Monday, June 8, 2026

Security Boulevard Logo

Security Boulevard

The Home of the Security Bloggers Network

Community Chats Webinars Library
  • Home
    • Cybersecurity News
    • Features
    • Industry Spotlight
    • News Releases
  • Security Creators Network
    • Latest Posts
    • Syndicate Your Blog
    • Write for Security Boulevard
  • Webinars
    • Upcoming Webinars
    • Calendar View
    • On-Demand Webinars
  • Events
    • Upcoming Events
    • On-Demand Events
  • Sponsored Content
  • Chat
    • Security Boulevard Chat
    • Marketing InSecurity Podcast
    • Techstrong.tv Podcast
    • TechstrongTV - Twitch
  • Library
  • Related Sites
    • Techstrong Group
    • Cloud Native Now
    • DevOps.com
    • Security Boulevard
    • Techstrong Research
    • Techstrong TV
    • Techstrong.tv Podcast
    • Techstrong.tv - Twitch
    • Devops Chat
    • DevOps Dozen
    • DevOps TV
  • Media Kit
  • About
    • Sponsor

  • Analytics
  • AppSec
  • CISO
  • Cloud
  • DevOps
  • GRC
  • Identity
  • Incident Response
  • IoT / ICS
  • Threats / Breaches
  • More
    • Blockchain / Digital Currencies
    • Careers
    • Cyberlaw
    • Mobile
    • Social Engineering
  • Humor
CISO Suite Governance, Risk & Compliance Security Bloggers Network 

Home » Cybersecurity » CISO Suite » Device Intelligence Boils Down to A Cup of Coffee

SBN

Device Intelligence Boils Down to A Cup of Coffee

by NuData on March 3, 2022

For many of us, the day starts with a cup of coffee — but what actually ends up in our mug each morning varies. Maybe you prefer your latte with almond milk and vanilla syrup. Or perhaps you lean toward an iced coffee instead of a steaming hot cup of joe. Individual preferences matter when it comes to your morning pick-me-up — it’s what makes every cup of coffee unique. And that uniqueness follows you when you enjoy a coffee outside of your home, too, which is why many of us end up with “the regular” at our local shop.

The same goes for device intelligence — or the manner in which we evaluate users based on elements of their online experience and ultimately work to prevent fraud. In fact, the concept of a go-to coffee order can help us identify flaws within popular security tactics and opportunities to leverage more sophisticated solutions that improve user experiences.

Security ingredients (and their limitations)

Many organizations are tied to incomplete security tools, which — while capable of monitoring some user attributes — don’t do so completely or very well over time. This leaves space for bad actors to take advantage of gaps in information, and also results in a clunky user experience for good users forced to continuously verify their identities and share more personal information with brands.

It’s no surprise many businesses turn to device IDs, device fingerprints and device user-agents as the primary way of validating users. But let’s break down these three common identifiers a bit more and explore the underlying roadblocks of each:

  1. Device IDs: This first string of data is unique to absolutely every device and is generated based on cookies stored on your browser. Device IDs are great identifiers, but for privacy reasons these IDs expire monthly, making them unreliable long term.Think of device IDs as your coffee cup. When you go to your favorite local spot, suppose you always bring a one-of-a-kind mug made by someone in your family. For a period of time, that cup makes you incredibly identifiable. But maybe your new cat grows fond of knocking over your mug and breaks it, and you end up purchasing a replacement. Having multiple coffee cups is not unheard of (some of us collect them), just as many users rely on numerous devices to go about their business online. However, that does make your coffee cup of choice week-to-week an incomplete identifier.
  2. Device fingerprints: The second string of data incorporates your device settings and attributes, including type of device, browser used, version of the browser and language settings. This set of information remains stable over time, but is never 100% globally unique. In fact, there’s a 40% chance of finding another device with the same fingerprint as yours. Overlap across device fingerprints will only grow more common as developers continue to standardize technologies and produce devices with fewer easily recognizable flaws.Think of device fingerprints as your java order. Throughout the day, there are likely other customers who also order vanilla lattes with almond milk. While your fingerprint appears unique in the moment, a big-picture perspective reveals relatively high similarities with other users (or coffee connoisseurs) — your order may not be as special as you think it is.
  3. Device user-agents: The third string of data offers basic details about your device. Again, while these underlying attributes are helpful, this small stamp of your phone/computer/tablet is easy for fraudsters to understand and replicate. Think of device user-agents as the name written on your coffee cup. Sure, your name is a helpful identifier, but someone else at the store may share your name. Likewise, over time it would be easy for others to learn and give your name at checkout.

IDs, fingerprints and user-agents offer unique and helpful information about our devices, and in many scenarios these details can prevent fraudulent interactions. That said, organizations still expect $4.1B in application fraud losses by 2023, so it’s clear current tactics alone are not enough to stop all bad actors from slipping through the cracks. Don’t worry, we’ll discuss solutions shortly — but first, an important question.

