a close up of a logo

The power of trust: thoughts on security in the digital age

Sian  John

Sian John

Chief Security Advisor

Read Time, 5 min.

When you’ve been working in digital security for a quarter of a century, as I have, people often ask what my number 1 piece of advice is to help businesses and organizations build trust with their customers and partners.

My answer is always the same: “Don’t be creepy!”

I know it’s a cliché to use films as parallels, but there’s a great example of what I’m talking about in Minority Report. Forget about the film’s overall premise, to predict when someone is likely to commit a crime before they do it. For me, the creepiest bit of the film is when Tom Cruise’s character walks into a department store and they scan his eyeball and then tell him exactly what clothes he’ll like. It might seem like a really good service, but it’s creepy. And I think people are worried about creepy things.

When companies talk about using advanced technologies like AI, an implication is that customer data can be used to profile people. So companies who do use AI have to do so with integrity and in an ethical way, so that people trust they’re using it with good reason and to good ends. Overstep the line, and you lose that trust.

My role is helping organizations to use technology in a way that builds trust. Here, I want to share some of the key things I think CISO’s should consider when approaching security in the digital age.

The importance of making trust leaps

Someone who has influenced a lot of my thinking on trust is Rachel Botsman, in particular her concept of what she terms Trust Leaps. For Botsman, trust leaps are when people have to make a mental leap from the known into the unknown. These leaps are characterised by a particular emotion: uncertainty.

When organizations move from on-premise to cloud-based infrastructures, they have to make a trust leap, which is to say: they have to confront uncertainty. So when we do make the leap to digital transformation, there needs to be enough information and visibility to make that leap as comfortable as possible.

Those CISOs who embrace the move to the cloud are looking at hyper-scale cloud service providers like Microsoft and asking themselves questions like:

  • Do I think that you as an organization are going to look after my data?
  • Do I know that I’ve got control over that data when it’s there?
  • Do I have visibility of what’s happening in the cloud service?
  • Can I get an understanding of how you’re going to operate in the backend?
  • Will I get visibility of risk?

We do everything we can to answer these questions and more because we understand that moving to the cloud is a massive chasm of trust to leap over for some organizations. The more information and transparency we can give, the less daunting that leap will be. Because ultimately, trust comes down to people feeling they are in control, and that what they expect to happen, will happen.

How transparency reduces the need for trust

Transparency is a word that often comes up when we talk about trust. But something Rachel Botsman points out that really resonated with me is that transparency does not actually build trust. What it does is reduce the need for trust. By being transparent, you reduce the amount of unknown, so it’s less of a leap to make to trust.

When it comes to security, having the right controls in place so you can see what’s happening, audit what happens and show engagement – all of that creates greater transparency, and so reduces the trust gap.

But I also believe that under the right circumstances, transparency can actually be used to build trust. The Norsk Hydro data breach is a great example of this in action.

Norsk Hydro is a huge global aluminium manufacturer whose factories rely on digital technologies to power their machines. So when they were hit by a massive ransomware attack, it spelled potential disaster for both their production line and brand image. But their response saved them.

When the attack hit, they held a public press conference. They were very transparent about it. They were transparent about the attack itself, the investigation, their engagement. So rather than the breach having a negative effect on their image, a lot of the commentary from people at the time was about the trust and respect they built in the industry because of the way they responded transparently to deal with it.

That’s a classic example of taking lemons and making lemonade with them. And it was made possible by being transparent, ethical, honest, and responsible with the trust of customers and partners whose data was put at risk.

Taking responsibility for cyber security

One of the characteristics of trust and privacy is that it is very emotional. To trust is to be vulnerable, and cyber criminals know that, which is why our trust is often the gateway they try to exploit to gain entry to our organizations.

They will continue to succeed. Because people are people, and they will continue to make mistakes. It’s easy to say “If you get a link, don’t click on it.” But security experts have to remember that the modern world has been set up to encourage people to click on links. So saying “don’t click on the link” is really saying “don’t do the thing you’ve been conditioned to do for the past 15 years”. It’s unrealistic, and I think security experts can be too hard on end-users, expecting them to behave in a way that isn’t natural to them.

The better response is to expect the breach and be prepared for it. That’s how I operate: I expect criminality to exist. I expect humans to make mistakes. And I accept responsibility for trying to manage that equation and mitigate its impact.

As I see it, technology is the greatest defence we have in this fight.

