Security Assessment Report as a Critique, Not Criticism

The key to a successful cybersecurity assessment report is to write it as a critique, not criticism. This isn’t easy, because assessment reports discuss gaps, weaknesses, risks, and other negative findings. Even when the report offers insightful advice, the recipients often react defensively, feeling like they are under a personal attack.

No Judgement

In an essay What is Critique, Judith Butler pointed out philosopher Raymond Williams’ concern that the practice of criticism has been unduly restricted to “fault-finding,” which lead him to propose that we find a vocabulary that does not “assume the habit (or right or duty) of judgment.” The notion of critique involves providing a well-rounded assessment of the subject’s structure, rather than personalizing the identified issues.

The Situation, Not the Person

A security assessment report that offers critique, comments on the factual findings, on the processes that contribute to the security issues, and on the structure of the organization that may need to be adjusted to improve security. This means staying away from chastising individuals, unless you are prepared to deal with their anger and defensive counter-accusations. An angry reader will ignore the report’s key messages, so focus on the situation, not the person.

Acknowledge the Positive

Another element of a critique-focused report involves the discussion of positive findings of the assessment. As the saying goes, a spoonful of sugar makes the medicine go down. Seeing what aspects of security you liked, will help the organization learn from what is working, so it better understands how to address the processes that aren’t. Positive reinforcement is often even more effective than negative reinforcement in changing behavior.

For more on the topic of delivering better security assessment reports, see my cheat sheet on creating a strong cybersecurity assessment report.

Updated

About the Author

Lenny Zeltser is a seasoned business and tech leader with extensive cybersecurity experience. He builds innovative endpoint defense solutions as VP of Products at Minerva Labs. Beforehand, he was responsible for security product management at NCR Corp. Lenny also trains incident response and digital forensics professionals at SANS Institute. An engaging presenter, he speaks at industry events, writes articles and has co-authored books. Lenny has earned the prestigious GIAC Security Expert designation, has an MBA from MIT Sloan and a Computer Science degree from the University of Pennsylvania.

Learn more