You are the weakest link

Byte-size Bulletin by Simon Heath in Security, News on May 28, 2021

Hole-in-the-fence-resized
 

It appears we humans aren’t helping enough with cyber security.

In fact, we are our own worst enemies according to 2020’s DBIR finding that 67% of breaches come from credential theft, errors and social attacks.

Verizon Media’s information security team, who call themselves The Paranoids, felt traditional security awareness training wasn’t cutting the mustard. It didn’t mimic real life or parallel behaviours that led to breaches, nor measure against real attacks.

They turned to Huang and Pearlson’s cyber security model that believes the right behaviour is driven by values, attitudes and beliefs visible at leadership, group and individual level. Influencing how employees prioritise and practice cyber security allows managers to create the right culture.

And it worked. Over two years they:

  • Tripled the adoption of password management software.
  • Halved phishing susceptibility.
  • Doubled accurate phishing reports.

Success is based on three steps:

  1. Identify a specific action that stops attacks.
  2. Measure it against a baseline.
  3. Test managerial mechanisms to improve the numbers, in other words - continuous improvement.

You can find Huang and Pearlson’s academic paper here and a case study on Verizon Media here.

 

The image is taken from the cover of the DBIR

Subscribe to our Bulletins





Free Download

Is IT a bottleneck to your company’s growth?

Discover how small business IT support can be a strong ally in making you more productive and competitive.

Download Ebook

bottlenecks