Arm your team with understanding to minimise cyber risk

Staff are often referred to as the weakest link in cyber security… they are at the top of our list of threat actors, and whether they make errors in judgement or in haste, they tend to be well-meaning – it is, after all, human to err.

Often these errors occur because of insufficient knowledge or training – or because people are easily tricked into doing something that could cause your organisation harm.

Do we need more than trust?

These well-meaning people are the same people that access your sensitive data so that they can do their jobs and enable your organisation to continue to operate effectively. As employers, we have to trust our employees to protect our sensitive data in the hope that they will not accidentally (or in some cases intentionally) abuse the privileges we have provided.

As individuals, we would be unlikely to trust the unqualified teacher to teach our children, or the hospital orderly to operate on our nearest and dearest, no matter how well-meaning that person is. We would expect each person to have adequate training to be able to effectively carry out their particular role. Therefore, it would make no sense to trust our employees with our valuable information and systems without providing them adequate and appropriate knowledge to do so.

Understanding how to identify threats takes practice

The other consideration is that learning facts is not the same as practical experience, and understanding how to identify threats to your organisation and act appropriately takes practice – especially when they are continually evolving.

This means we need to help our staff understand how to look for those key indicators that could suggest that they should not take an email or request for information or payment of an invoice at face value. We must help our staff understand the risks they are exposed to as the custodians of our businesses, and how they can protect our organisations from harm.

Zero trust approach

Trick emails and scams are clever, and on the rise. I’ve had several in the past few days … I have not received these previously and they come out of the blue. A mobile phone call from HMRC saying that a warrant was being issued for a fraudulent claim that has been made and to immediately press 1 to prevent this. A home phone call saying that a MasterCard transaction was being paid out to a foreign payee for £600 and to press 1 if this is not authorised.

They are designed to cause uncertainty, panic, urgency, and they are designed to relate to as wide an audience as possible by being both generic and somehow personal. A zero trust approach is now becoming our default setting.

How can we help our teams?

It’s easy to catch an unsuspecting person who is busy and wants to do the right thing, leading lead them to a momentary lapse in judgement by taking advantage of both their human nature and potentially their position.

By helping our staff understand the threats out there we put them in a much better place to identify them and protect our businesses… and also protect themselves in their own personal lives. But it takes a process of raising awareness, testing them and allowing them to fail in a safe environment, then teaching them a bit more, and help them to practice so that they are confident to question things and take the time to challenge requests and emails.

How Securious can help you tackle awareness training head-on

We’ve partnered with KnowBe4, a leading supplier of security awareness and training solutions to provide you with a proven, comprehensive approach, fully managed by our team of experts. Pricing is just £35 per user per annum – click here to find out more.