Employee Security Training: Beyond Posters
Your employees need more than slogans. Here's how to get them to take security seriously
Computerworld - It's the kind of breach that companies fear: workers giving out network log-in names or changing passwords when asked to by someone posing as an IT staffer.
The best firewalls on the market can't protect against such scenarios.
"Why even lock your doors if employees happily hold them open for a stranger following behind them?" asks Alex Ryan, security officer at VeriCenter Inc., an IT infrastructure and managed services provider in Houston.
The risk that employees pose is significant. They can fall prey to social engineering, a fancy term for being conned. They can ignore company policy by failing to encrypt sensitive data. Or they might install unauthorized software that can corrupt the system.
Think you're well protected? Recent findings from the Computing Technology Industry Association might convince you otherwise. In this year's CompTIA information security study, 59% of the organizations surveyed indicated that their latest security breaches were the result of human error alone. That's up from 47% last year.
Despite such statistics, many companies fail to do enough to educate their workers. That's what the Internal Revenue Service discovered, according to a March 2005 federal government report.
Federal inspectors posing as IT help desk staffers trying to correct a network problem called 100 IRS managers and employees and asked them to provide their network log-in names and temporarily change their passwords to ones they suggested. Inspectors persuaded 35 IRS workers to do just that.
This success came despite IRS efforts to educate employees.
Dan Galik, the IRS's chief security officer, says his agency "re-energized the awareness program" following the report. In addition to annual reviews, posted announcements and online courses mandated under the 2002 Federal Information Security Management Act, Galik says the agency has added some innovative approaches.
One was a Jeopardy-style game held last November during which workers tried to give the right answers on security-related topics.
"You've got to come up with something that will stick," Galik says.
Here are some other practices that have proved effective in getting the message across.
Make It Personal
"Many employees worry about their home machines' security. Leverage that concern to promote general security principles that can be applied at both home and work," Ryan says. "It's a way to make people personally interested in security." She e-mails employees newsletters with tips that alert them to the latest scams or viruses that could affect both their work and personal PCs.
Source: Exclusive Computerworld survey, March 2006



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
- Identity Governance: The Business Imperatives
- This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make... All Security White Papers
- Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game - When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
- Introduction to VMware vCenter Site Recovery Manager 5
- Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
- The Top Ten Secrets to Avoiding SAN Performance Problems
- Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
- Deduplication Without Compromise
- Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
- Director of Disk Products Discusses DXi6700
- Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts