Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Changing the Security Culture within an Organisation – How to be Forearmed Against an Internal Data Breach
Articles

Changing the Security Culture within an Organisation – How to be Forearmed Against an Internal Data Breach

ISBuzz TeamBy ISBuzz TeamMay 21, 2015Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Changing the Security Culture within an organisation
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Hindsight can be a wonderful thing, but when it comes to data security and potential breaches, it’s best to ensure that your security policies and tools are able to protect your organisation. Yet, despite the regular headlines caused by high-profile data breaches, many organisations still do not know how best to react once breached or, indeed, follow best practice to prevent a breach from happening in the first instance.

New research conducted by Bloor Research, in conjunction with Boldon James, highlighted data security as a critical or serious concern for most organisations surveyed, with data classification recognised as a foundational tool for ensuring data security. But whilst organisations may have the best intentions, some are still missing a trick and suffering with potentially-costly data breaches that not only impact on revenue (particularly with the impending European General Data Protection Directive set to come into effect shortly) but also their reputation within the industry and customer base.

So what measures should organisations look to implement, both in advance of, or after, a breach to ensure they have effective information governance strategies in place?

Don’t spend, spend, spend on any old security tool

Imagine the worst has happened and your organisation has suffered a data breach because a highly sensitive document was shared with a third party instead of a colleague. What do you do? Our research revealed that the most common reaction following a data breach (accounting for 86% of respondents) is to pump money into purchasing new data security tools and attempt to tighten security policies, assuming this will diminish the risk of future breaches.

This poses the question of which tools do you actually need? Is it a firewall, a Data Loss Prevention (DLP) solution, a Network Access Control (NAC) device, Security Information and Event Monitoring (SIEM) solution? All of the above? Organisations are faced with lots of options on new and next generation tools to purchase, but before they can make a choice they must also decide what it is they need to protect and how they are going to solve the overarching problem of understanding the value of the data to the business – if you don’t know what your data is, how can you decide how to protect it?

Many analysts including Forrester and Gartner now recommend that organisations adopt a data-centric security strategy. This means deploying tools that ensure the security afforded to an email or document (or any data within the corporate network) travels with that data throughout its lifecycle to inform any and all security decisions. Organisations can no longer just set up security policies and permissions that end at the network perimeter. With an increase in the ways data is shared and also the devices on which data is held in the workplace, data needs to be stored and communicated carefully and correctly to minimise the risk of a data breach, particularly with the advent of the BYOD and CYOD trends within businesses.

Include the users; don’t hide data security from them

One of the biggest assets organisations already have when implementing new security arrangements is often the one neglected from the beginning – the users. Historically, anything to do with IT Security was kept away from users by IT teams concerned that it was either too complex, too disruptive or required specialist skills to execute. However, this mind set needs to change and is changing –  in reality, users are already on the frontline of data security, as they are the ones creating and handling the data and therefore are best placed to understand its value to the business. Our research revealed that 60.5% of organisations focus on increasing user awareness and training following a breach, which is a positive sign. Including users expands the reach of IT security across the entire business and gets users proactively thinking about how to protect information and prevent a breach.

Such was the case with Allianz Ireland who implemented a user-driven data classification solution into their organisation in order to protect sensitive and valuable information assets and distinguish between the different types of data used by their organisation. The solution forced users to select a classification value before a document could be shared or an email sent. Within several months, they not only saw a 60% improvement in employee awareness of data security practices, but also found a significant reduction (89%) in breaches.

Changing the culture and perception of security

In order to make a real impact within an organisation, either before or after a data breach, there must be a change not only in the data security tools and policies, but a change in the security culture within the entire business. Implementing a data-centric security approach, driven by users’ knowledge of the value of the data can deliver tangible business benefits and reduce the risk of a data leak.

By Martin Sugden, Managing director of, Boldon James

BIO: Martin joined Boldon James in 1998 and has over twenty years experience in the Security Industry. He led the Management Buyout (MBO) of Boldon James backed by ISIS Equity Partners and the subsequent sale to QinetiQ. His career began with Ernst & Young as a Chartered Accountant and he has been the CFO of two LSE-listed companies, the first of which he floated. His main passion is business development and he has held significant roles in a number of blue chip UK and US companies. Martin has an honours degree in Economics and Geography from Bradford University.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}