Bharat Mistry, principal security strategist at Trend Micro, discusses what working from home means for CISOs
Does your cyber security policy need a rethink?
When history comes to be written about the current decade, the past few months may well mark a turning point. Exactly how remains to be seen, but one thing has become abundantly clear: the way organisations work may never be the same again. This matters a great deal for CISOs, because if you were worried about insider threats before, the same risks could be many times greater among workforce working from home.
This is where user awareness training comes in. But simply putting a blanket scheme in place may not work some employees dont break the rules out of ignorance but because theyve made a conscious decision to do so.
With the risks less related to education and more to psychology, its time for organisations to take a more nuanced approach to employee security training.
A recent global study of 13,200 remote workers in 27 countries found that although awareness of cyber-related risks is high, many employees choose not to conform anyway. A majority (85%) say they take instructions from their IT team seriously, agree that cyber security is partly their responsibility (81%) and even claim they have become more conscious of security policies since lockdown. A majority (64%) also recognise that using non-work applications on a corporate device is a security risk.
Steve Bennett, enterprise solutions architect at OGL Computer, discusses the role of IT in ensuring business continuity in todays new normal. Read here
Yet over half admit to doing just that, even uploading corporate data to these apps. Other security issues respondents admitted to include using work devices for personal web browsing, accessing corporate data from a personal device, and even accessing adult content and dark web sites on work devices.
Its easy to understand why employees do what they do. CISOs have always had trouble convincing them that productivity and protection are not mutually exclusive that users can do their jobs just as effectively by following policies, accepting security controls and using pre-approved apps and devices, and especially while working from home, the shift to productivity at all costs has threatened to disrupt this delicate balance.
It comes as cyber criminals look to capitalise on distracted home workers, unprotected endpoints, overwhelmed VPNs, and distributed security teams who may be forced to focus on more pressing operational IT tasks. Google is blocking as many as 18 million Covid-themed malicious and phishing emails every day. It takes just one to get through and convince a remote worker to click, and the organisation may be confronted with the prospect of a debilitating ransomware outage, BEC-related financial loss, or damaging data breach.
With many organisations struggling financially in the wake of government-mandated lockdowns, few will welcome the costs associated with a serious security incident.
Research from Specops has found that four in five computer and IT firms (78%) have seen an increase in cyber threats while working from home. Read here
Best practice cyber security requires a combination of people, process and technology. However, the people part has historically been neglected, which is one of the reasons why phishing attacks are today the most popular cyber crime threat vector. Training programmes are too often one-way, one-off affairs, which may raise awareness for a short time, but do little to actually change behaviours in the long-term.
Part of the reason for this failure is that they assume all staff members are basically the same. Of course, they are not. According to Edge Hill University Cyberpsychology Academic, Dr Linda Kaye, there are four key employee personas based on their cyber security behaviours.
Fearful employees are nervous about wrongdoing that might expose their organisation to cyber risk. Theyre highly accountable for their own behaviour, even if they dont know what the risks actually are and how to manage them.
Conscientious types are probably the CISOs dream: they understand cyber-risk and act on advice, not just avoiding risk but taking steps to proactively manage it.
On the other hand, ignorant users are a major risk because they combine a lack of cyber awareness with minimal personal accountability for their own actions. Their risky behaviour, however, is rooted in their lack of understanding.
More dangerous still are daredevil employees who break rules not because of their ignorance, but because of perceived superiority. Others should be accountable, but not them, they believe.
So what can CISOs do with this information as employees continue working from home? Certainly, different strategies may work best with different character types. Fearful staff members may react well to real-world simulation exercises, which allow them to try and experience things that they wouldnt normally. They may also benefit from being mentored by conscientious personas, who can be used as security champions in the organisation.
