Darren Richardson: Nine-to-Five and then F*ck It - Maintaining Psychological Safety in Technology
About this talk
In this talk, Darren Richardson addresses the critical issue of psychological safety in the technology sector, particularly within cyber security. He discusses the alarming rates of burnout among tech workers, highlighting that a significant percentage have experienced increased workloads and stress. The speaker emphasizes the importance of open communication, trust, and the need to advocate for oneself in the workplace. He critiques the culture of overwork, often fueled by unrealistic expectations set by management and societal norms. Additionally, Richardson explores the impact of external pressures from sensationalist cyber security reporting, arguing for the necessity of fostering a supportive environment where employees can thrive without fear of burnout.
Full transcript
[Music] ladies and Gentlemen please welcome our next speaker Darren Richardson presenting the topic 9 to5 mnfc maintaining psychological safety in technology we start with this picture this why we start with this picture I don't need to shout this is why we're here there's this interesting phenomenon that we're seeing you can see the English translation in the middle Europe refuses to work hands up how many people here
refuse to work one two thank you for being honest it really kicks things up at this point we're all here because we're working this this is our job this is what we do but there's this weird mentality against people who are working to live instead of living to work people who don't just want to be wage slaves don't want to work 80 hours a week what have
you so that's what brings me to my talk 9 to5 and then [ __ ] it this is how I maintain sanity in cyber security but to do this we have to learn a little bit about me I am an entirely sensible cyber professional I'm not a morning person so thank you whoever put me on at 9:00 a.m. I I normally wouldn't be awake for another I don't even
know where my watch is at this point in time so yeah I'm a morning person at all I am a cyber security professional I am usually a serious cyber security professional but as you can probably tell by my socks and my bright pink shoelaces I'm occasionally quite a silly person but I do work in cyber security I do have some experience in infrastructure iot and Ai and
at times I actually believe I do a good job impostor syndrome is a thing we to talk about but I want to talk about how we balance these things but first we need to talk about what is psychological safety and there's this excellent diagram here of what it is there are lots of aspects to safety the four key ones the feeling of inclusion the ability to learn
the ability to contribute and the ability to challenge and and most of this requires open communication respect trust encouragement of risk-taking that's a kind of key one non-punitive response to failure you shouldn't be punished for failing you should learn from failures it shouldn't be something you're afraid of and of course feeling included the benefits of psychological safety are Paramount obviously it will make you feel better about
your jobs it will make you be feel better about yourself but it will also tackle one of the largest issues we are facing today burnout in Tech show of hands how many people feel like they know someone experiencing burnout in technology hands up how many of you are that person who's experiencing burnout technology surprising number of hands you think but as we move on when we realize
that most of our work days look like this and we're just sat in the middle accepting it this is a problem and I have some numbers here approximately 71% of tech workers have experienced an increased workload in the past year that contributes to higher stress and burnout levels 71% of people are seeing that workload this means that a year or two down the line we might end
up with 71% of it professionals burning out if you'd like to know what percentage of them are currently burning out I don't know but there are some numbers floating around and they're wildly different one of them states that it is 31% one of them States as high as 59 we're seeing the two highest burnout rates among Tech workers and the financial sector Financial being 51% Tech being
57 I just want to take a moment to let that sink in more than half the people that you work with will experience burnout at some point in your life does that sound sustainable does that sound useful do we want half of our Security Professionals half of our it professionals experiencing burnout is that the direction we want to take our industry 7 uh sorry what's the statistic
let me get this 56% of it professionals cannot relax after their work day they take work home with them they take it to a place where they cannot switch off where they carry the weight of what's happening with them as they go home as they go to sleep and when they wake up and if you can't relax after your workday you are already burned out I'm sorry
that is an uncomfortable truth about the situation if you go home and you lack the ability to switch off you are burnt out and I'm sorry but hopefully the rest of this talk won't be as depressing as the entrance was I'm kind of hoping I'll pick it up to a more positive vibe but we'll see how that goes but I do want to mention our good friend
chat GPT and this is something I want to quote directly quiet quitting slork to contract talking points quiet quitting and working to contract refer to employees doing only what is explicitly required in their job descriptions are not taking on extra tasks or working Beyond their official hours this can be seen as a response to burnout poor work life balance and a lack of recognition or advancement opportunities
we talk about bias in AI quite a lot and this is my favorite instance of it because it shows how ingrained this idea of going above and beyond this it is not enough anymore to just do your job you have to be doing above what is required of your job that to me is unfair it is unsustainable and it's something we're going to talk about right now
