f |
e |
a |
t |
u |
r |
e |
Are your people as prepared as your playbooks? |
|
|
|
|
|
|
Cybersecurity teams rarely enter a major incident fresh – they arrive carrying the pressure of the job they were already doing. That pressure comes from competing priorities, persistent threat, regulatory scrutiny, technical complexity, resource constraints and the knowledge that something important could happen at any time. Then the incident arrives, and all of that existing demand continues while a new and much more intense layer is added – and that distinction matters.
Rebecca McKeown, Founder and Principal Psychologist with Mind Science
We tend to think about cyberincidents as discrete events, and much of our preparation reflects that model. Playbooks, tabletop exercises, escalation procedures and technical training are designed to help people know what to do when an incident occurs.
Cybersecurity preparedness depends not only on robust technology and incident response plans, but also on whether security professionals can maintain effective judgement and decision-making under sustained pressure. In an exclusive interview, Rebecca McKeown, Founder and Principal Psychologist with Mind Science, tells Intelligent CISO Editor Mark Bowen why cognitive readiness must become a core component of cyber-resilience and how organisations can better prepare their people to perform effectively when a major cyberincident occurs.
Research with experienced cybersecurity practitioners suggests a different picture. The incident itself may not be the biggest human performance risk. The bigger risk may lie in the sustained pressure of business as usual and what that pressure progressively does to people’ s capacity to perform.
Performance can remain stable while capacity is disappearing
One of the most important findings from the research was also one of the least visible. When demand increases, experienced professionals do not suddenly become bad at their jobs, they compensate. They concentrate harder. They work longer. They invest more effort. They prioritise the most important tasks and defer those that can wait. From the outside, their performance continues to look perfectly acceptable.
Psychologist Robert Hockey described this through his theory of compensatory control: under high workload and stress, people can protect primary task performance by investing additional effort. Performance is maintained, but at a cost.
This creates a problem for organisations because we tend to use visible performance as evidence of whether or not someone still has the capacity to meet additional demands. If the work is still getting done, we assume the person is coping, but that may not be the case. Performance capacity can be consumed long before performance visibly deteriorates.
We tend to think about cyberincidents as discrete events, and much of our preparation reflects that model.
WWW. INTELLIGENTCISO. COM 37