Don Randall MBE, former Bank of England CISO and advisory board member at METCloud, discusses cloud security, his new role and what to expect from a CISO. Read here
Ignorant users need training and practical advice on how to mitigate risks. To keep them engaged, it may be necessary to use gamification techniques, or again those phishing simulation exercises, which can be updated each time to reflect current scams. Its also important to recognise that these personas may require additional intervention to help them understand the consequences of risky behaviour. Daredevils are perhaps the most challenging as they dont respond well to authority. However, even here, CISOs can achieve promising results, perhaps by using reward schemes to change behaviour.
Ultimately, no two organisations are the same. CISOs will need to approach this task according to their risk appetite and the type of tasks staff working from home undertake. The most important thing to bear in mind with user training is to keep lessons short and regular, and act on the feedback you receive to continuously improve courses. These should never be a chore for employees. With a more considered, personalised approach, CISOs can change user behaviours and build both an effective first line of threat defence and a security-aware corporate culture.
See original here:
What working from home means for CISOs - Information Age
- Mind uploading won't lead to immortality - Life 2.0 ... [Last Updated On: June 10th, 2016] [Originally Added On: June 10th, 2016]
- Mind uploading won't lead to immortality - Life 2.0 ... [Last Updated On: June 12th, 2016] [Originally Added On: June 12th, 2016]
- Mind uploading in fiction - Wikipedia, the free encyclopedia [Last Updated On: June 12th, 2016] [Originally Added On: June 12th, 2016]
- Mind Uploading [Last Updated On: June 21st, 2016] [Originally Added On: June 21st, 2016]
- Trasferimento della mente - Wikipedia [Last Updated On: June 28th, 2016] [Originally Added On: June 28th, 2016]
- Mind Uploading FAQs [Last Updated On: June 30th, 2016] [Originally Added On: June 30th, 2016]
- Mind uploading - RationalWiki [Last Updated On: June 30th, 2016] [Originally Added On: June 30th, 2016]
- Brain Uploading - TV Tropes [Last Updated On: July 1st, 2016] [Originally Added On: July 1st, 2016]
- Carboncopies.org Foundation [Last Updated On: July 1st, 2016] [Originally Added On: July 1st, 2016]
- The History of SIM, Whole Brain Emulation and Mind Uploading [Last Updated On: July 31st, 2016] [Originally Added On: July 31st, 2016]
- What are the Benefits of Mind Uploading? - Lifeboat [Last Updated On: November 12th, 2016] [Originally Added On: November 12th, 2016]
- 2100 Technology | Timeline | 22nd Century | Future ... [Last Updated On: November 21st, 2016] [Originally Added On: November 21st, 2016]
- Unsterblichkeit Wikipedia [Last Updated On: November 23rd, 2016] [Originally Added On: November 23rd, 2016]
- Mind uploading - Transhumanism Wiki - Wikia [Last Updated On: December 2nd, 2016] [Originally Added On: December 2nd, 2016]
- Make Money from Images, Documents and Photos Uploading [Last Updated On: December 7th, 2016] [Originally Added On: December 7th, 2016]
- Immortal but Damned to Hell on Earth - The Atlantic [Last Updated On: January 29th, 2017] [Originally Added On: January 29th, 2017]
- Faultlines, black holes and glaciers: mapping uncharted territories - The Guardian [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- How to keep your children safe online as it's revealed half of six-year-olds use the internet - Mirror.co.uk [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Yetunde Olasiyan: Between Having a Voice & the Need to Show Off on Social Media - Bella Naija [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- How a WiFi Pilot Program Is Helping Students in the Rio Grande Valley - Texas Public Radio [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Looking for a New Job? 4 Ways to Job Search Discreetly - U.S. News & World Report (blog) [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Khloe Kardashian narrowly avoids a wardrobe malfunction in sexy underwear photo - OK! Magazine [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- How a WiFi Pilot Program Is Helping