with coping strategies I actually hate the word coping coping strategies it's negative it implies that it is something problematic like the word coping shows that without these you are struggling it applies a negative connotation and I think it is important how we represent these things coping is the ideal situation and yet we view it negatively so we're just going to say strategies seems like an easier way
to approach it then of course I don't like the word strategies so I'm not even sure why I made this first Slide the strategies are kind of useless if you don't talk about the reason why these things exist so third times the charm root causes and strategies and I'm going to start by talking about the number one root cause for all psychological safety issues at workplace it's
your boss don't tell them I said this actually do please go and tell your bosses that I said they're the problem and I want to see how many angry emails get the fact is your boss exists for two purposes one is to represent you towards management and the second is to represent management towards you in my opinion when I was a manager that's how I did things
and it was ideal because it meant everyone hated me what happened is my subordinates thought I was with management and manag thought I was with subordinates and I don't think this was actually a useful leadership method when it comes down to it but it was what I tried and what that meant is that my managers were unhappy my subordinates were unhappy and no one was getting what
they need now I can just put a funny slogan here and say hey your boss is the problem but I do want to get into it here are some of the things that your may or may not be causing the first being skeleton Crews how many of you think that your it and security teams are understaffed about 60% of you how many of you believe that your
it and security underfunded about the same number how many believe this is a carefully constructed social engineering attack to gather information about your security teams okay kudos to those who didn't put their hands up 2% is the normal amount spent on security and it teams of turnover people suggest that a good number is 6% on average you're seeing 2% these numbers are based on my investigation because
if youve ever investigated numbers about this you end up with wildly Divergent results from different sources this is me collecting them together so they may be accurate they may just be me painting a pessimistic picture 1% spent on security 83% of security teams are staffed we've already talked about the 71% increased workload most people have a ratio of 200 or more users to one security staff or
IT staff and the most frightening statistic to me 66% of users or companies believe they are not targets when it comes to hackers they believe they are too small they believe they are irrelevant they ask the question why oh why would the attackers Target us we're just an innocent company doing nothing of interest to anyone has anyone ever gone to a ransomware group's website and scrolled down
the list of compromised targets it's a fascinating experience where you find tens of thousands of innocent companies who weren't doing anything wrong they just happened to exist this is how attacks work and it's something we need to talk about no one is being targeted attacks are General but that doesn't mean they don't include you they do they're just not targeted at you and this is the main
problem you'll have with your boss in my experience you will have people who do not listen when you say we are vulnerable we are a Target even if we are small even if we are a startup even if we're not profitable yet we are vulnerable an interesting statistic came up when I was doing a previous talk which was 60% of companies will never recover after a serious
ransomware attack they will simply not be able to get out under the weight of the problems caused and they will fold within six months it's fascinating when you tell that statistic to people who believe they are not a target try it see what happens another thing you may see is manipulation and there is a couple of good examples of this the first if you have someone who
tries to make you as an engineer feel like it is your fault that you are underst staffed this is probably the most common example of manipulation of someone making you believe that you have to do more because a proper investment has not been made they make it personal responsibility and the thing you do for both of these ISS oh there's actually one more I want to talk
about here now that I come to think of it how many of you have had a boss who said we're like family yep plenty of hands up thank you for admitting it we are like a family I've had bosses who said that to me I've had bosses who fired me who said me this is kind of an interesting situation we are like a family if you die
tomorrow your family will not be auditioning for your replacement the next day your company will and I don't want to seem anti-b business the company should be doing that because it is a company it is not your family you are replaceable I am replaceable we are all replaceable and and that is how we need to see our jobs and this brings us to the first action point
I'm sorry I've been such a downer up until now but we're going to talk about this for a minute advocation advocation means standing up for yourself for the things you need inside a company you have to voice your needs early and you have to voice them often I was once in a situation where I was saying uh the workload is kind of high but it's okay for
now and I didn't realize that what my boss was hearing at that point was the workloads okay I was saying I was managing and he was hearing you're managing just fine this went on for two and a half years and what we need to take from this is that we have to advocate for what we need if you are part of a security team which is underst
staffed you need to make that known if you are part of an IT team that known if you are part of a situation where you do not have the ability to do a job you are required to do without throwing extra hours at it you need to make that known because you saw from the start Europe refuses to work that's what Europe is doing we're refusing to
