Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Teaching Staff To Respect The Risk Of A Data Breach
Articles

Teaching Staff To Respect The Risk Of A Data Breach

ISBuzz TeamBy ISBuzz TeamFebruary 18, 2017Updated:December 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Data Breach Responsibility
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Last year was another one characterized by constant, confusing, and highly consequential data breaches. At this point, all organizations need to take this persistent threat seriously. Yet research by the Ponemon Institute reveals that just 35 percent of respondents who are familiar with their companies’ data protection and privacy training programs feel that executives prioritize their employees’ understanding of the causes and effects of data breaches.

This statistic should concern every organization. Although attacks on data originate from external sources, the vulnerabilities exist internally. In fact, employees themselves are most often responsible for introducing a threat into an IT infrastructure. Most executives who realize that their employees don’t know much about security also struggle with the fact that, if there is a major breach, it’s them — the CEOs and CIOs — who will lose their jobs.

Consider a Symantec report from 2016 that revealed the number of spear-phishing attacks directed at employees increased by 55 percent in 2015, ransomware attacks went up by 35 percent, and around 100 million fake technical support scams were thwarted. These types of attacks, having been specifically designed to take advantage of the knowledge gap that exists within most organizations on the subject of security, are only effective when an internal employee enables them to bypass security protocols.

Such increases are especially troubling because the dominant approach to cybersecurity is based on securing assets using advanced technologies instead of educating employees who carry the keys to the vault, so to speak. This type of risk management is both incomplete and ill-equipped to handle the sophisticated, intelligent threats of today, much less those of tomorrow.

Companywide security initiatives must place a major focus on social engineering in order to minimize the risk of user errors. In all organizations, but especially in those operating within highly vulnerable fields such as healthcare and finance, true cybersecurity is impossible without extensive user education. Employing the following strategies can help them begin to address the problem.

  1. Institute a culture of security. Due to the evolving nature of data threats, organizations cannot focus on a specific group of employees or a certain type of behavior in order to eliminate user errors. On the contrary, they must foster a culture in which everyone understands, respects, and keeps security top of mind.

Highlighting the consequences of a data breach is a reliable way to secure buy-in from employees at all levels. Point out that the cost of data breaches quadrupled between 2013 and 2015 and is expected to quadruple again by 2019 to an estimated $2.1 trillion. Astronomical figures like those underscore just how existential the threat of data breaches has become.

  1. Train, test, repeat. Relying on memos and bulletins to educate employees about the part they play in network security is ineffective because it misrepresents the scale of the threat. Moreover, training can seem impersonal if done remotely, and people will multitask while taking it.

Face-to-face training is essential so attendees can ask questions and wrap their heads around the issue, but a one-time session is not adequate. Repetition on at least a quarterly basis helps reinforce core concepts while keeping security issues top of mind. Emphasize how threats put both institutional and personal employee data at risk to help promote engagement.

The final component is to test the efficacy of that training by testing employees without their knowledge. Dummy phishing attacks sent out by the IT department can reveal individuals and teams who require further training. Currently, up to 30 percent of all phishing emails do get opened. Recurrent training and testing are the only reliable ways to reduce this alarming figure.

  1. Reward best practices. Even with the most educated and committed IT team in place, it can be difficult to personalize security best practices. Instead of punishing users for a breach in protocol, reward those who abide by best practices and effectively respond to both real and simulated threats with extra paid time off or whatever best motivates employees.

Gamifying the process with a practice log where points are earned can nurture a healthy sense of competition. In a survey about e-learning, 89 percent of respondents said that a point-based system would help them stay more actively engaged. Offering some sort of prize or perk creates a powerful incentive and boosts enthusiasm about security, which might otherwise seem like a dry subject.

Staff awareness is not just a component of a security strategy — it is the foundation. A brief history of cybersecurity shows that all prior tech-based tools have been incomplete or quickly became obsolete. Even when they work perfectly, a seemingly secure environment can easily be compromised by the innocent mistake of a single, uninformed user.

As threats continue to proliferate, organizations must see past the myopic notion that computers, not users, are the problem and can provide the solution. A concerted effort to boost staff awareness is not guaranteed to deflect all attacks. However, it is the best way to prevent most breaches. Organizations that rely only on external solutions will always be at risk.

[su_box title=”About Karin Ratchinsky” style=”noise” box_color=”#336588″][short_info id=’100796′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}