CYBERSECURITY REVIEW8 FEB - MAY - 2023With the plethora of technology-based controls that have been brought to bear upon the would-be threat of evil doers the world over, cyber attackers have had to refine their tactics to focus on that asset which remains unsecured, the employee. Just like any other system in our organization, "we the human" handle sensitive information, we communicate with other humans in our network, and we process requests and produce output. Unlike other corporate systems though, we can't be laden with a host of endpoint detection, data loss prevention, and SIEM clients (though sometimes we're still sluggish to boot-up in the morning). These truths require us to shift our information security focus away from cyber, and delve into the realm of communications, training, marketing, and corporate culture. It turns out that combating our cyber risk now requires a soft-skills solution, a fact that many organizations have come to recognize. According to the Verizon 2021 DataBreach Investigations Report; social engineering leads the pack in causes that lead to a breach, and 85% of breaches involved a human element. With that in mind, the first question that always gets asked is... "how?". You mean to tell me that if I want to bring our risk within appetite, I'm going to have to change hearts and minds? I agree, the idea of trying to shift a corporate culture feels daunting, like trying to move a mountain with a megaphone. There are a couple of key principles to keep in mind when tackling this particular bear, and that's what I'd like to talk about today. The technical side of managing human risk involves good access controls and passwords standards, and it isn't uncommon to find INFORMATION SECURITY AWARENESS PROGRAMS SECURITY CONTROLS FOR THE MOST VULNERABLE ATTACK VECTORBy Alexander Cummings, Information Security Awareness Program Manager, SouthState BankIN MY OPINIONAlexander Cummings
<
Page 7 |
Page 9 >