It's time for an enterprise security education week

There's still the need for greater awareness of enterprise security risks, according to Davey Winder...

Education technology
I'm not usually one to advocate the likes of the consumer oriented 'Get Safe Online' campaign, which ran last week, not least because I think they are a waste of time. However, I am fast reaching the conclusion that something similar is required within the enterprise space. The alternative, I fear, is we start waving a white flag and surrender to the bad guys.
Don't get me wrong, I'm not falling into the trap of slagging off awareness campaigns for the sake of it, but organising coffee mornings, talking to 'vulnerable users' and spreading the word about cyber security is pointless unless the message is heard, understood and implemented further up the food chain.
Likewise, teaching kids about cyber-security skills from the age of 11 as part of the national curriculum might be good PR in the run up to a general election, but will do little unless it's properly taught and that means using teachers whop properly understand the issues and how to solve them.
Will the government make sufficient money, any money, available in order to teach the teachers? I doubt it. Will the government produce sufficient incentives for members of the IT security business sector to donate time and effort to teach the kids? Ditto. That ditto effect carries over to the Get Safe Online debate, and my argument that we need to be moving the emphasise from just educating the end user to educating the technology providers as well. I can sum my side of the debate up thus: end users are idiots for using weak passwords, ditto to the providers that let them. End users are idiots for sharing passwords, ditto to the providers that do nothing to prevent this behaviour. 
Advertisement - Article continues below
Why should the enterprise care? Because you can swap end user and employee with impunity, the end results are the same. According to Chris Sullivan, vice president of Advanced Solutions at security outfit Courion, some 61 per cent of security incidents are caused by rogue employees and 13 per cent of data breaches feature an abuse of access privileges. Still not convinced that training and education are critical?  
According to research from Centrify Corporation, the average employee wastes 261 a year (in lost productivity) trying to manage multiple passwords, which soon adds up in the average enterprise. So why aren't you educating them to prevent this? In fact, why aren't you providing a better system so they don't have to?
So, who's with me; who's up for an Enterprise Security Education Week and who's going to get the ball rolling?
Featured Resources

The essential guide to cloud-based backup and disaster recovery

Support business continuity by building a holistic emergency plan

Download now

Trends in modern data protection

A comprehensive view of the data protection landscape

Download now

How do vulnerabilities get into software?

90% of security incidents result from exploits against defects in software

Download now

Delivering the future of work - now

The CIO’s guide to building the unified digital workspace for today’s hybrid and multi-cloud strategies.

Download now



Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019

Most Popular

Microsoft Azure

Microsoft, not Amazon, is going to win the cloud wars

30 Nov 2019

Raspberry Pi 4 owners complain of broken Wi-Fi when using HDMI

29 Nov 2019
Amazon Web Services (AWS)

What to expect from AWS Re:Invent 2019

29 Nov 2019
Google Android

Samsung Galaxy A90 5G review: Simply the best value 5G phone

22 Nov 2019