Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Rules Are Made For Fools
Articles

Rules Are Made For Fools

ISBuzz TeamBy ISBuzz TeamOctober 13, 20144 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
security
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

I surprised my son last week. He was in the proverbial doghouse for dropping the family laptop. Now the crazed crystal garden that was growing across the screen with cracks like scale San Andreas models could only mean one thing…something expensive was going to happen. Lessons are important when given a personal edge, and there was a mixture of compassion and awakened responsibility when we made the decision that he’d have to fund the repair from his savings he’d accumulated over the last nine months (mainly due to birthday funds sent from remote relatives), and the new bike would as a result have to go on hold. Cruel to be kind. Perhaps. Where I surprised him was this…I told him that he was now the member of the family I’d trust most with the laptop. He was speechless. But what was nice was the beam that shone from his face as he guessed correctly why I was awarding him this new level of trust. He had vaguely known about being careful with electronic devices prior to that incident, but like the labouring minister in the pulpit, it always seemed like the real message had been for the person sitting next to him. Until tragedy had struck. Now he knew the consequences of carelessness.

Free Download: Is An Outright Ban On Workplace Social Networking A Good Idea?

Now of course we can’t wait for everyone to have their Damascene moment of tragedy and revelation. It’s no good bombarding people with a constant stream of scary messages. The recipients could easily become desensitised to it all. By the time you get to Friday the 13th: Part IV, the gore is more comedic than shocking. And it’s the same with security.

Banks are driven by regulation. OK. Sometimes it’s about working around the regulation, and we see where that got us. But on the whole it’s about following a whole lot of rules. Sometimes you may get away with it, but when you don’t, the effect can be catastrophic. So it is with security. Every business has explicit regulations of compliance to contend with – accounting rules, caring for personal information about customers and employees, and so on. We want to get the widgets off the production line, get the service staff out to the clients, and keep track of the invoices and receipts. Don’t hang over your staff like the proverbial sword. After all, you won’t have time, and they will soon be immunised to your ever-watchful gaze. At the same time, don’t expect everyone from the switchboard to the board room will become experts on all threats to the business and the regulatory environment.

What you need to do is make small inoculations of knowledge and know-how. Instil a bit of pride. Make the recipients beam about their attention to data protection, appropriate use of social media sites, and protection of tangible security measures such as passwords, ID cards, and padlocks on the filing cabinets. Make them active defenders in the battle with unknown assailants who could easily wipe their jobs off the map from a warehouse in Belarus.

Security should be a natural part of the business culture tempered by the level of threat. We don’t all have to protect a power station, but we do need to protect our jobs without security taking over and leaving us either like the proverbial deer in the headlights. If you want to get compliance as much a business mainstay as collecting a wage slip, you need to give your staff easy steps to succeed in. Just as they edge their way day-by-day to the end of the month, and just as the salary payments are a cycle, so too are those messages of how to make information security a norm in your business. Repeat them in small engaging eddies of activity with ways for staff to be rewarded for good behaviour as well as understanding that there has to be action (i.e. specialized training) for repeat offenders.

In the meantime, new laptop screen ordered. Waiting for the bill. Lesson learnt. But no doubt small, kind reminders will be still be needed as my son grows up.

About Bob’s Business

Bob's_BusinessBob’s Business™ was originally created through collaboration between the Mid Yorkshire Chamber of Commerce and Industry (MYCCI) and the Department for Business Innovation and Skills (BIS). Bob’s Business™ was developed as a tool to raise awareness of Information Security related issues in Small and Medium Enterprises (SMEs).

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}