Do you want whipped cream on that?

For a long time, companies have prioritized learning as much as possible about customers. This effort revolutionized the level of personalization now expected when we shop and continues to improve user experiences across all digital channels. But there’s a lot more we can still learn about end users when we pay closer attention to not only their devices and goals, but also their behaviors when online — especially when it comes to improving security practices.

Let’s go back to our coffee shop illustration. While we were focused on the specifics of your drink order, we actually missed out on a series of extremely helpful behavioral queues. Imagine you typically stop by your local store on Friday mornings because you enjoy ending the work week on a high note. It’s not uncommon for you to walk your dog to the shop since it’s in your neighborhood (yes, you have a cat and a dog). And you always say yes when asked if you’d like whipped cream on your drink (it’s Friday after all).

Altogether, that’s a lot of identifying details that go well beyond your coffee order, and instead focus on your unique behaviors. As mentioned earlier, other customers may also order vanilla lattes or share your name. However, the time of the day you tend to swing by, how often you make purchases and the type of mug you typically bring presents a distinct picture with significantly lower overlap. This clear sense of “you” enables your barista to react appropriately upon your arrival, and may even trigger certain events like an employee grabbing your preferred cup size or a special treat for your puppy. Equipped with more behavioral knowledge about you, the barista can also make adjustments when scenarios feel off, too.

While it’s unlikely that someone will try to impersonate you at your local coffee shop, if this does happen, you’d want employees to spot this deception and intervene.

These details also exist in our digital world. As mentioned above, the device intelligence strategies we turn to most often can no longer solve our security problems on their own. Fortunately, it’s possible to combine details already known through your device ID, fingerprint and user-agent with what we can now learn about users through their passive biometric habits, such as how they type, browse and hold devices.

Behavioral technologies help you avoid getting burned

Much like a bad cup of coffee, insufficient security measures and difficult user experiences leave a bitter taste in customers’ mouths. It’s important to avoid mistakes from the jump.

To do that, behavioral characteristics create a device-based profile much more difficult for bad actors to replicate — making these details a great source for both pinpointing fraud and validating good users. Behavioral technologies work well in today’s world because rather than looking out for generically “suspicious” actions to identify bad actors, your organization can turn to legacy user information and flag instances that feel off based on the behaviors of your known good actors.

How behavioral biometrics can stop social engineering and malware scams dead in their tracks

This includes going beyond catching occurrences of spoofing and double device breaks, as well as the ability to reliably link several devices to the same authorized user. Layering behavioral technologies into your overall device intelligence strategy is a direct response to the advanced social engineering tactics bad actors now lean on, and avoids overreliance on data points like device IDs, fingerprints and user-agents.

Top security solutions actually provide a risk score triggered by device intelligence insights as well as behavioral information, allowing your company to automate responses based on your organization’s particular risk tolerance. Customizing fraud intervention strategies based on your unique industry and customers goes a long way toward safeguarding user experience. For example, merchants may choose to respond only to very high-risk behaviors since their customers are more sensitive to false declines, while banks fall on the opposite end and will likely respond to relatively medium-risk behaviors to prevent even one instance of financial fraud. Over time, you can change policies and introduce new triggers/rules to improve security practices.

So, the next time you visit your local coffee shop, pay attention to what makes you stand out from the crowd. You might be surprised by all the things you notice — and how those details change the way you think about device intelligence.

The post Device Intelligence Boils Down to A Cup of Coffee appeared first on NuData Security.

*** This is a Security Bloggers Network syndicated blog from NuData Security authored by NuData. Read the original post at: https://nudatasecurity.com/resources/blog/device-intelligence-behavioral-tech-improves-security-efforts/

March 3, 2022March 3, 2022 NuData account takeover, Blog, Phishing, Resources, risk management, user experience, user verification
  • ← Introducing improved risk detail display and management workflows
  • Anton’s Security Blog Quarterly Q1 2022 →

Techstrong TV

Click full-screen to enable volume control
Watch latest episodes and shows

Tech Field Day Events

Upcoming Webinars

Toxic Flows: When Your Agent Skill Becomes a Supply Chain Attack
The Cost of Exposure: Managing the Operational Risks of Executive Security Incidents
The Future of Agentic Software Delivery: Unifying Source & Binaries
35 Million Lines, Zero Build-Breakers: How Adyen Scaled DevSecOps
Zero Trust for Agentic AI: Managing Non‑Human Identities at Scale

Podcast

Listen to all of our podcasts

Secure by Design

5 days ago | Jack Poller

Senator Sanders Wants to Own AI Companies — and Hand America’s Adversaries the Keys

