I take umbrage with headlines like this.
-
I take umbrage with headlines like this. It wasn't the employee's fault for the data breach at Ascension, a healthcare giant with over 140 hospitals across the United States. It was Ascension's leadership that failed to implement adequate cybersecurity defenses that resulted in the breach of 5.6 million patients' data.
-
-
@zackwhittaker The error was by the humans in the C-suite and the boardroom
-
@zackwhittaker Management, not taking security seriously enough to even try and do the right thing, you say? SACRE BLEU!
-
-
-
Bob Lord ๐ :donor:replied to Zack Whittaker last edited by
@zackwhittaker
Human error describes the proximate cause of an incident, not the root cause.
Human error is a symptom, not the cause, of failure.ย
Human error is a social judgment, not an objective conclusion.
Human error is the start of the investigation, not the conclusion.
Human error can reveal systemic design flaws in the system that fail to account for human use.
Human error as a conclusion will lead to myopic and insufficient remedies like โuser educationโ.
Human error is a label that shifts responsibility from system designers to system users who will inevitably fail.๐ฆ๐๐๐๐ฒ๐บ๐ ๐๐ต๐ฎ๐ ๐ณ๐ฎ๐ถ๐น ๐ฏ๐ฒ๐ฐ๐ฎ๐๐๐ฒ ๐ผ๐ณ ๐ฎ๐ป ๐ถ๐ป๐ป๐ผ๐ฐ๐ฒ๐ป๐ ๐บ๐ถ๐๐๐ฎ๐ธ๐ฒ ๐ฏ๐ ๐ฎ ๐ต๐๐บ๐ฎ๐ป ๐ฎ๐ฟ๐ฒ ๐ฑ๐ฒ๐๐ถ๐ด๐ป๐ฒ๐ฑ ๐๐ต๐ฎ๐ ๐๐ฎ๐. ๐ง๐ต๐ฒ๐ ๐ฎ๐ฟ๐ฒ ๐ฏ๐ฟ๐ถ๐๐๐น๐ฒ ๐ฏ๐ ๐ฑ๐ฒ๐๐ถ๐ด๐ป.
If you are curious as to why we should be intolerant of the label โhuman errorโ when talking about security incidents, please see Behind Human Error by David Woods and friends.
-
-
-