Running a successful PSIRT often has much more to do with the human relationships involved -- internally & externally -- than the technical issues you’re trying to address. Whether working with a security researcher, bug bounty hunter, IT admin, or end-user, knowing about your stakeholder is critical to a great outcome. This presentation dives into common personas -- archetypes, not stereotypes -- that a PSIRT will interact on a long-enough timeline. With an associated interaction framework, we explore how more-desirable outcomes can be achieved by placing our stakeholder’s motivations & needs at the forefront of the actions we consider.
Using real-world examples and sharing perspective from nearly two decades in the information security community, the basis of this presentation is rooted in practical awareness that any PSIRT can take into account the next time they receive an email from a person they don’t quite understand how to work with. Incident response is hard enough without compounding issues stemming from poor interactions with third parties. Come hear how one PSIRT manages this interpersonal risk and what strategies your team can take to find a better way forward, too.