This is a series of blogs where i intend to discuss the psychology of security, the first blog will try and focus on bridging formal security practises into my experience in psychology, i should immediately add a trigger warning to some posts will discuss some potentially distressing content as we discuss psychology concepts.
How do we actually know that something is a threat?
It’s not an easy question to answer, is it - and having worked in Security for about 35 years, i am no closer to answering it.
for a SOC analyst, is it
someone logging in from Taiwan when they last logged in from the U.S less than 24hrs ago?
Is it PowerShell spawning from Word?
Is it 124 character domains appearing in your DNS logs
Maybe the CEO just wanted to watch the new Game Of Thrones S6_E6.mp4.exe
Which of these things is actually a threat? We don’t know, do we? There is a distinction to be made between unusual ≠ threat.
Something can be normal -> unusual -> sus -> malicious -> threat
Maybe the employee in Taiwan is visiting a sick relative and is a very conscientious, or diligent employee and simply wanted to check in? Or maybe their creds have been stolen and someone is using the VPN to login?
Threats are not necessarily observations, they are interpretations based on experience in some cases.
Maybe the employee simply opened their email app on their corporate phone to see if they have any updates before and after they landed in Taiwan to visit their sick relative, we have now the context needed to address the interpretation of a perceived threat.
What does Intelligence actually add?
because remember, IPs, domains, hashes and intel laundering isn’t actually intel.
“Hey, check out badguy@outlook.com” within your data, its bad” This is both a brilliant and a terrible example of how contextless alerts require information to be interpreted and provided a meaning, and ultimating a decision.
An observable of an event is not a threat. The issue we’re faced with as humans is the human brain will bring the following:
experience
expectations
assumptions
bias
fear
pressure
pattern recognition
knowledge(or lack of)
Two analysts can look at the same event and reach differing conclusions
Yes, this meme is old but its an accurate depiction of the concept. Sherman Kent wrote about this in depth, here is a brief discussion:
Now the uncomfortable question: who decides when an interpretation becomes a threat? We have already mused the objective process:
Something happened → someone identifies the something → a threat is confirmed → the entity responds.
But we all know that is not how any practical sense of security works. The layers of judgement that occur before a choice has been made will contribute to the final decision.
I ask myself, and so should you: when did this become a threat?
The login? The analyst alert? The escalation? The CISO ping on the golf course? The CEO resignation? The shareholders notification? Or, simply, when the entity decided to acknowledge and change their behavior because of the threat?
A bright analyst can interpret this as a targeted intrusion given their experience and provide an assessment based on this. A CISO may say, “I believe we’ve experienced a nation-state intrusion.” Of course, these two sentiments are different things. The idea of security based on the notion of compromise has been interpreted and partly constructed through language, authority and, in the end, acceptance.
Let me be clear: ransomware activity, targeted intrusions are very real. I have dealt with, and responded to, both. The notion we talk about in this blog should not diminish the roles incident responders and executives play in the response.
The interpretation of authority should be the core argument, if any.





Nice.


