Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - The Biggest Threat To Your Info Security Is Sitting In Your Office Right Now
Articles

The Biggest Threat To Your Info Security Is Sitting In Your Office Right Now

ISBuzz TeamBy ISBuzz TeamMarch 24, 20146 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Executive Order Limiting Usage Of Commercial Spyware Signed
Executive Order Limiting Usage Of Commercial Spyware Signed
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

At Certification Europe we certify lots of organisations for information security management systems. It is one of our main strengths as an organisation, it’s what we do, and we are recognised internationally as the best there is. This might seem like a bit of humble boast but could you imagine the reputational damage that we as an organisation would suffer if we ever allowed our clients information to be breached?

Don’t worry if you can’t imagine. Cintas document management conducted a survey in October last year and the results are scary, 66% of adults would not return to a business where their information was breached.

– 55% would change their bank.
– 46% would change their insurances companies.
– 40% would change their medical provider.
– 38% would not donate to a charity again.

So you can imagine how scared I was when we started getting spam messages to our Twitter account. At first we were getting weird links direct messaged from accounts that we followed, they looked fairly suspect so I didn’t have any fears about our social media team clicking on them.

Then the malware got creative!

“Are you the 3rd from the left in this shot from a couple years ago?”

Sent as a tweet from someone we follow on twitter. It is easy to see why people might fall for it. Luckily our marketing team has been trained in recognising threats, specifically cyber threats and malware.

This leads me onto the subject of the biggest threat to your information’s security. It’s the person sitting beside you, maybe not directly beside you, they might be beside the photocopier, or next to the water cooler, or in the hot desk.

The fact is that the dangers posed by hackers and malware pale into insignificance beside the biggest threat to your information’s security, and directly your businesses future. Staff that have not been trained to handle data properly are the number one source of data breaches.

There have been countless studies conducted by organisations such as Ponemon, Symantec and Compuware that have found that human error causes most data breaches. In fact less than 1% of corporate data losses were caused by hackers.

If you are still not convinced in why training your staff is vitally important you need look no further than the fines associated with data breaches.

In June 2012 Islington Council in the UK responded to a freedom of information request by supplying 3 excel sheets with pivot tables the fulfilled the request. However they also gave a copy of the raw data from which these pivot tables were derived. This data table was hidden from view but still accessible to someone with training.

These data sets contained the personal information of 2375 council tenants or people who had applied for council housing. Some of the more sensitive data breached was ethnicity and gender of local residents the council had rehoused, details about residents history of mental health issues or instances of reported domestic abuse. These spread sheets were hosted on a UK based site https://www.whatdotheyknow.com for approximately 3 weeks until July 2012 before the breach was reported to the Information Commissioner’s Office (ICO).

Islington council conducted their own internal investigation and they concluded that lack of training, specifically around the preparation of data for public release was to blame. They could not however hold any staff member accountable because they had not trained them. There was no standard to bench mark against and there was no ability to recognise or correct the error.

Head of Enforcement at the ICO, Stephen Eckersley fined the council £70,000 and had this to say in his commentary

“Councils are trusted with sensitive personal information, and residents are right to expect it to be handled in a proper way.

Unfortunately, in this case that did not happen, and Islington Council must now explain to residents how it will stop these mistakes being repeated.”

The importance of training is even enshrined in the relevant data protection acts. Principle 7 of the UK act calls for “robust policies and procedures”, “reliable, well-trained staff” that are “ready to respond to any breach of security swiftly and effectively.”

The need for “more effective and appropriate training” is reflected in too many judgements for an activity that is largely preventable. In the UK the ICO hands down harsher fines and punishment because of wilful neglect of best practise. Failing to train staff on the dangers of mishandling data is inviting trouble to your business’s door and this is something every organisation could do without.

Michael Brophy | www.certificationeurope.com | @CertEurope_

Michael Brophy

Professional Biography:

Michael Brophy is Founder and CEO of Certification Europe which was founded in 2001 with Head Quarters in Dublin, Ireland. In 2012 Certification Europe Limited opened their London operation which, along with offices in Belfast, Turkey, Japan and Italy, is a group of accredited certification bodies which provides ISO Certification and Inspection services to organisations globally.

Michael is a graduate of the University of Ulster and the Universidad de Zaragoza (Spain), with a Master in European Policy and Regulation at Lancaster University, and is one of Ireland’s leading authorities on standardisation.  Michael has a wealth of experience in Information Security and Business Continuity Management Systems implementation for Government, military and various business sectors (pharmaceutical, telco, financial, IT and security printing sectors).

Michael has particular expertise in the field of electronic signatures; developing national legislation and national regulatory bodies to govern the use and legal basis for electronic signatures. He has previously advised on the establishment of standards at a national and international level, and he would be viewed as one of Ireland’s leading authorities on standardisation and has served on various EU Commission committees.

Certification Europe is the only Irish accredited certification body operating in the field of Business Continuity standards, it was the first accredited industry player in Ireland to offer Information Security and IT Service Management Systems assurance schemes, and it is a world leader in Energy Management System certification.

Michael is also Chair of the Association of Accredited Certification Bodies (AACB).

Other articles from Certification Europe include:
–
Chasing Shadow IT
– Humans are the weakest part of your information security system
– A Chain Is Only As Strong As Its Weakest Link

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 404

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}