Do you have a Bieber Policy?!
You have been Biebered....

Do you have a Bieber Policy?!

What are you doing to change behavior in your org to reduce infosec risk?

Many of my guests on Cyber Security Interviews (Perry Carpenter, Joseph CarsonLance Spitzner, Theresa PaytonKristin Lovejoy) have talked about people centric approaches to cyber security.

One thing that I did in a prior organization was to implement "The Bieber Policy" for unlocked workstations. Get up and leave your workstation unlocked, you get Biebered, for all in the office to see. 

It was a written policy limited to our security team/group. All you could do was change the desktop background to Bieber photos, you couldn't do anything else (explicit deny).

So what happened? Behaviors changed and people locked their workstations. No one likes being Biebered :(

Something simple to reinforce a policy and keep the shoemakers kids thinking about their OWN organizational security responsibilities in a bit of a silly way. You need to find ways to make security fun.

It also spurred innovation. When Georg Thomas was on the team, he wrote (in C? Georg correct me?) a simple Bluetooth utility that would pair with his phone and auto lock his workstation when he got up and walked away. 

What are some tactics YOU have done to change security culture in your organization and what were the results?

Nicole Anderson

Writer. Organisation Developer. Supporter of Change.

7y

Peter McNamara Renee Hancock this has got me thinking...

Like
Reply
Edgar Zayas

Fraud Prevention through Behavioural Biometrics

7y

That's great. I recently saw the security culture folks @NAB use custom post it notes to stick on monitors. They were so successful they ran out quick. End users came back asking for more.

Like
Reply
Douglas Brush

Interim CISO for Regulatory and Legal Compliance | ESI Court Appointed Neutral (Special Master) | Data Breach and Duty of Care Expert Witness

7y

Georg Thomas that's right! Bieberfication on a stick!

Like
Reply
Dr. Georg Thomas, MAICD

DInfoTech, MMgmt(InfoTech), CISSP, CISM, C|CISO, CIPM, ISO27001 LI/LA - Experienced Information Security, Cyber Risk, Data Privacy & Technology Leader

7y

Douglas Brush, you forgot to mention my other innovation - weaponising your policy...the Bieber-stick

  • No alternative text description for this image
Dr. Georg Thomas, MAICD

DInfoTech, MMgmt(InfoTech), CISSP, CISM, C|CISO, CIPM, ISO27001 LI/LA - Experienced Information Security, Cyber Risk, Data Privacy & Technology Leader

7y

Yes, C. To this day, I was the only one that never got Bieber'd

Like
Reply

To view or add a comment, sign in

Insights from the community

Others also viewed

Explore topics