's against the law, and yet, if you've cycled, driven or just observed London's cyclists, you'll know that many of them don't stop when there's a red light....

31 Aug 202554min

Dr Nuno Reis on Rare Dots

Dr Nuno Reis on Rare Dots

What if the ideas that linger in the back of your mind — the ones you can’t quite explain — are the ones you most need to pay attention to?Episode SummaryIn this episode, I explore that question with ...

24 Aug 20251h 7min

Professor Christian van Nieuwberg on Radical Listening

Professor Christian van Nieuwberg on Radical Listening

Is listening a hidden superpower we’ve overlooked?  You've heard of Active Listening, but what is Radical Listening and why does it matter?Episode SummaryOn this episode, I’m joined by Professor Chris...

17 Aug 20251h 9min

Dr Sunita Sah on Defiance - how to speak up when it matters

Dr Sunita Sah on Defiance - how to speak up when it matters

Why do we follow orders or go along with things that feel wrong? Why might defiance be better than compliance? And how can we go about becoming more defiant?Episode SummaryI’ve always been fascinated ...

9 Aug 20251h 2min

Dr Libby Maman on Measuring and (Re-)building Trust

Dr Libby Maman on Measuring and (Re-)building Trust

What happens when citizens lose faith in the institutions that serve them? And how can we rebuild that trust?Episode SummaryOn this episode, I'm speaking to someone who cares passionately about this s...

2 Aug 20251h

Iain Morrison on When The Show Mustn't Go On

Iain Morrison on When The Show Mustn't Go On

We’ve all heard the phrase ‘the show must go on’.  But when shouldn’t the show go on?  To help me answer that, I’m speaking to someone who has spent 35 years managing some of Australia’s most iconic l...

26 Jul 20251h 5min

Zsike Peter on Thinkbait

Zsike Peter on Thinkbait

What if the real risk of AI isn’t job loss but brain atrophy?Episode SummaryIf you've spent any time on social media recently, you'll be familiar with the flood of low-quality AI-generated sludge. And...

19 Jul 20251h 9min

Dr Kiran Bhatti & Professor Thomas Roulet on Wellbeing Intelligence

Dr Kiran Bhatti & Professor Thomas Roulet on Wellbeing Intelligence

What if we treated mental health like a capability instead of a crisis? On this episode, I'm talking to a business school professor and a counselling psychologist about their new book that looks at pr...

12 Jul 20251h 2min

Populært innen Vitenskap

fastlegen
tingenes-tilstand
jss
rss-zahid-ali-hjelper-deg
rekommandert
sinnsyn
rss-paradigmepodden
liberal-halvtime
vett-og-vitenskap-med-gaute-einevoll
forskningno
rss-overskuddsliv
villmarksliv
kvinnehelsepodden
nordnorsk-historie
grunnstoffene
tidlose-historier
rss-inn-til-kjernen-med-sunniva-rose
nevropodden
dekodet-2
rss-rekommandert