Employees need to love cyber security for everyone's safety
Ensuring staff care about cyber security is crucial to modern work
Protecting your computers and networks, and the data that they contain is a complex issue.
If you are to have any chance of success, then the attitudes of your employees towards cyber security is the most important factor.
Every UK business is under threat. Some are in an active state of war
because of the industry they are in and their relationship to other
companies. Every business in the UK is now a potential victim of crime
and that threat has now dramatically increased due to the emergence of
AI, because AI makes finding victims easy.
- Protecting your computers and networks, and the data that they contain is a complex issue.
- If you are to have any chance of success, then the attitudes of your employees towards cyber security is the most important factor.
- Get employees onside
- Cyber posture
- Awareness training
- Cyber posture needs ongoing training
- Watch out! There's a hacker about
- Reward awareness
Get employees onside
There are a number of actions that you can take to get your employees to understand what the problem is and to help them to become your greatest asset. The first thing that you need to do and to be able to demonstrate is that you have gained buy in from the top of your organisation. If the management is not actively supporting the activity, why should the employees?
Make sure that you have a cyber security policy and that everyone has read it.
Ensure that it addresses, as a minimum, specific rules for email, internet browsing, social networks and mobile devices.
Cyber posture
Cyber security is a state of mind. A point made over and over again by the insurance industry. To get cyber security insurance it’s essential to be able to demonstrate that your organisation is aware of the ongoing nature of cyber attacks. An attitude the insurance companies call cyber posture.
Cyber awareness means being prepared for the unexpected. An email out of the blue, an unsolicited phone call, an unusual request. Frequently it is a connection that depends on keeping the line of communication that has been started with you open.
In nearly all cases the best line of defence is to break that line of communication and double-check the source. A mental attitude that needs support from training.
Cyber security is a question of knowing your data and being intelligent about protecting it. If you understand your data then you begin to understand who, and what, has access to it.
Awareness training
Put in place a cyber security awareness training programme that employees are exposed to from the time that they join the organisation. That way new employees, from the time they start, begin to understand that cyber security is important, and important to you, and that they are going to be given continuous awareness and training.
Do not forget that training needs to be comprehensible and people-friendly. Cybersecurity may seem daunting to many of your employees, so a good approach is to break it into small sections and be smart with your targets – they should be specific, measurable, actionable, relevant and time-constrained.
Cyber posture needs ongoing training
The training needs to be delivered continuously throughout the year, at all levels of the organisation.
A good place to start is when a new employee is inducted – make reading the policy part of the process. After that, all employees should read it again at regular intervals (perhaps as part of an annual review?) to make sure that they are up-to-date. Keep your security policy simple and concise so that employees will be able to read it and digest the core security messages.
As a part of the awareness and education programme, clearly communicate the potential impact of a cyber incident on your organisation. You can also explain the potential consequences of everyday activities and bad habits and use examples to illustrate the points.
For example, you could use scenarios such as what could happen if someone accessed work documents over an open Wi-Fi network in a café, or opened personal emails on a work device.
Watch out! There's a hacker about
You should also highlight the risks of revealing personal information on social media sites, such as the partner’s or childrens’ names, memorable dates, etc. which may give an insight into passwords used for work applications. You should also be very aware that your social media can become a hacking target for Open Source Intelligence (OSINT) that can be used to target you for email attack, the commonest form of hacking attack. Someone knowing the name of your football team, the sports your family play, and the schools they go to is invaluable information.
The majority of staff do not even realise how they’re potentially undermining your business through everyday behaviour.
Make cyber security everyone’s responsibility. Include management and the IT staff in your education programme.
The more senior an employee, the more information they typically have access to, making them a more attractive target to cyber criminals. IT staff have even greater power over the network, so ensure that complacency doesn’t set in.
Plan how to best to communicate cybersecurity information to all employees and get all departments on board with both training and learning best practices.
Reward awareness
Reward good behaviour by employees. For example, reward users that find malicious emails, and share stories about how users have helped to identify and prevent security issues,
If an employee makes a mistake, be understanding – after all, it is better to get the staff to report breaches than to try to hide them for fear of repercussions. However, if one employee or group of employees seem to be having a lot of security issues, look into it and identify the cause so that you can take remedial action.
Help employees understand the importance of cyber hygiene not just in the workplace, but also at home. Teach them about privacy, security, and show them how the lessons learned at work can be applied in their home and in their personal lives. This should help to get them to adopt good practices and give them some useful knowledge for their personal lives.
Tailor the training to help your employees to recognise and respond to a cyber attack and give them information on how to report an incident. For example, provide an emergency contact number to alert the system administrator to any suspicious emails or unusual activity, or for the reporting of a lost device.
Mobile Devices have become an increasingly important business tool but with them comes a new set of cyber threats. Consider making sure that your employees have password-protected devices, encrypt emails, and approved security applications to help keep the mobile data safe.
Carry out evaluations of both employees and systems to find out how vulnerable your organisation is to an attack.
While there is no fool-proof method to protect your business, educating your employees about security threats and best practices for online behaviour and privacy can at least reduce the likelihood of a breach caused by human error.
Keep security simple.