July 2, 2015 By Diana Kelley 3 min read

In the third and final part of our interview series with Kelley Misata, we discuss millennials and their views on cybersecurity and risk communications, among other topics. Misata, a Ph.D. candidate at Purdue University, previously chatted with Security Intelligence about issues relating to privacy and risk communications as well as information security in the first and second installments.

Question: At Emerson College, you’re teaching students about surveillance, privacy and risk communications. Do you think there are fundamental differences between how Gen Xers and millennials view privacy and cybersecurity? How will that impact the security landscape in the next decade?

Answer: My time teaching at Emerson has been amazing, and I’ve been very fortunate to have students in my classes who are engaged and curious about these topics. There are some differences between how Gen Xers and millennials view privacy and cybersecurity that are very different from those of us who remember life before the Internet and smartphones.

Actually I would have to say there is a chasm more than just differences. Their lives are out there 200 percent online and in ways that many of them never give a second thought to because they haven’t had a need to think about it. Even with the news about widespread surveillance in our country, many of these students saw that as something that didn’t relate to their daily lives. Until we discussed it.

One exercise I had them do was, in one 24-hour period, count how many surveillance tools and technologies they came across; it was interesting to see them focus on the cameras they see around them but never considering the tracking being done online through online browsing, GPS locations, postings, etc. What was also interesting, and how I feel this is going to impact the future of the security landscape, is that often people just see things from one side. The beauty of conversations and learning is to help people see even controversial and scary things from two sides.

My students and I walked through several examples of how surveillance is used for the power of good as well as the power of evil. We discussed how technology is morally neutral, and at the end of the day, its impacts are about the people using it, about the people we trust with our information and about how we are showing up in the online space. If we persist in encouraging users to have narrow and somewhat naïve views of cybersecurity, then how can things move forward in a positive direction?

Any advice on what companies can do now to leverage and improve their privacy and risk communications practices from the lessons you’ve learned working with crisis centers and crisis management?

First, I encourage organizations to break down the silos between IT groups, security groups, marketing, communications, human resources and others. Though no one should expect to be an expert in all the fields, broadening the view and helping to drive more interdisciplinary conversations is essential in any environment. Everyone has something to bring to these conversations.

Second, though I know it’s frustrating for IT and security professionals to discuss technical concepts at an elementary level, bring in people like me who don’t mind doing that. We have to help more people understand how important security and privacy is today and into the future. Last, there are some exciting new approaches to crisis communications and management. The more we live in the digital realm, the more challenging this gets, but it’s not impossible to manage if you prepare.

I suppose the big message here is let’s not wait for something bad to happen to prepare. I learned a long time ago that you never know what is lurking out there, but thinking about it every day will drive you crazy. So we don’t have to sit in the land of paranoia every day, but raising the level of understanding and awareness in any organization can have huge payoffs.

Hear more from Kelley Misata in this exclusive podcast interview

More from CISO

Overheard at RSA Conference 2024: Top trends cybersecurity experts are talking about

4 min read - At a brunch roundtable, one of the many informal events held during the RSA Conference 2024 (RSAC), the conversation turned to the most popular trends and themes at this year’s events. There was no disagreement in what people presenting sessions or companies on the Expo show floor were talking about: RSAC 2024 is all about artificial intelligence (or as one CISO said, “It’s not RSAC; it’s RSAI”). The chatter around AI shouldn’t have been a surprise to anyone who attended…

Why security orchestration, automation and response (SOAR) is fundamental to a security platform

3 min read - Security teams today are facing increased challenges due to the remote and hybrid workforce expansion in the wake of COVID-19. Teams that were already struggling with too many tools and too much data are finding it even more difficult to collaborate and communicate as employees have moved to a virtual security operations center (SOC) model while addressing an increasing number of threats.  Disconnected teams accelerate the need for an open and connected platform approach to security . Adopting this type of…

The evolution of a CISO: How the role has changed

3 min read - In many organizations, the Chief Information Security Officer (CISO) focuses mainly — and sometimes exclusively — on cybersecurity. However, with today’s sophisticated threats and evolving threat landscape, businesses are shifting many roles’ responsibilities, and expanding the CISO’s role is at the forefront of those changes. According to Gartner, regulatory pressure and attack surface expansion will result in 45% of CISOs’ remits expanding beyond cybersecurity by 2027.With the scope of a CISO’s responsibilities changing so quickly, how will the role adapt…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today