work I don't even know where that comes from it's water nonsense what we need to do is say this is what we need to do our work if we do not meet this Baseline the work cannot be completed I would like to complete complete the work however I need it to be within this framework within the agreed reasonable constraints and I want to say here I'm not
saying you should never ever work overtime that's something else we're going to come to very shortly if you need to work overtime that's fine if it is persistent over time you have a problem and that leads leads us to the second biggest problem it's you and there were a couple of Chuckles around the room when I said hey it's your boss a couple of people like that
not a single smile when I say it's you no one is amused by this but hands up if you are in fact a fully functioning adult few more hands yep what I did when I told to my boss hey the workload is high but it's okay for now is I gave him permission to keep that workload where it was whose fault was it it was mine it
was my fault for not being clear about what I needed by saying yes this is a high workload but I can handle it this is my problem and this is the thing we are all adults here we need to communicate what we need who we are and I realize this slide may make you feel a attacked if that is the case I can't wait to see your
response to the next one is this you from ages 5 to 18 maybe you started coding on something that plugged directly into a TV maybe you were socially awkward as a child did you spend way too much time online often at night did you mostly stay home not go out I'm guessing I'm describing 80% of the people in here I think that's probably Fair here come the
hard questions do you have a hobby that looks a lot like your job do you like to code casually do you do it daytoday regardless of if someone's paying you do you like to build server forms in bedroom do you have a home lab does your hobby feeds directly into your job again I'd like a show of hands anyone has a hobby that feeds directly into their
job raise your hand please more than half of you so we end up with this problematic situation where by the time we turned 21 those of us who had a Commodore 64 ZX Sinclair Spectrum I think in my case the one with the rubber keys and the space button we got to 21 and then we were the 21 year olds with 15 years of experience that everyone's
looking for it was great for a while but that it set this unreasonable expectation that we create these high barriers that you are not enough in cyber security you are not enough in technology unless you grew up doing something like this unless you code as a hobby you'll see it in job listings you have to code for or a hobby casually what other industry makes a requirement
of free time as a like a method of entrance can you think of any of them do you think the finance sector is going home and pulling out their fun spreadsheets they've they're done with the boring ones now they're on to the interesting excels no of course they don't why would they do that that would be a ridiculous thing but for us it's perfectly normal because with
in Tech and this is the problem we need to learn to set boundaries boundaries are so useful a boundary is a very obvious thing it's a wall but it doesn't have to be a high wall it just needs to be a line saying this is the line I cross I'm going to ask you to raise your hands again how many of you have work notifications on your
phone basically all of you how many of you don't have work notifications on phone a few I'm proud of you like genuinely it's so easy to be pressured into being available 24 hours a day in security teams are underfunded teams are underand and we have this mentality that security issues are so problematic that if we don't resolve them the world will end and that may well be
the case however it was not the job of the engineer level people to ensure that sufficient resources were had for actually resolving issues 247 so the second you make yourself available 247 then you are and why would anyone invest if they don't need to this is important we have built a culture of compliance in the workplace where we do not advocate for ourselves where we do not
draw boundaries where we do not say no and one of the things that you should take away from this because I'm not breaking new ground here I'm not telling you anything lifechanging these are all Comm sense things that you know I'm hoping that me being here talk talking about them gives you permission to do them learning to say no is important and again I don't want to
be inflexible if you have to work late a couple of nights because there's a deadline that's fine why not who cares it's important that's that's how work Works you're allowed to take some over time time if overtime is your standard if you are working in a flexi time system and are perhaps sitting on more than 50 hours of free time that's when it becomes a problem learning
to say no is the most important skill you can pick up and it's difficult because you have managers who put expectations of you you might have subordinates who put expectations on you you might have family who put you it is important to be able to rise above expectations and say no don't end up like this this is a person posting how proud he was to be working
99 hours a week that's what 14 and a half hours a day or something presumably he spent the rest asleep look at how he phrases it I'm unstoppable and then the only response you're a victim you have become a victim of this work culture a culture that doesn't ask that you go above and beyond it demands it this is the harsh reality as I don't want to
be negative I understand this is how most of what I've said comes across I want to talk about some positive sides and one of them is the Flow State achieving a flow state state is one of the best things you can do for your psychological safety and this is a state where you are able to do your daily tasks without interruption without deviation without having anyone bothering
you and the best example of this is the bourma peak obviously this is how it works with the judicious application of alcohol I don't recommend you drink at work but it illustrates the point a lot of my work at least gets interrupted by people sending me messages it is okay to ignore them my work gets interrupted by people sending me meeting requests it is okay to reject