Students in the Rio Grande Valley - KWBU [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Connectivity in a digital world - Iowa City Press Citizen [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Does Your Vision for Your Life Cause You to Look Up...or Down? - Huffington Post [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- How to improve your LinkedIn profile - ArabianBusiness.com [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- How a WiFi Pilot Program Is Helping Students in the Rio Grande Valley - KUT [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Deal: New customers can get Google Play Music and YouTube Red free for 4 months - Android Authority (blog) [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- Procurious and SOPO Launch Innovative Online Community Platform for Government Procurement Professionals - PR Newswire UK (press release) [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- Breaking Down Global Silos (Part 2): Lessons Learned from Conflict - Spend Matters [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Robbie Williams' wife Ayda proves she's the best ever as she completely overshares with hilarious birthday card to him - The Sun [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Morality and Murder Collide in Two New Horror Movies - Film School Rejects [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Jefferson schools urged to use cable TV station - Daily Union [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Olly Murs sings Happy Birthday to Robbie Williams with full backing band in sweet video - The Sun [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Eric Adler Is Living The Dream With The New England Patriots - Cape Cod Chronicle [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- Squash review: Drop and compress your way to smaller image files in a flash - Macworld [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- It's time to get tech-savvy with The Mind Lab by Unitec! - Scoop.co.nz [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- Tennyson soundtracks movies for your mind with Like What - Straight.com [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- Fake news, who benefits? - Shelbyville Times-Gazette (blog) [Last Updated On: February 17th, 2017] [Originally Added On: February 17th, 2017]
- Crazy Videos on YouTube That No One Can Explain - Thrillist [Last Updated On: February 18th, 2017] [Originally Added On: February 18th, 2017]
- Barbie becomes a hologram version of herself - TechCrunch [Last Updated On: February 18th, 2017] [Originally Added On: February 18th, 2017]
- The Owl at the Window review: They the living - Irish Times [Last Updated On: February 18th, 2017] [Originally Added On: February 18th, 2017]
- Tax Software: The Basics Work, but Peace of Mind Costs Extra - New York Times [Last Updated On: February 18th, 2017] [Originally Added On: February 18th, 2017]
- How To Run A Rogue Government Twitter Account With An Anonymous Email Address And A Burner Phone - UPROXX [Last Updated On: February 20th, 2017] [Originally Added On: February 20th, 2017]
- The three reasons YouTubers keep imploding, from a YouTuber - Polygon [Last Updated On: February 22nd, 2017] [Originally Added On: February 22nd, 2017]
- SnailBlitz 2017: Citizen Scientists Wanted - NBC Southern California [Last Updated On: February 22nd, 2017] [Originally Added On: February 22nd, 2017]
- Breakdown In Immigration Screening: The Devil Is In The Details - Daily Caller [Last Updated On: February 22nd, 2017] [Originally Added On: February 22nd, 2017]
- Appealing Social Security Decisions Online - Danbury News Times [Last Updated On: February 26th, 2017] [Originally Added On: February 26th, 2017]
- Nikon D5600 Review: Hoping to Make Photo Transfers a Snap - Huffington Post [Last Updated On: February 26th, 2017] [Originally Added On: February 26th, 2017]
- How to file your social security appeal online - KARE [Last Updated On: February 28th, 2017] [Originally Added On: February 28th, 2017]
- Comparison: 3 Platforms Paying You in Bitcoin for Uploading Images - Nigeria Today [Last Updated On: February 28th, 2017] [Originally Added On: February 28th, 2017]
