Startup Security Tactics: Friction Surveys

June 21, 2023hacker newscyber security

startup security

As we plan each quarter, my team breaks down goals into four evergreen outcomes:

  1. Reduce the risk of information security incidents
  2. Increase confidence in Vanta’s information security program
  3. Reduce the friction created by information security management
  4. Leverage our security expertise to support your business

This article will focus on the third, reducing friction.

declare one’s intentions

There is value in making “friction reduction” an explicit goal of your security program. This is one step for him to set the right atmosphere with colleagues across the organization and build a positive security culture.

When I first presented that work in a company-wide forum, I received the following Slack message from a senior leader who had just joined the company.

“It’s great to hear that the security team is focusing on removing invisible security controls. Great philosophy from the security team.

[…]

it’s just awesome

Too many security teams view security as an exclusive trade-off between team operational capabilities and security. ”

hidden friction

When introducing new security controls, trade-offs between security and user experience may need to be carefully considered. There are many scenarios where friction is not very clearly understood.

  1. Friction caused by security controls not fully understood by you or your team in advance
  2. Individuals outside your organization have enabled security controls in good faith without your knowledge or your team’s knowledge.
  3. Employees attribute the annoying controls to the security team, but they were actually implemented for completely unrelated reasons.

Each of these scenarios brings hidden friction. Hidden friction undermines team trust and pushes security culture in a negative direction.

The solution to hidden friction is friction research.

find hidden friction

Vanta conducts employee surveys twice a year to find hidden friction. He works with his two other teams, Enterprise Engineering and Privacy, Risk & Compliance, to avoid “survey fatigue” when employees are also surveyed on engagement surveys.

Each of our three teams put together a few questions to better understand how the company views the friction caused by our work.

Ask your security team three questions:

  1. How would you rate the friction caused by Vanta’s security controls in conducting your day-to-day activities? (1-5 scale)
  2. Describe how and where security controls affect your work at Vanta.
  3. Do you have any other thoughts or comments about the security team or our work? (If you chose 3/Neutral or lower for any of the above questions, we would love to hear from you.)

This survey was first conducted in the second quarter of 2022. It received positive reviews, but not much actionable feedback. I tend to see this as a sign of limited engagement rather than rave reviews.

When we ran the survey again in Q4 2022, we got even more interesting results. We found a major source of friction that we attributed to security, but had nothing to do with our team.

We also found that many people were running into issues with the new authentication policies we started rolling out. They didn’t know what the expected flow was, so when they encountered a bug that required multiple authentications per day, they figured it was just part of the policy.

take action

As a result of the investigation, we created a document summarizing the results and future efforts and shared it within the company. We want to be as transparent as possible. The goal is to clarify when something has friction because you’ve made explicit trade-offs, when you’ve made a mistake, and when there’s additional context to help people better understand your controls is.

result

Friction research is a valuable tool in combating the traditional norms of security culture. By building positive working relationships with all colleagues, you can work more effectively on other outcomes your team is trying to achieve.

Over time, these results become powerful program metrics and can be tracked as part of your KPIs.

Note: This expert-contributed article was written by Vanta Security Lead Rob Picard. Rob Picard heads his Vanta’s information security program. Prior to joining, he was the founder of a Y Combinator-backed security startup, a longtime security consultant, and built several security features at Robinhood. He enjoys applying the lessons learned to help startups build modern, effective and efficient security programs. This article was originally published on LinkedIn.

Did you enjoy this article? Follow us twitter You can read more exclusive content we post on LinkedIn.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *