Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Security Culture Predictions 2016
Articles

Security Culture Predictions 2016

ISBuzz TeamBy ISBuzz TeamJanuary 1, 2016Updated:July 4, 20246 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Google TAG Alerts Of ARCHIPELAGO Cyberattacks Linked To North Korea
Google TAG Alerts Of ARCHIPELAGO Cyberattacks Linked To North Korea
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

2015 was the year the tipping point was reached with regard to public awareness of hacking, data breaches and cybercrime. Hardly a week seemed to go by without another high-profile breach hitting our TV screens. At times it felt like a coming of age: CEO Dido Harding confessed on camera to not knowing whether or not stolen customer data was encrypted, and the Ashley Madison hack taught us that our ‘digital exhaust’ just got dirtier.

Whether it’s as a consumer, end-user, or potential ‘insider-threat’, the human factor moved centre stage in 2015, with seven out of the top ten vulnerabilities being identified at end-user level. We predict that every security professional will be dealing with security culture and behavioural change in one form or another throughout the coming twelve months.

Here are our thoughts on the top trends to look out for:

  1. The role of the Security Chief will include risk and culture – No longer just a tech lead, the security professional is now both a business risk leader and security culture advocate. What we have discovered in all the organisations that we have worked with over the past year, is that the key to the success of a positive security culture comes down to knowing who the people are, in your business, who share your passion for positive security. Very often these ‘unsung heroes’ of security are fulfilling job roles unconnected with the official security structure but they are, for example, informally educating people in their department about security, or talking about the breaches in the news, or passing on good practice tips. Finding these allies is a key strategic aim which every security professional needs to have high on his/her to do list, because they can help to start the conversations that grow security culture across the organisation.
  2. Process, process, process will become a fundamental aspect of your security strategy – Bruce Schneier said it back in 2000 and now it’s more of an issue than ever. Technology has been demonstrated to be, at best, a partial defence against data breaches, but processes that recognise the instability of any product are critical to effective protection. The 2015 Global Threat Intelligence Report (NTT Com Security) discovered that 76% of vulnerabilities identified had been known of for more than two years and 9% of vulnerabilities were over ten years old. Constant housekeeping requires more than a yearly audit; it needs an engaged security culture committed to an ongoing processual evolution in the service of protecting valuable data. You need people who care about security across the business to do that.
  3. Phishing/Data Harvesting will grow in sophistication and catch out even more people – We can all agree on this one: phishing ain’t going away! What’s different about the phishing threat in 2016 is that the personal data available for harvesting is going to grow (thanks to the IoT market) and the nature of that data will become more intrusive, and therefore more valuable. The black market rate for data is soaring, thanks to the ever-more inventive uses it’s being put to in the construction of social engineering or spear phishing attacks, and that means that attacks on end-users will become increasingly sophisticated. It’s time to recognise that the development of good security behaviours is as important to productivity as speed and efficiency – and that means ditching the ‘carrot and stick’ approach in favour of collaboration across the organisation in pursuit of long-term goals.
  4. The ‘Insider Threat’ continues to haunt businesses – There’s been some confusion about this term over the past year;  what was once the term used to define a rogue, grudge-bearing employee has grown incrementally to include anyone with access to potentially valuable data. Whilst not being a particularly helpful shift, this redefinition of the ‘insider threat’ demonstrates awareness that the more valuable data becomes, the more of a temptation it becomes for low-paid workers to ‘sell’ access to it. Rather than shooting the starting pistol on a witch-hunt, however, we would urge businesses to invest in the development of a cohesive security culture, built on conversation, and nurtured by security advocates across the organisation. A security culture is built on values such as trust, pride in one’s work, defence of the common good; it encourages the very best instincts in employees and provides an organisation-wide surveillance team who are rather more user-friendly than the tech products currently being touted to do the job.
  5. Internet of Things and Digital Exhaust will render the ‘one policy fits all’ approach defunct – As the market for IoT products grows, so will the need to regulate and manage the range of operating systems carrying our data. The McAfee Labs 2016 Threat Predictions report suggests that we are entering an era in which our personal digital data will include: frequently visited locations, what we eat, watch, listen to, our weight, blood pressure, prescriptions, sleeping habits, daily schedule, and exercise routine.  The democratisation of mobile communications has been difficult enough to manage to date, but the most recent reports predict that the number of individual operating devices will grow incrementally, producing more and more ‘digital exhaust’. The ‘one policy fits all’ approach is no longer operable in this scenario and organisations will find it difficult to enforce the use of company devices. One possibility for its replacement is a cultural security working practices document which is developed collaboratively and recognises the values and responsibilities of employees across all their devices.

[su_box title=”About Sarah Janes” style=”noise” box_color=”#336588″]Sarah JanesSarah Janes is a managing director at Layer 8 Ltd. Sarah have spent most of her working life in the field of security awareness, communications and culture change. Having started her career running security awareness at BT, and then moving on to deliver award-winning behavioural change programmes to FTSE 100 clients at The Security Company, She understand issues to do with the ‘human factor’ in security from both sides of the fence. Over that time she’ve see priorities shift: whereas it used to be the case that security communications were simply for compliance purposes, now effective communications need to change behaviour. Merely ticking the compliance box is no longer an option, as businesses of all sizes tell us loud and clear.[/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}