# Exercise: Cognitive Bias Identification - **PURPOSE:** Helps security professionals identify and counteract cognitive biases that affect how risk information is perceived and acted upon. - **WHEN TO USE:**When preparing important security communications or after experiencing resistance to security recommendations. ## **STEP 1:** Identify potential biases affecting your security communications | Cognitive Bias | How It Affects Security Decisions | Signs It May Be Present | Countermeasures | | --- | --- | --- | --- | | Availability Bias | Focus on recent or memorable security events rather than most significant risks | "We need to focus on ransomware because Company X was just hit" (while ignoring higher risks) | Provide objective data on actual threat frequency and impact in your environment | | Optimism Bias | Underestimating vulnerability to threats ("It won't happen to us") | "Our industry hasn't been targeted" or "We're too small to be a target" | Share specific examples of similar organizations affected; connect to actual vulnerabilities in your systems | | Status Quo Bias | Preference for current state over potentially disruptive security changes | Repeated deferral of security improvements despite acknowledged risks | Highlight costs of inaction; frame security changes as enabling business rather than disrupting it | | Framing Effect | Different responses to identical information based on how it's presented | More concern about "losing $1M to a breach" than "failing to save $1M by preventing a breach" | Present both potential losses and potential savings in your communications | Table 1: Potential biases affecting your security communications ## **STEP 2:**Review recent security communications Examine a recent security report or presentation and answer: - [ ] Did you rely heavily on technical metrics that executives may not understand? If so, rewrite with business metrics. - [ ] Did you present risks in terms of potential losses or potential protection? Try reframing. - [ ] Did you assume technical urgency would translate to business urgency? Add explicit business context. - [ ] Did you provide concrete scenarios or only abstract possibilities? Add a specific scenario. ## **STEP 3:** Create a bias-resistant communication plan What objective data will you include to counter availability bias? - [ ] How will you overcome optimism bias by making threats concrete and relevant? - [ ] How will you address status quo bias by making change seem less disruptive? - [ ] How will you frame the information to maximize impact? ## IMPLEMENTATION TIPS: - Review this exercise with both technical and business colleagues to identify blind spots - Use actual examples from your organization's history to make the biases more concrete - Revisit this exercise periodically, as biases can change based on recent experiences *** (c)[Kayne McGladrey](https://kaynemcgladrey.com/) - [Get the full book "Cyber Risk is a Myth"](https://www.routledge.com/Cyber-Risk-is-a-Myth-A-Business-Approach-to-Integrated-Risk-Management/McGladrey/p/book/9781041249054)