1

Here we are: 1 in 3 employees don’t understand why cybersecurity is important

Désolé, cet article est seulement disponible en Anglais, Russe et Ukrainien. Pour le confort de l’utilisateur, le contenu est affiché ci-dessous dans l’une des autres langues disponibles. Vous pouvez cliquer l’un des liens pour changer la langue du site en une autre langue disponible.

 

Even worse – only 39% say they’re ‘very likely’ to report a security incident.

 

A startling new report indicates the disconnect between employees and their company’s cybersecurity efforts.

 

Nearly one in three (30%) employees don’t think they personally play a role in maintaining their company’s cybersecurity posture, according to new research from Tessian.

 

Moreover, only 39% of employees say they’re “very likely” to report a security incident. When asked why:

– 42% of employees said they wouldn’t know if they had caused an incident in the first place, and

– 25% said they just don’t care enough about cybersecurity to mention it.

Obviously, that makes investigation and remediation even more challenging and time-consuming for security teams.

 

In fact, all IT and security leaders (99%) agreed that a strong security culture is important in maintaining a company’s cybersecurity posture. Yet, despite rating their organization’s security 8 out 10, on average, three-quarters of organizations experienced a security incident in the last 12 months.

 

According to Kim Burton, head of trust and compliance at Tessian “Everyone in an organization needs to understand how their work helps keep their coworkers and company secure. To get people better engaged with the security needs of the business, education should be specific and actionable to an individual’s work.”

 

The report suggests this could stem from a reliance on traditional training programs; 48% of security leaders say training is one the most important influences on building a positive cybersecurity posture.

But the reality is that employees aren’t engaged:

– just 28% of UK and US workers say security awareness training is engaging and

– only 36% say they’re paying full attention.

Of those who are, only half say it’s helpful, while another 50% have had a negative experience with a phishing simulation.

 

 

“It’s the security teams’ responsibility to create a culture of empathy and care, and they should back up their education with tools and procedures that make secure practices easy to integrate into people’s everyday workflows,” Burton said.

 

The generational issue

 

The report also revealed generational differences when it comes to cybersecurity culture perceptions. The youngest generation (18- 24-year-olds) is almost three times as likely to say they’ve had a negative experience with phishing simulations when compared to the oldest generation (55+).

 

In contrast, older employees are four times more likely to have a clear understanding of their company’s cybersecurity policies compared to their younger colleagues, and are five times more likely to follow those policies.

 

When it comes to risky cybersecurity practices such as reusing passwords, taking company data and opening attachments from unknown sources, younger employees are the least likely to see anything wrong with these practices.

 

Source: Tessian

Related Posts

card__image

Zero-Day Vulnerabilities: Cases about Consequences from 17 members of Forbes Technology Council

Désolé, cet article est seulement disponible en Anglais et Ukrainien. Pour le confort de l’utilisateur, le contenu est affiché ci-dessous dans l’une des autres langues disponibles. Vous pouvez cliquer l’un des liens pour changer la langue du site en une autre langue disponible. Zero-day vulnerabilities are flaws or weaknesses in software or an operating system […]

card__image

100% security — mission impossible?

Désolé, cet article est seulement disponible en Anglais et Ukrainien. Pour le confort de l’utilisateur, le contenu est affiché ci-dessous dans l’une des autres langues disponibles. Vous pouvez cliquer l’un des liens pour changer la langue du site en une autre langue disponible. At some point CIOs and CISOs have inevitably to provide a smart […]

card__image

4 key mistakes CISO make at board meetings

Désolé, cet article est seulement disponible en Anglais et Ukrainien. Pour le confort de l’utilisateur, le contenu est affiché ci-dessous dans l’une des autres langues disponibles. Vous pouvez cliquer l’un des liens pour changer la langue du site en une autre langue disponible. Presenting to the board is a challenging opportunity. CIOs and CISOs would […]

Laisser un commentaire

Votre adresse e-mail ne sera pas publiée. Les champs obligatoires sont indiqués avec *