How Can Companies Nip Employee Negligence in the Bud?

How Can Companies Nip Employee Negligence in the Bud?

By David Bisson and edited by Robert de Haan

Employee negligence continues to be a top information security risk for key figures in the enterprise, especially IT security professionals who rely on internal threat reports to do their jobs. This risk can take the form of genuine human error, a lack of security awareness or even deliberate attempts to steal corporate data for personal gain.

According to the 2018 State of the Industry report from document destruction company Shred-it, 96% said they view employee negligence as at least a minor cause of data breaches against companies. Some were even more convinced: 84% of C-suites see it as one of their biggest information security risks — and 51% of small-business owners agree.

Reflecting this viewpoint, the majority of businesses revealed that they’re struggling to keep pace with modern workplace trends. In particular, 86% of C-suites, and 60% of small-business owners said they believe the risk of a data breach is higher when employees work remotely.

How can companies increase cyber awareness among nontechnical employees and better incentivize them to report potential security issues before they become full-blown incidents?

What Are the Consequences of Employee Negligence?

According to the Shred-it report, two main factors are driving up the level of concern over instances of workforce negligence, which includes accessing company systems over remote and unsecured networks or improperly disposing of sensitive data.

Employee carelessness is the first factor and has historically been one of the primary causes of data breaches. The IBM X-Force team uncovered as much in its 2018 Threat Intelligence Index, noting that negligent actions were behind two-thirds of total records compromised in 2017.

Employee negligence is the second factor and makes the job of IT security professionals more difficult. To adequately defend organisations against cyberthreats, security teams need employees to report any issues they come across. However, organisations don’t always encourage them to do so. According to a 2016 Ponemon report, 67% of respondents said their organisations don’t provide incentives for employees to report security issues proactively.

This lack of engagement can cause small issues to evolve into major security incidents. For example, 79% of respondents to a Keeper Security survey that suffered ransomware attacks said the threat entered their systems through phishing emails.

Employees can help identify phishing attacks — but without the knowledge or incentive to do so, many either fall for the scam or simply keep it to themselves. As a result, security teams must devote their resources and respond to these issues that could have been prevented in the first place.

How Companies Can Minimize the Effects of Human Error

Organizations can counter negligence among their workforce by integrating data protection measures, such as resiliency backup and other disaster recovery tools, into their business practices.

Companies should also continuously evaluate and measure the effectiveness of their security strategies and ensure that internal protocols are keeping pace with the increasingly sophisticated threat landscape. These policies should include ongoing security awareness training for the entire company and provide employees with incentives to report potential threats.


要查看或添加评论,请登录

Robert de Haan的更多文章

  • Psychological and Security issues when working from home

    Psychological and Security issues when working from home

    Have you ever wondered what are the psychological risks and cyber security impacts are, that we encounter when our…

    1 条评论
  • The paradox of our time in history.

    The paradox of our time in history.

    · We have taller buildings but shorter tempers, wider Freeways, but narrower viewpoints. We spend more but have less…

  • Paying it Forward

    Paying it Forward

    In this time of life-altering change, Layer 8 Security is offering to assist any company with a complementary offer to…

    1 条评论
  • FREE “Working remotely” online security course

    FREE “Working remotely” online security course

    To assist organisations to address the potential risk of staff working from home, Layer 8 Security are offering a FREE…

  • Legal Threats Make Powerful Phishing Lures

    Legal Threats Make Powerful Phishing Lures

    Some of the most convincing email phishing and malware attacks come disguised as nastygrams from a law firm. Such scams…

  • How to quickly change security behaviour

    How to quickly change security behaviour

    Security awareness training aims not only to impart information but also to change behaviour. In order to accomplish…

    1 条评论
  • A habitually funny story.

    A habitually funny story.

    I was running a security awareness training session for some executives of one of our customers recently, when I put up…

  • Addressing Human Risk

    Addressing Human Risk

    Addressing human risk, compliance and appropriate controls isn’t as easy as just doing some email phishing, some…

  • Building a better security culture

    Building a better security culture

    Everyone knows how crucial security is and how it must be embedded into everything an organization does. A simple…

    1 条评论
  • Opinions on security predictive behaviour

    Opinions on security predictive behaviour

    I’m sure you heard the theme many times over the past few years that the best ROI for cybersecurity spend, comes from…

    2 条评论

社区洞察

其他会员也浏览了