The Power of Persuasion: Better Security Through Manipulation?

Nate Lee

BSidesSF 2025 — Here Be Dragons · Day 2 · Main

Overview

Security professionals spend most of their careers trying to influence people — engineers, executives, end users — who don't report to them and don't have to care. Nate Lee surveys the psychological and behavioral science literature on persuasion heuristics and maps six principles directly to the security context, arguing that understanding how human brains actually make decisions is as important as any technical skill a security leader can develop. ---

Watch on YouTube

Visual summary for The Power of Persuasion: Better Security Through Manipulation? by Nate Lee
Visual summary for The Power of Persuasion: Better Security Through Manipulation? by Nate Lee

Key moments

  1. 3:29 Experiment: word "because" alone boosts compliance from 60% to 90%
  2. 5:29 Price anchoring: same bracelet sells more when labeled expensive
  3. 7:00 Likability principle: attractive candidates get 2.5x more political votes
  4. 9:59 Reciprocity in security: doing small favors earns big cooperation later
  5. 14:59 Social proof: security policies adopted faster when peers visibly comply
  6. 18:59 Scarcity and urgency: framing security deadlines to drive action
  7. 22:59 Authority signals: how credentialing shapes employee security behavior
  8. 27:00 Ethics line: persuasion vs. manipulation boundary in security programs

The Power of Persuasion: Better Security Through Manipulation?

Speaker: Nate Lee

Conference: BSidesSF 2025 — April 26-27, 2025, San Francisco

YouTube: Watch the full talk

Reading time: ~7 minutes

TL;DR

Security professionals spend most of their careers trying to influence people — engineers, executives, end users — who don't report to them and don't have to care. Nate Lee surveys the psychological and behavioral science literature on persuasion heuristics and maps six principles directly to the security context, arguing that understanding how human brains actually make decisions is as important as any technical skill a security leader can develop.

Introduction

The familiar picture of the security professional's job — hardening systems, writing policies, responding to incidents — misses a large and arguably dominant component of the work: persuasion. Budget requests require convincing a CFO. Security adoption requires convincing engineering teams that don't report to you. Risk acceptance decisions require convincing executives to pay attention to something abstract. End-user behavior change requires convincing people who, by and large, have little personal motivation to care.

Nate Lee, a CISO and headliner presenter at BSidesSF 2025, has been reading neuroscience and psychology research with a specific lens: what does this literature tell us about how to be more effective in these influence situations? His talk surveys six behavioral heuristics — all empirically validated, all operating largely below conscious awareness — and demonstrates how each one can be deliberately applied to improve security outcomes. The title's question mark is genuine: these techniques work whether they are used ethically or manipulatively, which makes understanding them doubly important for the profession.

▶ Watch: Why security is an influence problem (00:00)

The Power of Heuristics: Why These Work

Before diving into specific principles, Lee establishes the mechanism. Heuristics are cognitive shortcuts — some evolutionary, some culturally conditioned — that operate quickly and largely outside conscious deliberation. Their power comes from the fact that most people believe these shortcuts do not affect them. Studies consistently show that when people are asked whether a given influence technique would work on them personally, the overwhelming majority say no. The statistics say otherwise.

One of Lee's most striking opening examples: a copier-line study where someone attempts to cut in line. If they say "I need to go first," about 60% of people comply. If they say "I need to go first because I'm running late," compliance jumps to roughly 90% — simply because the word "because" was added, even if the reason given is trivial. The implication for security: adding "because" to your requests, explaining your rationale even when it seems obvious, will materially improve compliance rates.

▶ Watch: The copier experiment and why "because" matters (04:01)

The Six Principles and Their Security Applications

Likability. People do things for people they like. This sounds obvious, but its applications in security are often neglected. More likable security teams get early warning of problems — engineers come to them before a project ships rather than after. Lee points to research showing that political candidates rated as more attractive receive two and a half times more votes despite voters explicitly denying that appearance affected their decision. For security practitioners, deliberate likability-building tools include: matching communication styles (if the engineering team uses emoji in Slack, use them too), finding and calling out genuine similarities with counterparts in other departments, giving compliments even ones that aren't wholly earned (research shows the likability effect holds even when the recipient knows the compliment wasn't entirely genuine), and attributing success to other teams publicly.

Reciprocity. Lee calls this the most powerful of the six principles. Rooted in the social dynamics of tribal human existence, reciprocity is deeply wired: if someone gives you something, there is a strong social obligation to return the favor. The asymmetry matters too — favors do not need to be proportional. A small favor creates a meaningful sense of obligation. Security teams that carve out time to do small favors for other teams — helping debug a non-security issue, clarifying something for legal, answering a question for finance — are building a reserve of goodwill that pays out when they need something much larger in return. A specific language note: saying "it's nothing" after doing someone a favor negates the obligation. Saying "I'm sure you'd do the same" preserves it.

