

Today, I'm going to talk about a shameful topic. 今天,我要谈一个难以启齿的话题。
This has happened to many of us, and it's embarrassing , but if we don't talk about it, nothing will ever change. 很多人都有这样令人尴尬的经历, 但如果我们放着它不谈, 我们将永远不能改变现状。
It's about being hacked . 这个经历就是被黑客入侵。
Some of us have clicked on a phishing link and downloaded a computer virus. 有些人点击了网络钓鱼链接 并因此下载了电脑病毒,
Some of us have had our identities stolen. 还有些人的身份被盗取了。
And those of us who are software developers might have written insecure code with security bugs in it without realizing it. 那些软件开发工程师 有可能写了不安全的 有安全漏洞的代码, 却毫无意识。
As a cybersecurity expert, 作为一个网络安全专家,
I have worked with countless companies on improving their cybersecurity. 我为无数公司工作过, 帮他们提升网络安全性。
Cybersecurity experts like me have advised companies on good cybersecurity practices, monitoring tools and proper user behaviors. 像我这样的网络安全专家 建议过公司 采取良好的网络安全实践, 监控工具, 以及正确的用户行为。
But I actually see a much bigger problem that no tool can fix: the shame associated with the mistakes that we make. 但我其实认识到了一个更大的, 没有工具能够解决的问题: 伴随犯错出现的羞耻感。
We like to think of ourselves as competent and tech savvy , and when we make these mistakes that can have a really bad impact on us and our companies -- anything from a simple annoyance , to taking a lot of time to fix, to costing us and our employers a lot of money. 我们喜欢将自己视为 有能力且精通技术的人, 但当我们犯错时, 这些错误不管是对个人还是公司 可能会有很糟糕的影响—— 其中包括一个简单的小麻烦 到需要很长时间去解决 且耗财耗力的大问题。
Despite billions of dollars that companies spend on cybersecurity, practitioners like me see the same problems over and over again . 虽然公司在网络安全上 花了几十亿的美元, 像我这样的专业从业者 还是反复看到相同的问题。
Let me give you some examples. 让我给你几个例子。
The 2015 hack of Ukrainian utilities that disconnected power for 225,000 customers and took months to restore back to full operations started with a phishing link. 2015 年, 一次乌克兰公共设施被黑事件 导致 22.5 万客户的断电经历。 这场始于网络钓鱼链接的危机 花了数月才恢复全面运行。
By the way , 225,000 customers is a lot more 225,000 people. 顺便一提,22.5 万位客户 可远多于 22.5 万名个体。
Customers can be anything from an apartment building to an industrial facility to a shopping mall . 客户可以是任何形式—— 再到一个购物中心。
The 2017 data breach of Equifax that exposed personally identifiable information of 140 million people and may ultimately cost Equifax something on the order of 1.4 billion dollars: 2017 年 艾可飞(Equifax)的信息泄漏事件 暴露了 1.4 亿人的 个人身份信息, 最终可能导致 公司 14 亿美元的损失。
that was caused by an exploitation of a well-known vulnerability in the company's customer consumer complaint portal . 事件的起源是一个众所周知的 隐藏在客户投诉网站中的漏洞。
Fundamentally , this is about technology and innovation . 归根结底, 这一切与科技创新有关。
Innovation is good; it makes our lives better. 创新是好的, 能提升我们的生活水平。
Most of the modern cars we drive today are fundamentally computers on wheels. 今天,大多我们所驾驶的机动车 本质是车轮上的计算机。
They tell us where to go to avoid traffic, when to take them in for maintenance and then give us all kinds of modern-day conveniences . 它们告诉我们免堵车路线, 什么时候车子需要保修, 给我们带来了很多现代化的便利。
Many people use connected medical devices like pacemakers and glucose monitors with insulin pumps . 很多人使用互联医疗设施, 例如起搏器 和带有胰岛素泵的血糖监控器。
These devices make these people's lives better and sometimes even extend their lives. 这些设备让用户的生活更美好, 有时甚至延长了他们的寿命。
But anything that can be interconnected can be hacked when it's connected. 但是,任何可互联的设备 在被连接时都有可能被黑。
Did you know that the former US Vice President Dick Cheney kept his pacemaker disconnected from Wi-Fi before he received a heart transplant ? 你知道吗?前美国副总统 迪克 · 切尼(Dick Cheney) 在做心脏移植手术前 切断了他的起搏器的网络连接。
I will let you figure out why. 我想让你自己品味其中缘由。
In a digitally interconnected world, cyber risks are literally everywhere. 在一个数字互联世界里, 网络危险真的无处不在。
For years, my colleagues and I have been talking about this elusive notion of cybersecurity culture. 多年来,我和我的同事们 都在谈论 一个难以捉摸的概念—— 网络安全文化。
Cybersecurity culture is when everybody in the organization believes that cybersecurity is their job, knows what to do and what not to do and does the right thing. 网络安全文化 是指当组织的每个人 都视网络安全为己任, 知道该做什么和不该做什么 并且做正确的事。
