What sits underneath observable behavior: the cognitive signals that explain why the workforce decides what it decides.
Sumona explains the cognitive signals behind workforce decisions — and what they mean for how you design your program.
Clicks and policy violations are the visible end of a decision. The factors that shape that decision sit one layer deeper.
Sumona explains the cognitive signals behind workforce decisions — and what they mean for how you design your program.
The signals that sit underneath observable behavior.
The factors that shape a decision before it becomes an action.
Designing guidance around how people actually think.
Auto-generated from the live recording. Click a timestamp to jump to that moment in the video.
0:09 Hello, everybody. Can you hear me? Yeah, awesome. So… Hello? Hello. You know, before we start, I wanted to just give a quick background on who I am, why am I here, why should you be listening to me? My mission over here is singular. And always has been. Which is helping people recognize, resist, and respond to manipulation. All forms of manipulation. and build cognitive resilience in this era of AI. And so, this mission, Took me through a journey. From being… which started as a documentary filmmaker, all the way to working for a company that was building deepfake technology, to learning about psychology, neuroscience, the impact of these technologies on the human mind, on human cognition, and how it's altering it. And what does this actually look like, and how do we help humans Adapt to these technologies, the tsunami that's coming our way.
1:14 And so, currently, I'm doing my PhD in the field of cyber psychology as well, to answer this question. And this solution in MindShield was built out of this question. So I want to start with a simple scenario. Imagine you go into a doctor's office, and you see 3 patients with stomach pains sitting there. You know, the doctor comes out, and you see the doctor see, oh, 3 people with a stomach ache. Okay, here are some antibiotics. Go home. They take it home, Do it for a week. They come back after a week, one person is cured. The other person is not, and the third person is not either. And the doctor says, oh, I think you just need another round of antibiotics. So here. They come back after a couple of weeks. They do a couple of rounds of this. Before realizing, hey, it's not solving the problem. And now, guess what? Their bodies are building immunity to antibiotics. It's counterintuitive.
2:11 Why is this happening? The doctor is not a great doctor. He skipped diagnosing them. Why were they having the stomachache? Because if he diagnosed them, he'd find out one had appendicitis, one had acidity, and only one of them had a stomach infection. You would never go to this doctor. They would lose their license within, like, a few hours of… But this is the exact issue we're seeing in cybersecurity today. you have Say, two individuals in your organization. Right now, you run a phishing test. They get flagged up because they clicked. Oh, repeat clickers, put them through training. But then they're clicking again after a few months, and they're clicking again after a few months, and we keep wondering, why is this not working? What else do I do? So, what MindShield is trying to do is say, okay, why don't we, like, peel the cover a little and go into the diagnostic? Let's take a diagnostic approach to this. And if you take a diagnostic approach, you know, there's one layer of data that we could see that living security is already really mastering, which is what kind of social engineering attack Have they really fallen far?
3:22 So now we can see, okay, two people may fall for totally different attacks. One falls for an impersonation, one falls for a donation scam. Why? Why does person… why does Chris, the gentleman here, not fall for the CEO scam and verify, versus Tira over here, not fall for a donation scam, and ignores it? And so if you add the cyber psychology layer and the cognitive data layer, which we are building right now. Amongst many, many traits that we are assessing for, you could see that there are a few things that get highlighted. You have Tira over here that showed high levels of authority bias. And you had Chris show high levels of altruism and empathy. Now, we can ask why, you know, maybe someone came from a background where obedience was etched into the culture, you do not, you know, you don't question authority, and so she didn't have the reflex to even do so, or it feels awkward and uncomfortable.
4:19 Whereas Chris comes from a culture where that's totally normal. You can call up and, you know, it's less hierarchical, but, you know, he has high levels, it makes him a great manager, especially in the healthcare space, but this is exactly the thing that gets him hooked. So… Tira and chris, what makes them susceptible is totally different, and therefore they should have different interventions, and this is the layer of data that is missing that we want to really bring into the game. So we know about 65%, social engineering, all of us know that, and psychology is the thing hackers are attacking. So why are we not looking at interventions from a psychology perspective? Why haven't we yet? For the last 50 years, we have been looking at cybersecurity from a technical standpoint. Now it's time to evolve beyond And, Thanks to Mike, actually. You gave me this great illustration last night. I had to put it in last minute. But this is the evolution we're seeing, right? We started with casting wide nets, this is the biggest problem. We started with the casting of the wide nets, with the hackers casting wide nets, and then having spear phishing, which was targeted to an individual, took a lot more resources.
5:29 Today, the game is completely different. We are seeing mass-scale, hyper-personalized, targeted spear phishing attacks everyone. And we're really not prepared for this yet. We have to, and we are racing against time to do so. We have some other small problems. Actually, there's pretty big problems that we're dealing with. One is that we know that expertise does not equal behavior change. Right? Because you have even CISOs sometimes falling for phishing attacks. The second is, even though people recognize a fish, there is a very low reporting rate in most organizations. So why is it that even though someone understands and perceives it, they're afraid to actually take action on it? And third is, after a while, training engagement starts plateauing. Right? And the fundamental thing is people are different, so we need to start understanding people.