- How to file your social security appeal online - WZZM13.com [Last Updated On: February 28th, 2017] [Originally Added On: February 28th, 2017]
- How To File Your Social Security Appeal Online - WFMYNews2.com [Last Updated On: March 1st, 2017] [Originally Added On: March 1st, 2017]
- B2B processes get smarter in the cloud - TechTarget [Last Updated On: March 2nd, 2017] [Originally Added On: March 2nd, 2017]
- Data limits are the worsthere's how to stay under yours - Popular Science [Last Updated On: March 2nd, 2017] [Originally Added On: March 2nd, 2017]
- Overcome problems with public cloud storage providers - TechTarget [Last Updated On: March 4th, 2017] [Originally Added On: March 4th, 2017]
- From AI to Anxiety Relief, The Brain Needs a Body - Big Think [Last Updated On: March 4th, 2017] [Originally Added On: March 4th, 2017]
- The Modest Problem of Death: On Mark O'Connell's To Be a Machine - lareviewofbooks [Last Updated On: March 4th, 2017] [Originally Added On: March 4th, 2017]
- Mind the gap: burn and destroy mission in Bengal fields leaves a few questions - Hindustan Times [Last Updated On: March 5th, 2017] [Originally Added On: March 5th, 2017]
- A man with vitiligo who was called 'zebra' by bullies has defied their cruel comments by becoming a model - The Sun [Last Updated On: March 8th, 2017] [Originally Added On: March 8th, 2017]
- Cam Site Launches iTunes-Like Marketplace Of Oral Sex For Women - AskMen [Last Updated On: March 10th, 2017] [Originally Added On: March 10th, 2017]
- Everything new in Stellaris: Utopia, one of Paradox's biggest game ... - PC Gamer [Last Updated On: March 10th, 2017] [Originally Added On: March 10th, 2017]
- Paytm to continue free uploading of money - Business Standard [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- Paytm to continue free uploading of money | Free Press Journal - Free Press Journal [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- How to upload photos to Instagram from a PC: Upload your favourite images to Instagram on Windows 10 without a ... - PC Advisor [Last Updated On: March 17th, 2017] [Originally Added On: March 17th, 2017]
- 2017 Foresight Fellows Announced in Molecular Machines, Space, Longevity, Artificial Intelligence - Benzinga [Last Updated On: March 17th, 2017] [Originally Added On: March 17th, 2017]
- Best Practices for 2017 SEO Audits [PODCAST] - Search Engine Journal [Last Updated On: March 23rd, 2017] [Originally Added On: March 23rd, 2017]
- Science to Beat the Death: 200 300 years old human in the Future! - Sri Lanka Guardian [Last Updated On: March 23rd, 2017] [Originally Added On: March 23rd, 2017]
- Microsoft's Windows 10 Creators Update lives up to its name - Engadget [Last Updated On: March 29th, 2017] [Originally Added On: March 29th, 2017]
- Film reviews: Ghost In The Shell and other releases - Herald Scotland [Last Updated On: April 2nd, 2017] [Originally Added On: April 2nd, 2017]
- Death of a Dystopian - The New Yorker [Last Updated On: April 3rd, 2017] [Originally Added On: April 3rd, 2017]
- Stealth Rick and Morty premiere a delightful surprise - Marquette Wire [Last Updated On: April 3rd, 2017] [Originally Added On: April 3rd, 2017]
- Severe Weather Risk on Wednesday - WEAR [Last Updated On: April 5th, 2017] [Originally Added On: April 5th, 2017]
- Showtime docu-series sees the 'Dark' side of tech - LA Daily News [Last Updated On: April 5th, 2017] [Originally Added On: April 5th, 2017]
- Report It - Maui Now [Last Updated On: April 7th, 2017] [Originally Added On: April 7th, 2017]
- The perils and false rewards of parenting in the era of 'digi-discipline' - Minnesota Public Radio News [Last Updated On: April 7th, 2017] [Originally Added On: April 7th, 2017]
- Elon Musk: Australian man pens desperate letter to download his brain - NEWS.com.au [Last Updated On: April 7th, 2017] [Originally Added On: April 7th, 2017]
- Police body cameras part of Dothan's new integrated system - Dothan Eagle [Last Updated On: April 10th, 2017] [Originally Added On: April 10th, 2017]
- This Is the Dawn of Brain Tech, But How Far Can It Go? - Singularity Hub [Last Updated On: April 12th, 2017] [Originally Added On: April 12th, 2017]
- 7 easy ways to make your iPhone videos look pro - CNET [Last Updated On: April 13th, 2017] [Originally Added On: April 13th, 2017]