Cyber-preparedness: Try the Five Minute Micro-Exercise

Cyber-preparedness: Try the Five Minute Micro-Exercise

Cybersecurity continues to be an evolving threat to the public and to our nation.

Micro-exercising is a concept in physical fitness where people engage in a short, targeted workout or slightly increase the intensity of a normal activity in whatever location or during whatever time they have available – think taking the stairs versus the elevator, or working while standing up instead of sitting at your desk. In the same vein, we can apply a similar approach to cyber-preparedness, as we recognize the number of vulnerabilities created through users’ behavior, activities, or other human errors.

Protecting networks and critical infrastructure from malicious attacks, equipment failure, human errors, and honest mistakes involves applying overlapping security controls in the context of strategies that may be opaque or seem incredibly complex to an authorized system user. When that happens, people may become less conscious of their activities as they are either overwhelmed with information or they think, “Someone else is taking care of this.” While that is often true and even as cybersecurity techniques evolve with proactive technologies to remove vulnerabilities or stem an attack before it happens, we still find that we often react to cyber incidents after the fact.

Enter the micro-exercise. Cybersecurity exercises that receive the most publicity are national in scale and have a broad scope intended to test, validate, or identify weaknesses in large-scale cybersecurity strategy. Beyond that, I often wonder how many system users actually get to participate in any cyber-exercise. I suspect it is not very many and, therefore, people may not have had the opportunity to reflect or understand cybersecurity best practices or response methods.

Managers have an opportunity, and potentially a responsibility to their organization, to provide that opportunity by starting with a simple question: “What would you do if you receive an email with an attachment from someone you don’t know?”  Or, “You see an antivirus alert on your computer, so you…?”  Or, “You are unexpectedly prompted to enter your user ID and password. Should you do that? Should you report it?”

It does not take a full-scale exercise to keep a network healthy. 

Ask the question in a staff meeting and have a five-minute conversation about what should happen next. If people don’t know the answer, rather than being “wrong”, it may mean that there is an opportunity to direct them to an authoritative source, to some awareness materials, or that there is a gap in policy, procedure, or awareness that can be addressed with the IT organization. When this is the case, they will be glad you asked.

Blog Cybersecurity

Contributors

Arc Aspicio |

Arc Aspicio enhances the future of our nation by creating bold ideas and bringing them to life. A consulting and solutions company, Arc Aspicio solves problems by applying our integrated capabilities in strategy, design, data, human capital, behavioral science, and technology. The company passionately pursues our vision to be the hub of creativity where people take action to change the world. To do this, employees collaborate with clients and partners to create solutions using a human-centered approach. Innovation is not possible without action. The company focuses on strategy first, then takes a hands-on approach implementing ideas to achieve results. Join Arc Aspicio and our Strategy Innovation Lab (SILab) by creating and sharing ideas to inspire people to change the world. Follow us on Twitter @ArcAspicio @SILabDC and, #welovedogs!

GSA Awards Arc Aspicio OASIS+ WOSB Contract

GSA Awards Arc Aspicio OASIS+ WOSB Contract

Arlington, VA, October 18, 2024 – GSA awarded Arc Aspicio the OASIS+ Woman-owned Small Business (WOSB) Indefinite Delivery/Indefinite Quantity (IDIQ) contract. A Government-wide contract vehicle, OASIS+ WOSB allows Arc Aspicio to competitively bid on opportunities to provide Federal government agencies with complex non-IT service requirements for the next 10 years, with no ceiling value and no cap on orders. Click to read more.

Smithsonian Institution Awards Arc Aspicio Consulting Services Contract

Smithsonian Institution Awards Arc Aspicio Consulting Services Contract

Arlington, VA, August 20, 2024 – The Smithsonian Institution selected Arc Aspicio as one of 11 firms on a 10-year Indefinite Delivery Indefinite Quantity (IDIQ) contract. This contract enables Arc Aspicio to provide the world’s largest museum, education, and research institution with services that support its transformation of learning and discovery – in person and digitally. Click to read more.

Arc Aspicio Celebrates 20th Anniversary Serving the Government

Arc Aspicio Celebrates 20th Anniversary Serving the Government

Arlington, VA, August 6, 2024 – Arc Aspicio announced its 20 years of service to the Federal government in solving complex challenges as they serve the American public through innovative consulting and professional services. Starting with an intense focus on homeland security, where it supported 154 projects for the Department of Homeland Security (DHS) and its agencies, the company has expanded into justice and law enforcement, museums and education, and serving non-profit organizations. Click to read more.

