Hacking Shame: A New Psychology for Advancing Infosec

No ratings

Presented at The GrrCON Cyber Security Summit and Hacker Conference 2024 by

In cybersecurity, the pervasive influence of shame significantly impedes progress for individuals, teams, and the industry overall. This talk will challenge the stigma of shame in infosec, where admitting “I don’t know” or getting “pwned” is unfairly seen as a sign of weakness or ineptitude. Shame is deeply embedded within the fabric of the cybersecurity culture. It manifests through individuals’ feelings of imposter syndrome, competitive one-upmanship within teams, and a collective industry struggle against repeated attacks employing unchanged TTPs. In this session, we’ll investigate how uncertainty fuels shame, then we’ll hack it. New research in psychology and neuroscience now demonstrates the untapped power of embracing the unknown. This session will unpack this research and teach attendees how to harness uncertainty to improve adaptive thinking, critical to evolving security risks. The implications of embracing uncertainty could have a transformative impact on cybersecurity at every level. For individuals, it paves the way for overcoming imposter syndrome by valuing continuous learning and vulnerability. At the team level, it cultivates a culture where expertise is balanced with open-mindedness, mitigating counterproductive competition. On an industry-wide scale, acknowledging and leveraging uncertainty can drive innovation in defense strategies and operational tactics. This presentation will investigate how reframing our relationship with uncertainty can dismantle the shackles of shame, fostering a more resilient, innovative, and inclusive cybersecurity community. Attendees will leave with new ideas about how uncertainty can be harnessed for improving individuals’ growth, team dynamics, and strategic industry advancements.