No Phishing
|

Linked – How to create a security-focused work culture

So the problem is laid out pretty well in this statement:

In a press release about the report, Monu Kalsi, vice-president of Shred-it, is quoted as saying, “The study’s findings clearly show that seemingly small habits [of employees] can pose great security risk and add up to large financial, reputational and legal risks.”

And the suggested fix for this, naturally, is to do more and better training. Now, as a long-time trainer, obviously I will advocate for that as well. Far too many places put a network security tool in place and hope for the best instead of actively involving their users as part of that defense. The article below lays out some good basics for that type of training.

But, I’m waiting for the organizations who take that one step further. After you’ve trained them, will you actually hold them accountable for their actions? When will we see corporate policies that spell out how many of these “small habits” can create actual security problems before you either don’t get to work there any longer, or it starts to impact performance reviews and raises.

Right now, we are starting to see more organizations hold people accountable for sitting through the training. This is good, but how many of them are measuring, in a meaningful and personal way, whether the users are following the procedures they are being trained on? Isn’t it time to consider the possibility that the user who continues to click on fraudulent links and use cloud services and personal devices to access or store confidential information with no regard for security, regardless of what training they’ve received, is more of a risk to the company than a benefit? Even if they are in management.

Or a partner in a law firm.

Truthfully, when we measure the members of our organization, this isn’t one the measurements we use to evaluate them. You get more of what you measure, and less of what you don’t.

Network and data security shouldn’t be something we want less of.

https://www.techrepublic.com/article/how-to-create-a-security-focused-work-culture/

Similar Posts

  • |

    Linked: Employees are twice as likely as executives to work in office full-time

    This is just wrong on so many levels.

    “Executives have often led the charge to return to in-person work — yet new research from Future Forum, Slack’s research consortium, reveals that non-executive employees are nearly twice as likely as executives to be working from the office five days a week.”

  • |

    Why I like Tweetdeck

    Over the weekend, after seeing quite a few references to it, I decided to download Tweetdeck and check it out for myself. The idea of breaking the people I follow on Twitter into different groups was sort of intriguing, but I wasn’t exactly sure how it would work out in practice. As I began to…

  • This Week’s Links (weekly)

    Why de-NISTing is just plain silly tags: LitSupport MM Resistance Is Not Futile tags: LitSupport MM Social Networking, Creative Licenses Highlight EDD News at ILTA tags: LitSupport MM Are You Guilty of Spoliation of E-Discovery Evidence? tags: LitSupport MM Swartworth Leadership Development Seminar: The Judge Advocate General on What Leadership Means To Me tags: MM…

  • Linked – The Making of a Myth: Big Tech, Billionaires, and the Wild West

    When Big Tech bros talk about being the cowboys of the modern age, the myth is what they want you to believe. They want us to believe that they are so brilliant and creative that they succeed without assistance and will solve any problem without needing oversight or regulation. They’ll forget to mention that the Internet they are building on only exists because of government programs or that many of them have gotten plenty of handouts from government and private equity. They will also not like to be reminded of the many ways they have overstepped and done real harm.

  • |

    Financial Stress and Mental Health – Why Younger Employees Leave

    I think this is interesting in a couple of different ways. Clearly, workers are putting a much higher value on their own mental health, and companies that don’t get that, and support it, are going to end up having quite a bit of turnover.

    But, the other thing that I wanted to think more about was what those specific reasons say about the mental health of Millennial and Gen Z workers. They seem to be dealing with a lot of stress around finances, and having that stress impact their mental health. Is that new? Or is it more likely that Gen X and Boomers have had those same stresses, but didn’t really identify them as mental health issues, like anxiety.

    I think there’s something to that. Not to start talking about how things were “back in my day”, but I don’t recall anyone talking about anxiety in the same way we talk about it now. I suspect that many of us had anxiety around finances, we just didn’t call it that, and our solution to that anxiety was, of course, to work harder and longer.

    And guess what? The next generations watched us do that, especially the Baby Boomers, and realized that it doesn’t actually work. Our mental health has sucked, for years, and we just didn’t admit it. They are willing to talk about it, and look for work that fits with lessening stress, especially stress that is related to finances.

    Now, you would think that if they had more stress around finances, they would also just “work harder and longer”, but that assumes that the relationship between employers and employees is the same as it was 25-30 years ago, and it’s just not. Companies come and go now overnight. They run out to hire when things are growing, and rush to fire when things are not growing. Whole industries barely exist anymore. None of us live in the same work world that we grew up in any more.

  • Tech chatting

    Kevin has the latest episode of his In The Trenches podcast up on his site. I quite enjoyed being part of the Tech Chat with Kevin, Kevin Mazur and Eric Maynard, chatting about the difficulties of dealing with dissimilar systems on your network. Eric put his show prep notes on his site, and I have…

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

To respond on your own website, enter the URL of your response which should contain a link to this post's permalink URL. Your response will then appear (possibly after moderation) on this page. Want to update or remove your response? Update or delete your post and re-enter your post's URL again. (Find out more about Webmentions.)