▶ Watch: Reciprocity — the most powerful principle (10:01)

Authority. The Milgram shock experiments of the 1960s are the canonical demonstration: people will comply with requests from authority figures well past the point of personal discomfort. For security leaders, the implications cut both ways. Displaying appropriate signals of authority — credentials, domain knowledge, confident positioning — makes people more likely to follow recommendations. But Lee adds a counterintuitive finding: expressing calibrated uncertainty actually increases perceived authority. Saying "I'm not completely sure, but I'm 95% confident this approach will cause problems" reads as more authoritative than false certainty, because it signals careful analysis rather than bravado. Demonstrating familiarity with other teams' domains — understanding cost-of-goods-sold distinctions when talking to finance, knowing sales cycle terminology when talking to the revenue team — also significantly raises perceived authority.

Commitment and consistency. People feel internal and social pressure to remain consistent with prior commitments, even small ones. Lee cites a Stanford study where a researcher asked homeowners to place a small sign in their yard. Weeks later, when asked to allow a much larger billboard, those who had agreed to the small sign were far more likely to say yes — because their self-image had already incorporated "I'm the kind of person who supports this cause." In security terms: get small commitments first. If you want an engineering team to adopt static analysis, tell them you know they care about code quality (compliment and identity framing), then ask them to participate in a pilot as the logical next step from their existing values. Involving stakeholders in writing policies is another form of commitment creation — people are far more likely to follow policies they helped write.

▶ Watch: Commitment, consistency, and building self-perception (18:02)

Social proof. When people are uncertain how to act, they look at what others are doing. This is a powerful lever for security awareness programs — and a dangerous one if misapplied. Showing users "look at how many people pick weak passwords, don't be like them" backfires: the takeaway is that weak passwords are normal. Showing instead that "95% of your peers are doing X" frames compliance as the norm. Critically, social proof works only when the reference group is perceived as relevant. Using JP Morgan's security practices as an example for a startup audience will not resonate — the example must come from a similar organizational context.

Contrast. Evaluations are not absolute — they are relative to what was presented first. Lee's practical application: when presenting a list of security requirements to a team, show the full NIST framework first, then tell them you've reduced it to three items. Even if you always intended to ask for those three things, they will feel like a dramatically lighter lift. Budget presentations follow the same logic: lead with the largest item, and subsequent items feel more reasonable by comparison.

▶ Watch: Contrast and anchoring in budget and requirements conversations (22:02)

Compounding the Principles

Lee emphasizes that these principles compound when applied together. A single interaction can simultaneously employ likability (matching communication style), reciprocity (crediting the team for prior work), commitment (framing the ask as consistent with their existing values), and contrast (anchoring against a larger ask). The cumulative effect on outcomes is substantial and measurable, even when the interactions feel natural and low-key to the participants.

The Q&A reinforces the strategic frame. Asked for book recommendations, Lee points to Robert Cialdini's Influence as the foundational text covering these principles with deep research backing. Asked about early-career paths to security leadership, Lee returns to the theme of cross-domain knowledge: understanding how finance works, how the sales cycle functions, and how security ties to business outcomes is what separates effective security leaders from technically skilled security practitioners.

Notable Quotes

"Security is a very, very good place to use these principles because most people don't know a lot about it, and they don't really care all that much." — ▶ 04:01

"Expressing appropriate uncertainty — 'I'm ninety-five percent certain this will cause problems' — actually makes you seem more like an authority." — ▶ 16:02

"It's very subtle, and it can be hard to measure — but these things are all very deeply backed with lots of research. Being aware of them lets you use them to influence others to drive better outcomes for everybody." — ▶ 24:02

Key Takeaways

  • Security is fundamentally an influence problem. Most security work requires changing the behavior of people who don't report to you and don't have intrinsic motivation to comply.
  • Likability drives access. Teams that like their security counterparts bring problems early, before they become incidents. Invest in communication style matching, commonality-finding, and genuine credit attribution.
  • Reciprocity is the most powerful of the six principles. Small favors create strong obligations; building a reserve of goodwill pays disproportionate returns when large asks come.
  • Social proof must reference the right peer group. Framing security behaviors as common among similar organizations drives adoption; showcasing negative behaviors as widespread backfires.
  • Contrast and sequencing change perceived cost. Present the most demanding option first; anchor asks against larger alternatives; use the contrast effect to make necessary requirements feel achievable.

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

Cialdini's six principles of influence with security examples stapled on. The applications are competent and some of the framing is sharp — the copier experiment opener works, the two-sided AI debate concept is stolen from BS25-004 which had it first — but this is a psychology literature review, not security research. Worth reading the book instead.

Heather Calloway (CISO) — SOLID

Lee's mapping of six empirically validated behavioral heuristics onto the security influence problem is well-executed and immediately applicable. The reciprocity framing is the most useful: small favors create meaningful obligations, and security teams that build goodwill reserves get materially better outcomes when large asks come. The broader security impact is limited by scope.

→ Top-rated talks at BSidesSF 2025 — Here Be Dragons

All talks from BSidesSF 2025 — Here Be Dragons