6:29 And so that's what MindShield is. We call ourselves a cognitive security platform. Cognitive security is the protection of the human mind, thought processes, decision-making, and judgment against manipulation, deception, and external influence. So what we found was there are specific psychocognitive markers in an individual that can be actually mapped To identify the root cause of what makes them susceptible. Therefore, improving their self-awareness prior to the fact. And using that data, To hyper-personalize the interventions down to the individuals. So now we have those two, basically what you saw with Tara and Chris. The goal over here is… How can we create a simple system that makes cybersecurity training more relevant, interventions and the entire concept of cybersecurity more relevant to the individual?
7:26 So we found it's a simple flow. We have an assessment platform, you know, it takes behavior telemetry data, and it also has employees actually engage in some simulations and microgames. And we create a cognitive… cyber-cognitive archetype. And we have come up with these cyber-cognitive archetypes for different people falling for different kinds of social engineering attacks or manipulation tactics. And then we use that. Inject the data to hyper-personalize the interventions. So, what I'm really excited about, and I was just so excited to see, especially what you're doing, Ashley and Mike, with, like, Livy, and how it's integrating and trying to close the loop, because Living Security is really, like, pioneering the… bringing what and who into one system. And what we are hoping to add to this is the why. Right? So, they're working with behavior, threat, identity.
8:21 MindShield is working with psychocognitive markers, understanding what drives and causes behavior, and the archetypes. And then we can use that information cohesively to build one singular profile of an individual that now maps not just their behavior, identity, and threat, but also their cognition. How do they make decisions? For example, you could have an executive who now gets flagged that, hey, you know, it's 4.59 PM on a Thursday, you've had 6 cups of coffee, and you've also been on 6 back-to-back meetings. Your cognitive load is really high. And, you know, you're hitting a level of fatigue, you have to make this really important decision, maybe postpone to tomorrow in the morning. Or go take a break. Right? Or these are the kind of scams that you might be susceptible to, so improve your vision. Vigilance to that particular tactic. And so the goal over here is, again, hyperpersonalization of the individual. Training, so matching the training to what they're susceptible to.
9:21 Second is, in-the-moment nudges, like I mentioned, someone has high cognitive load, a bias, or they are, you know, dealing with something, they can, in the moment, actually change that behavior, and also flows into the controls so that you can have proactive controls around the individual. So the goal over here is very simple. It's three things. Let's hyper-personalize our simulations and our training in the same way that the bad actors are hyper-personalizing their attacks. Let's match it. Second, let's reduce social engineering and manipulation susceptibility. But there's a third very beautiful thing, and you know, this is a longer conversation, but… Using AI is fundamentally changing how people think and make decisions. Cognitive surrender, cognitive offloading. And so, the goal over here is we have to maintain decision integrity, too. So imagine if we were able to reduce susceptibility to manipulation and simultaneously improve resilience, decision-making, and judgment by giving them the tools to make them think better.
10:20 That is what the vision over here is. And it all starts from helping people understand themselves. Understand your mind. Big tech, hackers, they know your mind. Why don't we? Why don't we know the same things they know about us? Right? So let's equalize that playing field. And so I, like, end with, you know, people's judgment is the last line of defense, we can make it the strongest one, and that humans are not the weakest link, we've just been the most unprotected. And that's why we are trying to build a MindShield. Literally, a shield for the mind. In the digital world. And, you know, if this is something you find interesting, you think it could add value with your current program, we have a QR code hovering around in some places that you can scan, it takes your landing page, you can learn more. That's all. Open to questions. Thank you.
11:28 reiterate something that maybe wasn't entirely clear, when Shimona presented earlier about MindShield. So, we are announcing a partnership today with MindShield, and as our customers, as our valued guests and member of our ecosystem, we're announcing a pilot program. Whereby if you have interest in testing out the MindShield capability, that's something that we can offer, at no charge, right? And we're gonna have a pilot program to see, is this something that could be a good fit for you? And then, ultimately, we see a scenario where that MindShield cognitive data could be integrated with Living Security Platform to produce those kinds of very hyper-personalized, tailored interventions that are taking cognition, into… into effect, okay? So, thank you very much, Shimona, and happy to have you as our partner. Alright, so, next up, we're gonna bring Gary back on stage, and I had the privilege of seeing Gary perform in Manhattan earlier this year in front of a very skeptical audience of about 40 CISOs.

Thirty minutes with a Human Risk Management specialist. Bring your stack and one incident you want to stop repeating — we’ll show you where the risk concentrates and what to do first.