them it is okay to structure your work around yourself it is okay to advocate for yourself to set things up in a way where you're working environment works for you you do not always have to be compliant with the requirements of everyone else if someone's sending you a message asking hey can you take a look at this spreadsheet I need it by now actually I need it
5 minutes ago I don't know why I didn't send it to you earlier say no feel free to tell them sorry next Monday is the earliest I can look at that and return to your work and this is what we're talking about it's self advocation we've talked about advocating for your work but advocate for yourself make your needs known early make them known often you've probably all
heard the phrase the squeaky wheel gets the grease in the case of the over the overloaded workload in mine I wasn't the squeaky wheel I was the problem I wasn't myself so as a brief summary what can you do I've seen some people taking pictures if you're going to take a picture of a slide from this one bit of advice to take away it is this slide
I recommend you Commit This to Memory because you can do two things you can advocate for the company and advocate for yourself for your own needs couple of people still taking pictures I'm going to pause so the last thing I want to talk about is the third problem which is everyone else you never know what dumb thing a person will do to ruin your day and let's
turn that around you never know what stupid thing you will do to ruin someone else's day and I remember actually when I joined eff code I joined a week before log 4J and I was then put in charge of and I tried to make some security decisions I'd been in the company 5 days it was the stupidest thing I've ever done so you can do stupid things
and they will ruin other people's days we actually had one person move from Finland to Norway shortly after that and I like to believe it was my stupidity that drove him away so this is a object lesson but I want to talk about something that's actually relevant to us as cyber Security Professionals which is cyber security reporting I hate it I hate it so much the next
10 minutes of this is dedicated to angry ranting and I'm sorry but this said in October of 2022 we had this news report come out I'd like to direct you to this part of it say that everyone and I mean everyone will need to patch everyone that is a bold claim your grandfather who believes the internet is a Russian plot and only has a DVD player does
he need to patch no probably not a more serious example let's say you have a system running disconnected on a boat somewhere do they need to patch on patch day no they're not even reachable they're in the middle of the Arctic they're fine this title is clickbait at its worst and this is what we see in cyber security reporting a lot so to demonstrate how stupid this
is I'm going to come up with an even more absurd example tomorrow everyone's getting stabbed that's what's going to happen every single person will be stabbed the human race will collectively Hemorrhage what four 40 billion lers of blood and then the world will end you might say no I live on a lighthouse and there's no one around for Miles I'm definitely not getting stabbed and you're correct
this this article is complete [ __ ] and it's [ __ ] for a number of reasons because it does this kind of we used to have this uh saying it was keep and Carry On from the British royalty it had a little crown on the top we knew it was sincere then keep calm carry on cyber security reporting doesn't do that it's inight panic and then retract this is what
cyber security reporting looks like and I'm going to go back here just for a second this is just the headline if we actually dive into it this everyone and I mean everyone was for op SSL 3 which at the time of publishing was in use in one LTS version of Ubuntu that had been out for about three month uh six months do you know anyone who's patching
LTS systems in the first three months of release at the time of writing neither auntu I think 18 or 20 the long-term releases were out of service yet as far as I'm aware everyone was still on them and what that meant the installation candidate for op SSL was only 3.0 in the 2022 release of Ubuntu every other had 1.1.1 everybody and I repeat everybody actually turned out
to be about six people there are more than six people I hope you're aware of this so this is how we are with cyber security reporting we have this kind of mentality of marketing sorry I can't believe I'm about to do this again we with my co with my colleague Mark we do a podcast and I was recently talking about the EU AI act and how I
hoped it would kill marketing and our head of marketing was not happy with me and now I'm going to sit here and talk about marketing again so apparently I will never learn if it leads no if it bleeds it leads so you have these companies who are not news companies they are entertainment companies they are wanting to sell you panic and then they want you to click
so that they get your click revenue and they can sell you ads and they can personalize ads this is not cyber security this inciting of panic is entertainment and it actually does interesting things to physiologically here are a small list of what happens when you read one of these things because what it actually does is Insight the flight or fight reflex so you end up with these
nice things like headaches depression heartburn pounding heart high blood pressure that's what's happened with post this post has caused high blood pressure across everyone who read it and it turn turned out to be absolutely nothing and here is the dark secret it is not an isolated incident this is happening every month week this is happening every day and why is it it's because of this CVSs scores
CVSs scores are they are a measure of how serious something is you probably know these let's use our ridiculous example if you stabbed this is a CVSs score of 10 you have several minutes to stop the bleeding get to a hospital and you know not die this is valid information for all the people who are being stabbed right now hands up if you are being stabbed at