Unfortunately , I can't tell you which companies do this well, because by doing so, I would put a juicy target on their backs for ambitious attackers . 虽然我不能告诉你 哪些公司在这方面做得很好, 因为这么做 会吸引那些雄心勃勃的黑客们, 从而给那些公司招来麻烦。
But what I can do is make cybersecurity less mysterious , bring it out into the open and talk about it. 但是我能做的 是使网络安全变得不那么神秘: 把它带到公众面前,并公开谈论它。
There should be no mystery or secrecy within an organization. 一个组织里不应该有秘密。
When something is invisible and it's working, we don't know that it's there until it's not there. 当一个隐形的东西正在产生影响, 在它消失之前, 我们不会知道它的存在。
Kind of like toilet paper . 这有点像厕纸。
When the COVID-19 pandemic began, what has been there all of a sudden became super important because we couldn't find it anywhere. 当新冠大流行病开始时, 平凡的厕纸 因为我们无法随处可见它的存在 突然变得很重要。
Cybersecurity is just like that: when it's working, we don't know, and we don't care. 网络安全也是如此: 当它正常运作时, 我们不知道也不关心;
But when it's not working, it can be really, really bad. 但当它出现故障时, 事情可以变得非常,非常糟糕。
Toilet paper is pretty straightforward . 厕纸的例子相对直接易懂。
Cybersecurity is mysterious and complex . 网络安全神秘且复杂。
And I actually think it starts with the notion of psychological safety. 我其实觉得 网络安全始于心理安全感的概念。
This notion was popularized by an organizational behavior scientist, 这一概念 是由一位组织行为学家普及开的,
Amy Edmondson. 她叫艾美 · 埃德蒙森。
Amy studied behavior of medical teams in high-stakes situations like hospitals, where mistakes could be fatal . 艾美研究了医疗团队在 高危险环境(例如医院)中的行为。 在这一环境下,错误可以是致命的。
And she found out that nurses were not comfortable bringing up suggestions to the doctors because of the fear of questioning authority . 她发现护士不愿意 对医生提出建议 因为他们害怕质疑权威。
Amy helped improve medical teams to make nurses more comfortable bringing up suggestions to the doctors for patient treatment without the fear of being scolded or demeaned . 通过让护士们更愿意 向医生提出病人的治疗建议, 而不屈服于被训斥或轻视的恐惧, 借此,艾美帮助医疗团队 提升团队行为表现。
For that to happen, doctors needed to listen and be receptive -- without judging. 为了这一改变的发生,医生需要 学会聆听且善于接受意见—— 而不是批判。
Psychological safety is when everybody is comfortable speaking up and pointing things out. 心理安全感指的就是 每个人都愿意发表自己的看法 并指出问题。
I want cybersecurity to be the same. 我希望网络安全也是如此。
And I want cybersecurity practitioners to be comfortable bringing suggestions up to senior executives or software developers, without being dismissed as those people who continue to talk about horrors and errors, and say no. 而且我希望网络安全从业人员 也能对高管或软件开发者 勇于提出建议, 而不是被忽视为一群一直谈起可怕事件与错误 并且只会说“不”的人。
Not doing so is really hard for the individuals who are responsible for the creation of digital products because fundamentally, it's about their pride and joy in their creations . 对那些数字产品的研发负责人来说, 不勇于提议的后果很严重。 其根本原因是这些人 对自己创作成果的自豪和喜悦。
I once tried talking to a senior software development executive about the need to do better security. 我曾经试着告诉一个 软件开发高级管理人员 他们需要提升安全性能。
You know what he said? 你猜他怎么说?
'"Are you telling me we're developing insecure code?" “你是在告诉我 我们的代码不安全吗?”
In other words, what he heard was, "Your baby is ugly ." 换句话说,他听到的是 “你的孩子不好看”。
What if instead of focusing on what not to do, we focused on what to do? 如果相反,我们不强调“不做什么”, 而是关注“做什么”呢?
Like, how do we develop better software and protect our customer information at the same time ? 例如,我们怎样开发更好的软件 并同时保护我们的用户信息?
Or how do we make sure that our organization is able to operate in crisis , under attack or in an emergency ? 或者如何确保 在面临危机、攻击或紧急情况下 我们的组织能够正常运作?
And what if we reward good things that people do in cybersecurity in some way and encourage them to do so, like reporting security incidents, reporting potential phishing emails, or finding and fixing software security bugs in the software that they develop? 如果我们通过某种方式奖励 在网络安全方面人们做得不错的地方 并鼓励他们这么做, 例如汇报安全事件, 报告潜在的网络钓鱼邮件, 或是识别并修复 他们研发软件中的安全漏洞, 事情又会怎么样?
And what if we tied these good security actions to performance evaluations to make it really matter? 如果我们将这些优秀的安全行为 与绩效评估联系起来 使网络安全成为一个值得认真对待的问题 又会发生什么?
