Councils spend more on 'mindfulness' than on IT security
Research has revealed they are spending nine times more on health and safety than IT security
Research by Citrix has revealed councils are spending nine times as much money on health and safety training than IT security training, which could have detrimental consequences.
An average of 27,818 is spent by the average local authority on health and safety, yet the budget only stands at 3,378 for IT security training.
While the total council spend on 'mindfulness' training was 140,888.81 in 2016, it stood at just 56,441.13 for IT security and 48,269.97 on data protection.
The amount spent on educating staff around health and safety issues has almost doubled in the last 12 months and includes topics such as meditation, working at heights and managing difficult situations, yet protecting IT systems against cyber criminals has fallen behind.
However, the information did point out that councils are making smart devices such as smartphones and tablets a key part of their IT strategy, with an average of 714 smart devices in use per local authority.
"A broad scope of training is vital in today's work environment," Jon Cook, director of sales at Citrix UK & Ireland, said. "We commend local authorities for arming their employees with these additional skills, as well as seeking to improve their work/life balance through issuing smart devices and committing to a well-rounded programme of training courses."
A total 86% of local authorities failed to spend anything at all on IT security training, data provided by Citrix's Freedom of Information (FoI) request revealed, and 40% of the smart devices in use by personnel aren't protected by enterprise mobility management software.
"Sadly investing in IT security usually falls quite low in the spending list for most local authorities," Mark James, security specialist at ESET, said.
"The consequences for failures in IT sec are significantly lower than other areas with no clear guidelines on what constitutes a failure. If you back that up with unsuccessful or fairly insignificant fines then in most cases it's easier to do something about it after it happens than before."
The report revealed that 24% of local authorities do make use of free e-learning' or on the job' data protection and IT security training to help educate staff, but Citrix said more effort must be made to protect the organisation.
"With the responsibility for managing citizen data, coupled with the risk of penalties of up-to 500,000 for data-breaches, it is crucial that employees know how to keep information secure from external threats," Cook said.
"With the stakes so high, councils must ensure that staff understand the importance of data protection in the growing threat landscape."
What you need to know about migrating to SAP S/4HANA
Factors to assess how and when to begin migrationDownload now
Your enterprise cloud solutions guide
Infrastructure designed to meet your company's IT needs for next-generation cloud applicationsDownload now
Testing for compliance just became easier
How you can use technology to ensure compliance in your organisationDownload now
Best practices for implementing security awareness training
How to develop a security awareness programme that will actually change behaviourDownload now