Safeguarding digital privacy

Discover the 5 ways to increase trust and empower people in our latest eBook, Safeguarding digital privacy

Discover more related articles per industry:

Education

  • a woman looking at a computer

    How Griftland College is putting technology at the heart of remote learning

    “When COVID-19 was on the verge of breaking out, we had to make a choice about how to go further,” says Kees Versteeg, the principle of Griftland College. The secondary school, located in the Dutch town of Soest, was one of the first in the Netherlands to close and start teaching 100% remotely. He describes […]

  • a person sitting at a table using a laptop computer

    Reimagining education: From remote to hybrid learning

    The COVID-19 pandemic has generated a torrent of individual and small-group responses as to how education could be transformed. We have found a groundswell of interest in the question, “How best to take advantage of the new opportunities arising from the disruption?” What people desperately need are opportunities to team up and find pathways of […]

Government

  • How VR Group is using automation to secure Finland’s railways

    How VR Group is using automation to secure Finland’s railways

    “Being at the helm of a critical piece of infrastructure, we have a huge responsibility towards our partners and clients. That’s why safety and security are crucial elements of what we do and how we operate.” Mikke Maronen, CISO at Finnish railway company VR Group, is talking about the importance of protecting his business from […]

  • a man and two women standing in front of a brick building

    Ajuntament de Lleida: transforming the public sector with a modern, virtual workplace

    “At Ajuntament de Lleida, we think differently. We embrace new technology. And when we see that it could add real value to the work we do, we find a way to make it happen.” Carles GinéSabaté, Systems Implementation Planning Manager at Ajuntament de Lleida, is reflecting on his organization’s open-armed approach to digital transformation and […]

Healthcare

  • a person sitting in front of a laptop computer

    The ‘Big Bang’ approach to digital transformation – and how to make it work

    These days there’s no such thing as ‘business as usual’. Change and disruption are the new normal. Just think of the changes affecting your organization right now, with new technology and techniques driving new attitudes and expectations from employees and customers alike. Everything is changing. And the one thing all those changes have in common […]

  • logo

    Why trust is the essential ingredient in healthcare digital transformation.

    My phone had scarcely stopped ringing for weeks. Now it was ringing again. “Veronica,” said the voice at the other end, “we have an idea!” Immediately, I recognized who it was. I’ve known Carlo Tacchetti for almost as long as I’ve been at Microsoft. He’s a professor at the Vita-Salute San Raffaele University and the […]

Manufacturing

Retail

  • GDPR and Retail: Four GDPR requirements and how Microsoft can help

    GDPR and Retail: Four GDPR requirements and how Microsoft can help

    Learn how we can help you meet GDPR requirements with solutions available today: Assessing your current risk profile “How do I understand where I am already compliant and where I need to focus next?” This is one of the most common questions from retailers in regard to the GDPR. It’s also one of the hardest to […]

  • Picture from the back of a person attending a Teams meeting with 2 colleagues, discussing about a furniture fabric.

    Zuiver: Supporting both business and culture through technology

    “Since moving to the cloud, there are no limitations anymore. And I’m certain without this technology, we would not have seen the growth we have today.” Jaap Landsaat, CFO and Head of IT at Dutch furniture designer Zuiver, is talking about the profound impact technology has had on the business he co-founded more than 20 years ago. “Back then, we had 100 orders a week […]

Discover more related articles per dossier:

Customer Stories

  • a group of people performing on stage in front of a crowd

    City of Liège: Facilitating decision making in difficult times

    For many organizations, social-distancing measures brought about by COVID-19 have drastically slowed day-to-day operations – and for some, even stopped them altogether. But for local governments across Europe, like the Belgian city of Liège, slowing down hasn’t been an option.  From supporting citizens and businesses to protecting frontline workers, Liège city had to quickly provide stability during this crisis and ensure important decisions could still be made in a democratic […]

Digital Transformation

Security & Privacy

  • Sofie Lindblom sat with Surface device in boardroom

    200 billion reasons why companies must face up to the challenge of cyber security

    200 billion. That’s how many connected devices there will be worldwide by 2021. It’s an incredible number – and one that’s going to have massive implications for the way we live and work. Today, everyone is mobile. We can work from anywhere and share our work and our passions seamlessly from device to device. The office cubicle is a relic; work has never been so fluid. It’s a wonderful thing – but it creates a big challenge. Security. […]

Tips

  • a person sitting at a table in front of a window

    Are you making the most of Microsoft Teams while working remotely?

    There are many reasons and requirements for remote work, and meeting those requirements flexibly is why we created Microsoft Teams: to help you stay connected with your teams and ensure you can continue working collaboratively and efficiently, wherever you are. Here are a couple of tips to help you get the best from Microsoft Teams […]