turns out it's no one what CVSs score does is it tells you how bad an incident is if it affects you and it is our only metric in cyber security so we see things like this op SSL thing which was a severity 10 issue for the eight people that affect it was affected by and everyone else passed it by log 4G terrible issue for everyone who was
running Java everyone who didn't have Java in their application stack they were just fine but it was severity 10 Talk of the internet and we've actually had a few speakers allude to this over the last couple of days we had uh we had krainov talk about epss which is actually a attempt to measure a vulnerability or the chance of something being exploited we had Dino tracers Davis
AI from Gareth who that basically again it tries to measure if you use tenable you may know it has VPS the vulnerability probability score which is the chance of someone actually attacking via that means and this is what I need this is what we all need and build we need a call for new metrics we can't use CVA SS CVSs is a panic inducing metric that basically
causes people to think that they're affected when they're not OP SSL was active in I think 30% of websites when I did a brief check I don't remember so even that if it had affected the whole of op SSL would have covered a third of the internet there are 66% of people people who would have been completely unaffected and this is something we don't pay any heed
to so what we need is we need new metrics and as another thought we also need to kill cyber security reporting as exists right now cyber security exists a state of media it sells clicks and that's what it's supposed to do what we need to do is we need to transition cyber security reporting away from media away from business and towards a public service and the EU
is actually doing some interesting things about this right now they're introducing NIS too the cyber security directive they're doing the eui ACT they are un starting to understand that cyber security is a public safety interest cyber security is not to something that's going away and it's not something that should be sold to us it is something we all need to partake in it is something that every
single one of us know the reason I have this up here I live in Finland I didn't always live in Finland and there's actually a lot of reasons I'm very happy to live in Finland one of them is because we have trafficcom who run a national cyber Center what these do these people do every morning I get an email which is a summary of all of the
recent exploits that have happened it is impartial it is unbiased and right now it's underfunded because it's literally just a copy and paste of what people have on their websites when they have a vulnerability what I would like to see is more funding going towards systems like this which can then invest in the research and start pushing forward a new score maybe epss is the best choice
something to show not the severity if you are hit but the chance that you are hit because with our absurd example there are going to sadly be quite a few people stabbed today I hope most of us aren't among them and what we have is a situation where it becomes important to know where these things can happen what is the likelihood of it happening not how bad
it is it if it happens so we're going to go on to our summary I'm quite negative I do apologize I do try to bring it up from time to time but generally there is a lot to complain about in this industry so how do I maintain my cyber my sanity security I like this quote cyber security is like Tetris your failures pile up while your success
vanishes and you're sat there thinking what the hell you just said you're a depressive person why would you end with such a such a shitty quote there is some optimism because we know where we stand with Tetris in 1996 amga magazine stated Tetris was the 37th best game of all time in 2007 the New York Times reported the tetris was named among the 10 most important and
influential video games of time we know where we stand we start from the start and we know we don't win we stack the blocks we get as high score as we can and then we lose and that's the simple fact of what we do if we do something we're particularly proud of we get to put our name next to the high score and then we lose and
we dust ourselves up and we pick ourselves up and we start again it doesn't matter that we know the ending of the game the game will be defined by the problems you can't solve there will always be battles and they will often be uphill you will often never get a long block when you need one these are no reasons not to play some games are just worth
playing thank you let's see we have some questions uh yep statistics are just trust me bro yep they pretty much are here is the dirty secret about statistics they all you are not wrong the rant about cyber security reporting is because it is the single largest source of frustration in my work life when people are inciting panic and then running off they are saying here is the
worst thing that will happen to the internet right now it's happening and then it turns out that someone just switched a server off and it's fine it's this constant peing of uh flight or fight response where you go oh [ __ ] oh it's fine oh [ __ ] oh it's fine this is problematic for your health this is why we're talking about it in regards to psychological safety because your
psychology is literally part of your body if you are constantly being tricked into these responses this will cause problems for you down the line and then question apparently no more questions it was deleted if someone has that question later on feel free to ask oh is it back chance to be hit is mainly cyber threat intelligence probably yeah they should but I refer you back to the
first question I asked how many of you think you're cyber security teams are under funded quite a lot of you who's paying for this analyst very few people so yeah you are not wrong but if you have one of those good for you lots of people don't and that's why we need better reporting metrics than CVSs for those people and that's all the questions thank you once
again