I would love for us to communicate these good cybersecurity things and encourage them in some sort of company-wide communications like newsletters , blogs , websites, microsites -- whatever we use to communicate to our organization. 我非常愿意大家交流 这些好的网络安全事例 并在公司范围的交流中 鼓励网络安全规范, 例如简报、博客、网站, 和微网站—— 任何我们用来和内部组织交流的平台。
What if a company announced a competition for who finds the most security bugs and fixes them in a two-week development sprint and then announces the winner of the competition for the quarter at a large company virtual town hall , 或许公司可以举办一场比赛, 比拼谁找到的安全漏洞最多 并能在两周的开发冲刺中修复它们, 之后在一个巨大的公司虚拟大厅 宣布这一季度比赛的冠军。
and then rewards these people, these winners, with something meaningful , like a week's vacation or a bonus. 随后公司可以用一些有意义的东西 奖励这些获奖者, 像是一个星期的休假或奖金。
Others will see the celebration and recognition , and they'll want to do the same. 其他人对这样的表扬和认可 有目共睹, 因此也会跃跃欲试,想赢得比赛。
In the energy industry, there is a really strong culture of safety. 在能源行业, 有一种很强的安全文化。
People care about this culture, are proud of it, and there is a collective reinforcement of this culture to make sure that nobody gets hurt. 人们很关心这种文化, 并为此感到骄傲。 这种安全文化存在集体强化 来保障没有人受伤。
One of the ways they exhibit and keep this safety conscious culture going is by counting and visibly displaying days since the last safety incident. 人们展现并维持这种安全意识文化的 其中一种方式 就是计算并可视化 距离上次安全事故已经过去了多少天。
And then everybody works really hard not to have that count go back to zero because that means that somebody did get hurt. 于是,每个人都非常努力地 避免这个数字归零, 因为归零意味着有人受伤了。
Cybersecurity is the same as safety. 网络安全和人身安全一样。
What if we all agree to keep that count of days since the last cybersecurity incident going on forever and then work really hard not to have it reset to zero? 如果我们齐心协力 将自上次网络安全事件后 过去的日子 一直计算下去 并努力不让其归零,
And then certain things are a no-no, and we need to clearly communicate to our organizations what they are in an easily digestible and maybe even fun way, like gamification or simulations , to make sure that people can remember this. 同时,有些事情是绝对不允许的, 我们需要用一种简单易懂的方式, 甚至是有趣的方式, 例如通过游戏或模拟, 在组织内 明确告知哪些事是被禁止的 以确保人们将其铭记于心。
And if somebody does something they're not supposed to do, they should face some sort of consequences . 如果有人做了不该做的事, 他们应该面对某种后果。
So, for example, if an employee buys equipment on Amazon or eBay or uses personal Dropbox for their company business, then they should face some sort of consequences. 举个例子来说,如果一个员工 用亚马逊或 eBay 购买了设备, 或用个人云存储服务账号 处理了公司业务, 他们就应该面对惩罚。
And when this happens, executives should get the same treatment as regular employees, because if they don't, then people won't believe that it's real and will go back to their old behaviors. 同时,经理也应像普通员工一样 受到同样的处置, 因为如果不这么做, 人们不会认真对待这件事 并且会重拾恶习。
It's OK to talk about mistakes, but just like a teenager who violates the rules tells us about it, we appreciate that they told us about it, but there should still be some sort of consequences. 谈论错误是可以接受的, 但就像违反规则的青少年 对此坦白一样, 我们应该感谢他们的诚实, 但他们依然应该面对后果, 为自己的行为负责。
Cybersecurity is a journey . 网络安全是一段旅程。
It's not a destination, and we need to keep working on it. 它不是一个目的地, 所以我们要持续为之奋斗。
I would love for us to celebrate cybersecurity people like the heroes that they are. 我希望我们能够赞颂 英雄般的网络安全从业人员。
If we think about it, they are firefighters , emergency room doctors and nurses, law enforcement , risk executives and business strategists all in the same persona. 如果我们仔细想想, 他们其实集消防员、 急诊医生和护士、 执法人员,风险主管, 和商业战略家 于一身。
And they help us protect our modern life that we like so much. 他们帮我们保护着 我们如此喜爱的现代生活。
They protect our identities, our inventions, our intellectual property , our electric grid , medical devices, connected cars and myriad other things. 他们保护我们的身份、 发明、知识产权、 电网、医疗设施、 联网车辆,和很多其它东西。
And I'd like to be on that team. 我很愿意做这个队伍的一员。
So let's agree that this thing is with us to stay, let's create a safe environment to learn from our mistakes, and let's commit to making things better. 所以,让我们一致同意: 网络安全与我们同在。 让我们创造一个 可以从错误中吸取教训的安全环境, 并共同致力于创造更好的世界。
Thank you. 谢谢。