Seeing is Believing: Design+Data in Leadership Decision Making

Seeing is Believing: Design+Data in Leadership Decision Making

In an era of data abundance, Federal agencies face the challenge of distilling vast amounts of complex information into actionable insights. To unlock the potential of data to inform strategic decision-making and policy and program implementation, traditional information presentation methods may fall short, occasionally leaving federal leaders without actionable insights.

Equity in Emergency Management: How Behavioral Science Can Help Support Preparedness and Disaster Response

Equity in Emergency Management: How Behavioral Science Can Help Support Preparedness and Disaster Response

In recent years, there have been many challenges driven by climate change that pose significant threats to our nation’s safety and security. More frequent and severe weather events continue to devastate communities around the world, even making some places uninhabitable.

Innovation and Ideation for Success: Innovation Labs

Innovation and Ideation for Success: Innovation Labs

Internal Innovation Labs are key to enhancing innovation and collaboration in Federal agencies. They allow employees the opportunity to engage in creative processes, such as brainstorming, design thinking, and creativity, which create solutions and spur innovation. These techniques allow organizations to solve complex problems and implement solutions efficiently.

Chief Executive Officer Lynn Ann Casey Named Outstanding Leader in 2024 Engage Homeland and National Security Honorees

Chief Executive Officer Lynn Ann Casey Named Outstanding Leader in 2024 Engage Homeland and National Security Honorees

Arlington, VA, November 7, 2023 – OrangeSlices has named Arc Aspicio Chief Executive Officer (CEO) Lynn Ann Casey as an outstanding leader in the 2024 Engage Homeland and National Security Honorees. This honor recognizes leaders who are driving real and measurable change in the way government and industry collaborate, sharing their insights and expertise for the betterment of all, and driving forward the key missions of the Federal government. Click to read more.

Good Data, Bad Data: The Value of Data Quality in Homeland Security

Good Data, Bad Data: The Value of Data Quality in Homeland Security

Homeland Security is a complex mission, one that is both vast in scale and broad in scope, and this creates a large volume of data that can help provide insight into operations and strategic decisions. From disaster preparedness to counterterrorism, Federal employees rely heavily on an abundance of data to assess problems accurately and implement effective solutions.

Transforming Government: The Road to Agile and Customer-Centric Modernization

Transforming Government: The Road to Agile and Customer-Centric Modernization

The Federal government has been making significant strides in technology modernization, shifting its focus from addressing only the most critical needs to becoming more agile, customer-centric, and innovative. As government agencies transition from an era dominated by the necessity of migrating their data and applications to cloud-based platforms, mission leaders are now turning their attention to emerging technologies like data visualization, customer experience improvement, low-code software tools, and artificial intelligence (AI).

Arc Aspicio Reappraised at CMMI-Services Maturity Level 3

Arc Aspicio Reappraised at CMMI-Services Maturity Level 3

Arc Aspicio achieved its second Capability Maturity Model Integration Services (CMMI-SVC) Level 3 Certification on September 29, 2023. CMMI is a Model that is used to guide process improvement across projects, divisions, and organizations. Arc Aspicio uses CMMI, a process level improvement training and appraisal program recognized for Government and commercial clients, as an indicator of high-quality performance.

The Link Between Innovation and Collaboration

The Link Between Innovation and Collaboration

Intentional collaboration can be the difference between simply completing a task and using innovative ideas to drive long-lasting change. When people come together to share their insights and perspectives, Government agencies can thrive and instill a culture where leaders engage with and listen to employees. In turn, these environments lead to more commitment from employees, as well as better Government agency relationships that help promote working towards strong solutions.

Design Thinking Techniques to Enhance the Online Meeting Experience

Design Thinking Techniques to Enhance the Online Meeting Experience

According to the Harvard Business Review, the average worker has attended 13.5% more meetings since the COVID-19 pandemic, with many held online. Given the Federal government’s partial shift to remote work when feasible, it is increasingly important to consider how teams can enhance the effectiveness and engagement of online meetings.

From Resistance to Acceptance: All Management is Change Management

From Resistance to Acceptance: All Management is Change Management

Effectively navigating organizational changes within Federal agencies requires understanding the unique dynamics of the Federal context, strong leadership communication, culture development and stakeholder engagement and collaboration. Continuous evaluation and proactive management of resistance to change is important.