Explaining the “Why”

As cybersecurity professionals, we understand the “why” of what we do because of years of training and experience. Yet one of the most overlooked areas in cybersecurity is explaining the “why” to people within the organization.

Think back to when you were young and asked one of your parents why you had to do something, only to be told, “Because I said so.” It did not answer your question, and you walked away disappointed because you wanted to understand.

Now take a moment and reflect on a situation as an adult when you asked a why question only to ignored, belittled, or left with an answer that made no sense. Now recall a time where someone gave you an answer to a why question that you understood. Getting an answer you can comprehend, to a question is knowledge transfer, it is educating others. That should be part of our duty and responsibility as technology professionals – enhancing the knowledge of others.

We received years of training and spent years or decades honing our craft. How did that happen? It happened when someone else was willing and able to answer our questions. They invested the time to educate us because that is their role (trainers), or they enjoyed sharing their knowledge with others. For those that are “self-taught,” you had to get the information from somewhere to gain knowledge. Someone took the time to put the information into a format you could comprehend and learn. So why is there such a reluctance to share knowledge with others when the biggest security vulnerability in any company is the people?

Too many security awareness training programs address the why questions like, “Why do I need to safeguard my password or passphrase” but lack any real substance about why we require strong passwords or why we use a privileged access management (PAM) solution. There are those that do not care and are not interested in learning; however, we should embrace teaching those that want to learn. Explaining the “why” of cybersecurity practices, software, policies, and other controls enhances employee knowledge and can only serve to strengthen a company’s security posture.

Here is the challenge: step outside your comfort zone and educate people outside of IT by answering their cybersecurity why’s.

Why? It is the right thing to do, it is empowering and just may reduce a portion of your security risk.

Kevin Hutchinson, CISSP, RPA
Core Cyber, LLC
Owner/Operator