2 weeks ago | Jack Poller

NIST’s Nine: The PQC Signature Race Moves to Round Three

2 weeks ago | Jack Poller

The Quantum Arms Race: Why Washington Just Wrote a $2 Billion Check to Nine Companies

3 weeks ago | Jack Poller

Beyond Moore’s Law: The Hyper-Acceleration of Autonomous AI Cyber Capabilities

4 weeks ago | Jack Poller

The Exception Economy: When Security Teams Stop Protecting and Start Negotiating

Press Releases

GoPlus's Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

GoPlus’s Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

Subscribe to our Newsletters

Most Read on the Boulevard

Anxious Security Pros Watch as Anthropic, OpenAI Expand Access to Frontier AI Models
AI-Powered Computer Worm Reveals New Cybersecurity Threat
Meta, Microsoft, DOJ, and Others Disrupt Southeast Asia Scam Compounds
Health Entities and Ransomware — HHS Adopts a “Blame the Victim” Strategy. Let’s See if It Works.
Is It Time For A U.S. Cyber Force?
Imperva Customers Protected Against CVE-2026-49975 (HTTP/2 Bomb) DoS
Cybersecurity Trends 2026
OpenAI Codex Supply Chain Attack Exposes Growing Risks in AI Development Environments
The June 2026 AI Executive Order: What federal agencies need to know and how Tenable can help
New Shai-Hulud Miasma Wave Hits Hundreds of npm Packages

Industry Spotlight

Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks
Cloud Security Cybersecurity Data Privacy Data Security Featured Incident Response Industry Spotlight Malware Mobile Security Network Security News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threats & Breaches Vulnerabilities 

Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks

April 12, 2026 Jeffrey Burt | Apr 12 Comments Off on Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks
The Day the Security Music Died
AI and Machine Learning in Security Cybersecurity Featured Industry Spotlight Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

The Day the Security Music Died

April 8, 2026 Alan Shimel | Apr 08 Comments Off on The Day the Security Music Died
The Lock, Not the Alarm: How Palo Alto’s Koi Acquisition Rewrites Endpoint Security
Featured Industry Spotlight Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Uncategorized 

The Lock, Not the Alarm: How Palo Alto’s Koi Acquisition Rewrites Endpoint Security

February 18, 2026 Jack Poller | Feb 18 Comments Off on The Lock, Not the Alarm: How Palo Alto’s Koi Acquisition Rewrites Endpoint Security

Top Stories

Ex-IBM Exec Accuses Big Blue and AT&T of Covering Up Foreign Data Breaches
Cloud Security Cyberlaw Cybersecurity Data Privacy Data Security Featured Governance, Risk & Compliance IoT & ICS Security Network Security News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threat Intelligence Threats & Breaches 

Ex-IBM Exec Accuses Big Blue and AT&T of Covering Up Foreign Data Breaches

June 7, 2026 Jeffrey Burt | 5 hours ago 0
Meta, Microsoft, DOJ, and Others Disrupt Southeast Asia Scam Compounds
Cloud Security Cyberlaw Cybersecurity Data Privacy Data Security Featured Incident Response Mobile Security Network Security News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threat Intelligence Threats & Breaches 

Meta, Microsoft, DOJ, and Others Disrupt Southeast Asia Scam Compounds

June 4, 2026 Jeffrey Burt | 3 days ago 0
Anxious Security Pros Watch as Anthropic, OpenAI Expand Access to Frontier AI Models
Cloud Security Cyberlaw Cybersecurity Data Privacy Data Security Endpoint Featured Governance, Risk & Compliance Mobile Security Network Security News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threat Intelligence 

Anxious Security Pros Watch as Anthropic, OpenAI Expand Access to Frontier AI Models

June 3, 2026 Jeffrey Burt | 4 days ago 0

Security Humor

Randall Munroe’s XKCD 'Types of Board Game'

Randall Munroe’s XKCD ‘Types of Board Game’

Download Free eBook

[su_panel border="0px solid #ddd" radius="0" text_align="center" padding-top="0px" padding-bottom="0px"]
Managing the AppSec Toolstack
[/su_panel]

Security Boulevard Logo White

DMCA

Join the Community

  • Add your blog to Security Creators Network
  • Write for Security Boulevard
  • Bloggers Meetup and Awards
  • Ask a Question
  • Email: [email protected]

Useful Links

  • About
  • Media Kit
  • Sponsor Info
  • Copyright
  • TOS
  • DMCA Compliance Statement
  • Privacy Policy

Related Sites

  • Techstrong Group
  • Cloud Native Now
  • DevOps.com
  • Digital CxO
  • Techstrong Research
  • Techstrong TV
  • Techstrong.tv Podcast
  • DevOps Chat
  • DevOps Dozen
  • DevOps TV
Powered by Techstrong Group
Copyright © 2026 Techstrong Group Inc. All rights reserved.
×

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.