CIO Straight Talk - Issue 10 - 12
It's imperative to make cybersecurity integral
to all business processes. But for cybersecurity
to be truly embedded in the daily life of the
organization and in all activities, cybersecurity
education has to touch all employees.
RAISIng eMpLOYeeS'
CYBeR pROFICIenCY
"Our top impacted areas are people, people,
people," Reyes states flatly. "The top challenge
comes down to human performance," Sheikh
agrees. "The user community is the weakest
link. Most breaches come from phishing. Once
access is provided, it's just a matter of time. I
can keep spending thousands on tools, but how
do you train?" Joe Kirk puts it another way: "All
the technology in the world won't prevent a user
from clicking on the wrong link."
So what's to be done about the people problem?
Like many companies, Entergy has implemented
fake phishing programs, followed by awareness
training "for anyone who clicks on it," Sheikh
says. Other members of the panel report similar
programs in their organizations. At Vistra
Energy, different types of phishing campaigns
are targeted periodically at 15 different types
of groups-executives, privileged access users,
compliance officers, admins, etc.
At Cisco, employees receive fake phishing
campaigns every quarter. They can go to an
internal web site (the "phish pond") to learn
more about phishing and validate any test phish.
This exercise has reduced clicks on fake phish
by two-thirds, says Martino. Those employees
that do click get immediate training and a month
later, they receive another fake phish.
Another common practice involves on-going
training programs and annual certification for all
employees. At ADP, for example, short animated
videos and interactive gamification (e.g., quizzes,
video games) work well to engage employees
12
and help with content retention, Cloutier says. Key
to such training is measurement, he adds, including
how many people take it, how much time it takes
them, and the nature of their feedback.
"You have to "grow"
[cybersecurity talent]
within your company
so they can understand
how business processes
are managed within
technology systems."
Zeeshan Sheikh
VP & CIO
Entergy Corporation
In addition to broad-based training programs,
the CISOs on our panel have developed
customized training to raise security awareness
of employees in specific type of jobs. At Cisco,
the "security ninja" program is targeted at
software developers building products and
services for Cisco's customers. They work their
way up various levels until they get the coveted
black belt. For business-related roles, special
training programs cover topics such as designing
secure business processes, regulatory issues, and
the employees' responsibilities as data stewards.
At DNB, the security coordinators mentioned
above customize a general training program to
fit their specific business area.
"When I talk to employees," says Martino, "I
communicate to them that the internet is great
but it's like being in the middle of a large city
rather than a small town's main street." Just
making them aware of the importance of backing
up their personal files is important, he says, as
18% of people never back them up and 39% only
do so when reminded.
All employees are foot soldiers in the battle with
hackers, but a team of security professionals
helps the CISO lead the charge. The trouble
is that it's hard to find people with the right
experience and expertise to fill the increasing
number of open cybersecurity positions.
Spam accounts for 65% of total email
volume; 8-10% percent global spam could
be classified as malicious.
CIO Straight Talk - Issue 10
Table of Contents for the Digital Edition of CIO Straight Talk - Issue 10
Contents
CIO Straight Talk - Issue 10 - Cover1
CIO Straight Talk - Issue 10 - Cover2
CIO Straight Talk - Issue 10 - 1
CIO Straight Talk - Issue 10 - Contents
CIO Straight Talk - Issue 10 - 3
CIO Straight Talk - Issue 10 - 4
CIO Straight Talk - Issue 10 - 5
CIO Straight Talk - Issue 10 - 6
CIO Straight Talk - Issue 10 - 7
CIO Straight Talk - Issue 10 - 8
CIO Straight Talk - Issue 10 - 9
CIO Straight Talk - Issue 10 - 10
CIO Straight Talk - Issue 10 - 11
CIO Straight Talk - Issue 10 - 12
CIO Straight Talk - Issue 10 - 13
CIO Straight Talk - Issue 10 - 14
CIO Straight Talk - Issue 10 - 15
CIO Straight Talk - Issue 10 - 16
CIO Straight Talk - Issue 10 - 17
CIO Straight Talk - Issue 10 - 17A
CIO Straight Talk - Issue 10 - 17B
CIO Straight Talk - Issue 10 - 18
CIO Straight Talk - Issue 10 - 19
CIO Straight Talk - Issue 10 - 20
CIO Straight Talk - Issue 10 - 21
CIO Straight Talk - Issue 10 - 22
CIO Straight Talk - Issue 10 - 23
CIO Straight Talk - Issue 10 - 24
CIO Straight Talk - Issue 10 - 25
CIO Straight Talk - Issue 10 - 26
CIO Straight Talk - Issue 10 - 27
CIO Straight Talk - Issue 10 - 28
CIO Straight Talk - Issue 10 - 29
CIO Straight Talk - Issue 10 - 30
CIO Straight Talk - Issue 10 - 31
CIO Straight Talk - Issue 10 - 32
CIO Straight Talk - Issue 10 - 33
CIO Straight Talk - Issue 10 - 34
CIO Straight Talk - Issue 10 - 35
CIO Straight Talk - Issue 10 - 36
CIO Straight Talk - Issue 10 - 37
CIO Straight Talk - Issue 10 - 38
CIO Straight Talk - Issue 10 - 39
CIO Straight Talk - Issue 10 - 40
CIO Straight Talk - Issue 10 - 41
CIO Straight Talk - Issue 10 - 42
CIO Straight Talk - Issue 10 - 43
CIO Straight Talk - Issue 10 - 44
CIO Straight Talk - Issue 10 - 45
CIO Straight Talk - Issue 10 - 46
CIO Straight Talk - Issue 10 - 47
CIO Straight Talk - Issue 10 - 48
CIO Straight Talk - Issue 10 - 49
CIO Straight Talk - Issue 10 - 50
CIO Straight Talk - Issue 10 - 51
CIO Straight Talk - Issue 10 - 52
CIO Straight Talk - Issue 10 - Cover4
https://magazine.straighttalkonline.com/hi_tech
https://magazine.straighttalkonline.com/issue12
https://magazine.straighttalkonline.com/assetheavy2020
https://magazine.straighttalkonline.com/lifesciencesandhealthcare2019
https://magazine.straighttalkonline.com/womenintech2
https://magazine.straighttalkonline.com/financialservices2019/
https://magazine.straighttalkonline.com/issue11
https://magazine.straighttalkonline.com/issue10
https://magazine.straighttalkonline.com/issue9
https://magazine.straighttalkonline.com/womeninit
https://magazine.straighttalkonline.com/financialservices
https://magazine.straighttalkonline.com/issue8
https://magazine.straighttalkonline.com/issue7
https://magazine.straighttalkonline.com/issue6
https://magazine.straighttalkonline.com/issue5
https://magazine.straighttalkonline.com/issue4
https://magazine.straighttalkonline.com/issue3
https://magazine.straighttalkonline.com/issue2
https://magazine.straighttalkonline.com/issue1
https://www.nxtbookmedia.com