Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint

8/13/2019
05:40 PM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

Does Personality Make You Vulnerable to Cybercrime?

A new study explores the connections between personality traits and susceptibility to different cyberattacks.

Could extraversion make you more vulnerable to social engineering attacks? It's a possibility, as seen in research investigating links between personality traits and vulnerability to cybercrime.

The study, compiled by ESET and the Myers-Briggs company, drills down into the "human factor" responsible for many security breaches. Verizon's DBIR found 20% of security incidents originate from people within an organization; separate data from Dtex shows nearly two-thirds (64%) of insider threats come from people who put the company at risk with careless behavior.

Myers-Briggs' goal in this research is to determine whether individuals' personality traits make them more susceptible to different types of security threats. As part of an ongoing study, it has so far polled 520 respondents who had completed the Myers-Briggs Type Indicator (MBTI) questionnaire. John Hackston, head of thought leadership for the company, argues the MBTI is a practical starting point for personality-based research as many people and businesses already use it for self-development.

If you're not familiar, the MBTI quantifies "best-fit" personality type using four traits: extraversion/introversion (E/I), which shows where you get energy; sensing/intuition (S/N), which indicates how you learn information; thinking/feeling (T/F), which tells how you make decisions; and judging/perceiving (J/P), which indicates whether you prefer a more structured or open-ended lifestyle. For the security-focused study, respondents also answered questions about their jobs, biographical data, cybersecurity habits, phishing experiences, and overall security knowledge.

"Everybody in an organization is an insider risk when it comes to cybersecurity," says Hackston. "We want to look at how MBTI relates to those to give people guidelines … so they can have guidelines to say 'What things should I look out for?' and 'What things might be my particular downfalls if I'm not careful?'"

There is no single personality type that's more security-savvy than the others, he explains. Similarly, being security-savvy doesn't necessarily mean someone is a lower-risk employee. Oftentimes, security practices boil down to the two middle letters of the MBTI type, which are intended to dictate how an individual processes data and how they make decisions.

As an example, Hackson points to the personality type INTP: a logical, analytical, detail-oriented and introverted person. Myers-Briggs' research shows people who are INTPs score higher on questions about cybersecurity knowledge; unfortunately, they're also more likely to think rules don't apply to them. An ESTP, an extraverted type who focuses on facts and logic, is also likely to flout rules.

The way a phishing attack is communicated can make a difference in which types fall for it, Hackston adds. An email that seems factual and promises someone can save money or be more efficient, for example, will be more effective on the objective, analytical "ST" types. The trusting, loyal "SF" type may be more likely to respond to an email that claims to be from an authority figure, and the warm, altruistic "NF" may fall for a phishing attack disguised as a charity email.

In general, researchers found, extraverts are more likely to fall for social engineering attacks. Their need to stay in tune with the world is "both a boon and a curse," Hackston says. While they're informed of new threats, extraverts' tendency to focus on people puts them at risk. A desire to build a personal connection may lure an extravert into a social engineering trap.

The Big 5

Of course, the MBTI isn't the only way to classify personality. Dr. Margaret Cunningham, principal research scientist for human behavior with Forcepoint X-Labs, has explored security risk alongside the "Big 5" personality traits: neuroticism, extraversion, openness, agreeableness, and conscientiousness, and she agrees extraversion can prove risky.

"We find in the Big 5 personality [traits] that agreeable people tend to be more willing to share information, which makes them more susceptible to social engineering attacks," she adds. When asked what they're doing, an extravert is more likely to be immediately transparent.

Conscientious people lean toward the practical side and use greater caution, she says. "These are the people who read service agreements," she jokes. "They're going to check the settings on a cookie pop-up. Those people tend to be a little less likely to [fall for] phishing attempts."

At the same time, it's important to note personality is a spectrum, Cunningham emphasizes. It's the people who exhibit the extremes of different personality facets who are easiest to associate with predictive behavior. You can be a detail-oriented extravert, for example, or an introvert who accidentally spills too much information to an attacker or falls for a phishing email.

"Knowing that these are the things that push our buttons helps us to be more wary," says Hackston. Security awareness training isn't a "one size fits all" project, and while organizations can't be expected to build different training programs for each personality type, it helps to inform employees where their weaknesses may lie so they're attuned to potential threats. As Cunningham says, people will continue to make mistakes even if they are informed of the risk.

"No matter how aware we are, we will continue to make mistakes and be phished," she says. "We'll continue to click not because of personality, but the limitations we have in cognitive skills like memory and attention."

Related Content:

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
Data Leak Week: Billions of Sensitive Files Exposed Online
Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/10/2019
Intel Issues Fix for 'Plundervolt' SGX Flaw
Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/11/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
The Year in Security: 2019
This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-5252
PUBLISHED: 2019-12-14
There is an improper authentication vulnerability in Huawei smartphones (Y9, Honor 8X, Honor 9 Lite, Honor 9i, Y6 Pro). The applock does not perform a sufficient authentication in a rare condition. Successful exploit could allow the attacker to use the application locked by applock in an instant.
CVE-2019-5235
PUBLISHED: 2019-12-14
Some Huawei smart phones have a null pointer dereference vulnerability. An attacker crafts specific packets and sends to the affected product to exploit this vulnerability. Successful exploitation may cause the affected phone to be abnormal.
CVE-2019-5264
PUBLISHED: 2019-12-13
There is an information disclosure vulnerability in certain Huawei smartphones (Mate 10;Mate 10 Pro;Honor V10;Changxiang 7S;P-smart;Changxiang 8 Plus;Y9 2018;Honor 9 Lite;Honor 9i;Mate 9). The software does not properly handle certain information of applications locked by applock in a rare condition...
CVE-2019-5277
PUBLISHED: 2019-12-13
Huawei CloudUSM-EUA V600R006C10;V600R019C00 have an information leak vulnerability. Due to improper configuration, the attacker may cause information leak by successful exploitation.
CVE-2019-5254
PUBLISHED: 2019-12-13
Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG6000V;eSpace U1981) have an out-of-bounds read vulnerability. An attacker who logs in to the board m...