Security Metaphors, presented at BSidesIOWA 2015

by Josh More,

Summary : There is a divide between the so-called "security/technical" people and the "business" people. We've all heard about how we need to "speak the language of business" and "get soft skills" to succeed. However, even after decades of trying, the divide still exists. Why does it seem that we never make progress? Are we truly not improving? Is the goal receding as we chase it? This presentation posits that we've been making a fundamental error in trying to explain things to people outside our field. One thing that people-oriented people do naturally and technically-oriented people do not is communicate with others using the target's metaphors. By taking this approach and translating issues into different frames of reference, more time is spent exploring the issue instead of arguing over why it matters.