In-depth

Is your enterprise a security thicko?

Security training needs to be much more targeted if it is to be successful, argues Davey Winder.

Recent research by Ernst and Young found that some 96 per cent of the 1,900 folk questioned felt unprepared when it comes to a potential cyber attack.

As you might expect given, an accountancy firm conducted the research, money was the main driver, but right behind it just three percentage points down,  a lack of skilled staff was being blamed for preventing good security.

What I found interesting was that the report also seemed to confirm that awareness of security issues had increased (with 70 per cent of those asked agreeing that IT security is being dealt with at a high level within the organisation, and a further 43 per cent saying that IT security budgets have risen). This made me wonder, whether that awareness of security issues is being directed at the right people and if the budgets should perhaps include a bigger proportion spent on education and training rather than concentrating mainly on defensive systems and software.

Nobody wants to be the class thicko, but with 32 per cent of respondents to that survey placing awareness and training last on their list of priorities (it finished second to last overall with threat and vulnerability management, surprisingly,  bottom of the priority pops) is there a danger that this is exactly what might be happening?

Could do better

Few people would argue that a lack of proper security awareness training within the enterprise increases the risk of successful attack, or take issue with the flipside of that statement that improving education and training of staff when it comes to IT security helps mitigate that risk.

So could the average enterprise do better? Let's look at some statistics, such as the online survey of UK office workers conducted independently by YouGov for Proofpoint. This showed 43 per cent of workers have received training on data and privacy protection but a staggering 37 per cent have not received any training at all. This last number is interesting in that it tends to crop up rather a lot, such as when Outpost24 perform social engineering tests. CSO Martin Jarteilus told me that they typically manage to hit between 20 per cent and 35 per cent of the staff targeted. A figure that increases to as much as 50 per cent when they include LinkedIn or Facebook in the attack toolbox.

"We have reached a level where 10 per cent of the users have provided usernames and passwords to a phishing website created for the security test," Jarteilus says.

He added that in a recent study targeting a government agency in Sweden "our testers could walk into not only the finance departments but also into a locked down office where external visitors were not allowed, all by smiling and being nice."

So when David Robinson, CSO and director of information security at Fujitsu in the UK and Ireland, insists that enterprises could do much better when it comes to training ans awareness, it really comes as no surprise at all.

Featured Resources

2021 Thales cloud security study

The challenges of cloud data protection and access management in a hybrid and multi cloud world

Free download

IDC agility assessment

The competitive advantage in adaptability

Free Download

Digital transformation insights from CIOs for CIOs

Transformation pilotes, co-pilots, and engineers

Free download

What ITDMs did next - and what they should be doing now

Enable continued collaboration and communication for hybrid workers

Recommended

The IT Pro Podcast: Why techies shouldn’t become managers
Careers & training

The IT Pro Podcast: Why techies shouldn’t become managers

10 Sep 2021
Podcast transcript: Why techies shouldn’t become managers
Careers & training

Podcast transcript: Why techies shouldn’t become managers

10 Sep 2021
The IT Pro Podcast: How umbrella companies exploit IT contractors
IT regulation

The IT Pro Podcast: How umbrella companies exploit IT contractors

3 Sep 2021
Podcast transcript: How umbrella companies exploit IT contractors
IT regulation

Podcast transcript: How umbrella companies exploit IT contractors

3 Sep 2021

Most Popular

What should you really be asking about your remote access software?
Sponsored

What should you really be asking about your remote access software?

17 Nov 2021
How to move Microsoft's Windows 11 from a hard drive to an SSD
Microsoft Windows

How to move Microsoft's Windows 11 from a hard drive to an SSD

24 Nov 2021
Nike to take customers into the metaverse with 'NIKELAND'
virtualisation

Nike to take customers into the metaverse with 'NIKELAND'

19 Nov 2021