Security is everyone’s responsibility
End users are your first line of defense for your network. After all, you can spend millions on technology, but if you can’t protect against a simple phishing email, all of your preparations will have been for nothing.
Talking to end users about security can be challenging, but it is doable and necessary. I recommend a three-pronged approach, starting with simple awareness: educating workers about the security challenges they are likely to face. You must be able to clearly communicate to your entire workforce, both tech-savvy and not, about appropriate security measures and emerging threats.
From there, you want to encourage ownership: showing workers that they too have a stake in the game. Security is everyone’s responsibility, and implementing robust QA measures within your organization can help keep everybody on track. Finally, empowerment: give users the tools they need to protect themselves and the company. Here, it’s incredibly important to have a strong training and education program to teach users how to effectively use the technology and tools that they are given to report issues. Ultimately, they should understand that they are the first line of defense you have.
Make no mistake: end-user security is a major challenge. Human error being what it is, someone is likely to make a mistake, especially as attacks get more complex and deceptive. There’s a reason that phishing and social engineering are as prevalent as they are — they work. But while you will never be able to fully eliminate human error, a strong end-user training and education program is still an incredible boon to your defenses, and should be part of a larger plan to not only limit potential points of attack, but to mitigate the damage if and when an attack occurs.
So when you’re making budgetary decisions on security, ask yourself one simple question: Are you investing enough in the workers who are on the front lines defending your network every single day?
Article written by David Levine, Vice President of Information Security & CISO for Ricoh USA, Inc.