Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - IT Security: How To Make People Listen And Take Action To Protect Your Organization
Articles

IT Security: How To Make People Listen And Take Action To Protect Your Organization

ISBuzz TeamBy ISBuzz TeamAugust 29, 20176 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Is IT security getting the attention it deserves in your organization? With the rise of remote access and cloud-based services, IT security has become more important than ever before. Everybody’s online and we all want to access our work anywhere, anytime. The truth is, IT departments just can’t control all actions in the digital world anymore. In the following editorial, IT professional Mark Herrewijnen speaks about how you can make sure everybody does their part to keep your organization and its data safe.

What’s so important about security awareness?

IT departments always do everything in their power to keep the IT infrastructure safe from potential threats. They try to limit the network and can keep a close eye on it, but you’ll never be 100 percent secure, 100 percent of the time. You can also invest a lot of time and money into training other employees in exact procedures and checklist for using the network and dealing with threats, but that doesn’t mean that they won’t make mistakes.

What you really need to keep your digital environment safe is people who are vigilant and able to recognize threats. In other words, you need to make sure employees are aware of IT security risks and willing to do their part. This doesn’t mean that all employees need to know exactly how to resolve these problems. They simply need to be aware that threats may occur and that they should notify IT if they come across risky situations. So awareness is a simple step towards a safer digital infrastructure.

If I work in IT, how can I get security awareness on the agenda in my organization?

There are basically two ways to go about getting IT security awareness on the agenda. The best option is to promote security awareness with managerial staff, starting with your own IT manager. If they’re convinced you’re on to something here, it’s much easier to get them to participate in an awareness program. Point out the benefits to the business. Having excellent IT security policies can make your company very attractive to potential customers, and being tech-savvy means you’re keeping up with the times.

The path you want to avoid is one where security awareness is triggered by something going horribly wrong. It’ll get the issue on the agenda, but most likely other departments will simply say “IT, this is your area right? Can you go and fix it?” That’s not the scenario you want. First of all, this approach gives little opportunity for preventive measures. Since other employees don’t have the tools to recognize dangerous situations, a lot of damage can be done before anybody realizes what’s going on. Besides that, fixing major security issues takes a lot of time and effort that could be spent more efficiently. There will always be incidents for IT to solve, but making people aware and empowering them to avoid dangerous situations can save a lot of time and money.

At TOPdesk, we as a department decided not to wait for big problems, so we started initiatives to inform our colleagues about IT security. This establishes a kind of mutual trust between us and other employees. They trust that we provide the right information and that what we ask of them is actually relevant. And we trust that they keep an eye out, don’t take unnecessary risks and inform us if they have any problems.

And how do I get all my colleagues on board?

If IT security awareness isn’t getting the priority it deserves, point out the potential consequences of bad security. Major data leaks are incredibly damaging to the company’s reputation, because customers need to be able to trust you with their data. If you end up on a list of companies with security issues, the financial department is going to notice it in turnover. So if you want to improve attitudes towards IT security awareness, you need to talk about the scary stuff too. But be realistic. You could go on a spending spree and get the best security money can buy, but what you need is the right balance. The important thing is to reduce risks to an acceptable, manageable level. Basic awareness among the rest of the staff is often a big step in the right direction.

Nobody wants to be responsible for damaging the company’s reputation because they were careless with data, and nobody wants to be forced to call their customers because they left a laptop with important information in a taxi. People will still make mistakes, but with this approach we’ve noticed people are more likely to come to us right away. And they know we won’t be angry. We may say we’re a bit disappointed, but even that we don’t really mean. Nobody’s perfect, people forget things. We can manage risks like that as long as everybody’s honest about them.

Once I have the organization’s support for our IT security awareness goals, what’s the best way to get there?

The right security awareness strategy is different for every company. If you want to keep things informal, you can provide short training sessions and present information in ways that are fun and light-hearted, but still get the message across so people will remember. It’s definitely a good idea to provide training to all new employees in their first few weeks on the job. But there are other little things you can do, such as putting up a simple, attractive poster with the basics so people are reminded of them regularly. Sending the occasional email to remind people to be vigilant can also be very effective, but keep it short and to-the-point. Essentially, do what’s needed to keep people aware, but don’t distract and annoy them with a constant flow of information.

How can I see if my approach is paying off?

People tend to think that if there are fewer incidents, their approach towards IT security awareness is working. But we’re noticing something very different. If there are no incidents, that doesn’t guarantee that nothing is going wrong. There could be other reasons why the IT department doesn’t hear about problems. Perhaps people are just hesitant to admit they made a mistake.

Or, if security awareness isn’t high on the agenda, many employees may not even notice security risks. Since we made a point of creating awareness for IT security, we’ve noticed that people have started coming to us more with questions about various situations. This seems like a lot of extra work, but it’s actually what we wanted. We’d rather get ten false alarms than miss one high-risk threat. The fact that people come to us means that although they don’t know exactly how to handle the situation, they identified a risk and trust the IT department to make sure things don’t get out of control. If everybody is aware of threats and knows who to go to if they encounter them, you don’t need to train everybody to solve every security issue. You just need to make sure the risks don’t go unnoticed.

[su_box title=”About Nancy Van Elsacker Louisnord” style=”noise” box_color=”#336588″][short_info id=’103274′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The Real Cost of Inconsistent Third-Party Access

December 18, 20255 Mins Read

What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

August 7, 20256 Mins Read

The Evolving Importance of Identity Governance in FinTech

July 10, 20258 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}