In-depth

It's time for an enterprise security education week

There's still the need for greater awareness of enterprise security risks, according to Davey Winder...

Education technology

I'm not usually one to advocate the likes of the consumer oriented 'Get Safe Online' campaign, which ran last week, not least because I think they are a waste of time. However, I am fast reaching the conclusion that something similar is required within the enterprise space. The alternative, I fear, is we start waving a white flag and surrender to the bad guys.

Don't get me wrong, I'm not falling into the trap of slagging off awareness campaigns for the sake of it, but organising coffee mornings, talking to 'vulnerable users' and spreading the word about cyber security is pointless unless the message is heard, understood and implemented further up the food chain.

Likewise, teaching kids about cyber-security skills from the age of 11 as part of the national curriculum might be good PR in the run up to a general election, but will do little unless it's properly taught and that means using teachers whop properly understand the issues and how to solve them.

Will the government make sufficient money, any money, available in order to teach the teachers? I doubt it. Will the government produce sufficient incentives for members of the IT security business sector to donate time and effort to teach the kids? Ditto. That ditto effect carries over to the Get Safe Online debate, and my argument that we need to be moving the emphasise from just educating the end user to educating the technology providers as well. I can sum my side of the debate up thus: end users are idiots for using weak passwords, ditto to the providers that let them. End users are idiots for sharing passwords, ditto to the providers that do nothing to prevent this behaviour. 

Why should the enterprise care? Because you can swap end user and employee with impunity, the end results are the same. According to Chris Sullivan, vice president of Advanced Solutions at security outfit Courion, some 61 per cent of security incidents are caused by rogue employees and 13 per cent of data breaches feature an abuse of access privileges. Still not convinced that training and education are critical?  

According to research from Centrify Corporation, the average employee wastes 261 a year (in lost productivity) trying to manage multiple passwords, which soon adds up in the average enterprise. So why aren't you educating them to prevent this? In fact, why aren't you providing a better system so they don't have to?

So, who's with me; who's up for an Enterprise Security Education Week and who's going to get the ball rolling?

Featured Resources

Choosing a collaboration platform

Eight questions every IT leader should ask

Download now

Performance benchmark: PostgreSQL/ MongoDB

Helping developers choose a database

Download now

Customer service vs. customer experience

Three-step guide to modern customer experience

Download now

Taking a proactive approach to cyber security

A complete guide to penetration testing

Download now

Recommended

Geico data breach leads to stolen driver’s license numbers
data breaches

Geico data breach leads to stolen driver’s license numbers

21 Apr 2021
UK’s IoT security regulation will also include smartphones
Internet of Things (IoT)

UK’s IoT security regulation will also include smartphones

21 Apr 2021
eBay, Apple, Microsoft, Facebook, and Google were phishers’ top targets in 2020
phishing

eBay, Apple, Microsoft, Facebook, and Google were phishers’ top targets in 2020

20 Apr 2021
Mastering endpoint security implementation
Security

Mastering endpoint security implementation

16 Apr 2021

Most Popular

Microsoft is submerging servers in boiling liquid to prevent Teams outages
data centres

Microsoft is submerging servers in boiling liquid to prevent Teams outages

7 Apr 2021
How to find RAM speed, size and type
Laptops

How to find RAM speed, size and type

8 Apr 2021
UK exploring plans to launch its own digital currency
digital currency

UK exploring plans to launch its own digital currency

19 Apr 2021