New York Tech Media
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
New York Tech Media
No Result
View All Result
Home Cybersecurity

The four types of remote workers your security awareness program must address

New York Tech Editorial Team by New York Tech Editorial Team
February 7, 2022
in Cybersecurity
0
Supply chain cybersecurity: Pain or pleasure?
Share on FacebookShare on Twitter

No matter how much technology you acquire or how many specific technical controls you install, when it comes to your information security awareness program, the most important control to tune within your environment is your people.

information security awareness program

I’m not telling you anything new here. But as we move into a third year of employees either working regularly from home or coming back into an environment which may be dramatically reconfigured and is staffed differently than before (the office), we are not going back to the way things were in “the before times”.

It’s important that your current security awareness efforts are appropriate for how your employees work today, not how they worked two years ago.

Here are four employee personas for you to consider and recognize as you review and update your security awareness program:

Employees as first-line defenders. The strongest security cultures are those where each employee fully understands that they are on the front lines. They are extended members of and the early warning system for your core team in the SOC.

Make it easy for them to express concern about something they’ve seen or experienced. It’s the same mindset of the “If you see something, say something” mantra we all see when we take public transportation. Don’t settle for developing and publishing an overly complicated policy which details the many steps the employee should follow if they believe there is suspicious activity. There’s often too much friction.

Think instead about how that concerned employee can quickly reach your information security team directly via a phone call and via chat. Providing multiple channels to ask for help increases the chances that one of them will be used. An employee who finds it too hard to fill out your helpdesk form to open a ticket may be an employee who decides it’s just not worth it.

Employees as people. And people are not machines. We get distracted. We get tired. We make mistakes. We want to do the right thing for our organization, and we need to get our job done, but sometimes it can seem like both goals are in opposition to one another.

When your training curriculum is presented like most other trainings employees consume – sitting through a multiple-choice exercise, trying to hit the minimum passing score to just to get it out of the way – you run the risk of your audience tuning out.

Consider a continuous “drip” approach versus a once-a-year “hammer” approach. One way to accomplish this is to wrap additional content around the main curriculum/test each year – in some organizations, the wrapper might even replace the single test.

One example: a quarterly email which directly connects a reported incident elsewhere in the industry to the employee behavior which led to the incident.

Taking a more overt approach where you explicitly nudge employees during their day-to-day work is another alternative: you may have technology in place which can monitor email during composition and insert a “are you sure?” prompt when an email is going outside the organization to a known-risky domain, or if it contains an attachment with sensitive information.

Employees as parents. Employees with families have found the last two years especially challenging. They didn’t sign up to do their own tech support at home. They didn’t sign up to enforce your corporate-grade security rules within their home environment. And they didn’t sign up for sometimes unusual working hours and significantly increased stress when trying to be a worker and a parent during a pandemic, when those two roles are sitting behind the very same laptop on the dining room table.

Help them, show them how to secure their work devices and their home devices. Don’t be afraid to explain the “why” along with the “how.”

As an example, maybe you sent out explicit guidance about home networks: “Make sure your Wi-Fi router’s password is complex.” Good advice, to be sure. But from the employee’s perspective, what exactly is a complex password? Why is it that a complex password does a better job protecting an information asset versus a non-complex password? Where can a non-technical employee check to see what the current Wi-Fi password is? Is there a difference between an administrative password and the password they use to join a device to their Wi-Fi network? How do they recognize the distinction between their Wi-Fi router and their cable modem? Issue your guidance but take the time and the care to explain.

Employees as threats. We know that there are two primary types of threats from our employee population: accidental, and intentional. Your security awareness content should account for these two audiences.

Trainings should include scenarios involving both external and internal threat actors, scenarios which are more than “don’t do this” but “if you see this, here’s what to do.” This can also be a good opportunity to explain exactly why your organization reserves the right to monitor employees. And even in environments where you may be less concerned about insider risk, ensure that your training also includes a third-party angle, especially for that subset of your team who works with external partners.

There will always be employees who just don’t care, who won’t care, and can’t be bothered to pay attention to your training curriculum. Your job is to reach as much of your audience as you can, and to recognize that outliers will always exist.

Remember: work is not a location, but an outcome. Now is the right time to review your existing security awareness program to confirm it respects the new reality your remote employees are experiencing every day.

Credit: Source link

Previous Post

San Diegans competing in the world competition

Next Post

Product showcase: Group-IB Atmosphere – Help Net Security

New York Tech Editorial Team

New York Tech Editorial Team

New York Tech Media is a leading news publication that aims to provide the latest tech news, fintech, AI & robotics, cybersecurity, startups & leaders, venture capital, and much more!

Next Post
Product showcase: Group-IB Atmosphere – Help Net Security

Product showcase: Group-IB Atmosphere - Help Net Security

  • Trending
  • Comments
  • Latest
Meet the Top 10 K-Pop Artists Taking Over 2024

Meet the Top 10 K-Pop Artists Taking Over 2024

March 17, 2024
Panther for AWS allows security teams to monitor their AWS infrastructure in real-time

Many businesses lack a formal ransomware plan

March 29, 2022
Zach Mulcahey, 25 | Cover Story | Style Weekly

Zach Mulcahey, 25 | Cover Story | Style Weekly

March 29, 2022
10 Raunchy Movies on Netflix You Won’t Regret Watching

10 Raunchy Movies on Netflix You Won’t Regret Watching

May 20, 2024
How To Pitch The Investor: Ronen Menipaz, Founder of M51

How To Pitch The Investor: Ronen Menipaz, Founder of M51

March 29, 2022
Japanese Space Industry Startup “Synspective” Raises US $100 Million in Funding

Japanese Space Industry Startup “Synspective” Raises US $100 Million in Funding

March 29, 2022
Startups On Demand: renovai is the Netflix of Online Shopping

Startups On Demand: renovai is the Netflix of Online Shopping

2
Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

1
Menashe Shani Accessibility High Tech on the low

Revolutionizing Accessibility: The Story of Purple Lens

1

Netgear announces a $1,500 Wi-Fi 6E mesh router

0
These apps let you customize Windows 11 to bring the taskbar back to life

These apps let you customize Windows 11 to bring the taskbar back to life

0
This bipedal robot uses propeller arms to slackline and skateboard

This bipedal robot uses propeller arms to slackline and skateboard

0
laptop on glass table

Automat-it Cuts Deployment Friction as Monce Scales AI Order Processing on AWS

April 13, 2026
Lee's Famous Recipe Chicken

Why Lee’s Famous Recipe Chicken Is Betting on Hi Auto to Quietly Rewire the Drive-Thru

April 9, 2026
computer generated image of letters

San Francisco Tribune Lists 11 HumanX Startups Moving AI Closer to the Operating Core

April 8, 2026
Impala CEO and Highrise AI CEO

The Industrialization of AI Infrastructure: What Impala and Highrise AI Reveal About the Next Scaling Frontier

April 7, 2026
Employee Time Tracking

What is an Employee Time Tracking Solution? A Definite Guide for 2026

March 31, 2026
Voltify founders

Voltify Raises $30 Million Seed Round as It Challenges $1 Trillion Rail Electrification Model

March 31, 2026

Recommended

laptop on glass table

Automat-it Cuts Deployment Friction as Monce Scales AI Order Processing on AWS

April 13, 2026
Lee's Famous Recipe Chicken

Why Lee’s Famous Recipe Chicken Is Betting on Hi Auto to Quietly Rewire the Drive-Thru

April 9, 2026
computer generated image of letters

San Francisco Tribune Lists 11 HumanX Startups Moving AI Closer to the Operating Core

April 8, 2026
Impala CEO and Highrise AI CEO

The Industrialization of AI Infrastructure: What Impala and Highrise AI Reveal About the Next Scaling Frontier

April 7, 2026

Categories

  • AI & Robotics
  • Benzinga
  • Cybersecurity
  • FinTech
  • New York Tech
  • News
  • Startups & Leaders
  • Venture Capital

Tags

AI AI QSRs Allseated Automat-it AWS B2B marketing Business CISO CISO Whisperer Collaborations Companies To Watch cryptocurrency Cybersecurity Entrepreneur Fetcherr Finance FINQ Fintech Funding Announcement hi-tech Hi Auto Impala Investing Investors investorsummit Israel israelitech Leaders LinkedIn Leaders Metaverse Mindset Minnesota omri hurwitz PointFive PR QSR Real Estate start- up startupnation Startups Startups On Demand Tech Tech leaders Unlimited Robotics VC
  • Contact Us
  • Privacy Policy
  • Terms and conditions

© 2024 All Rights Reserved - New York Tech Media

No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital

© 2024 All Rights Reserved - New York Tech Media