ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

SME Toolkit in association with http://ad.doubleclick.net/clk;205413468;14699245;m?http://adfarm.mediaplex.com/ad/ck/2397-58840-22058-14

Ending the epidemic of ignorance

Jonathan Yarden

Published: 18 May 2005 13:15 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Because of my experience, groups frequently ask me to be a guest speaker about security issues. In most cases, however, the majority of the audience is already painfully aware of the immense challenges presented by Internet and information security.

That means that many of my presentations amount to nothing more than "preaching to the choir" about current security issues. And while I enjoy participating, reminding people to click the Windows Update menu item in Internet Explorer each week isn't even a mildly interesting topic for most IT professionals, and neither is my suggestion to use free antivirus software.

I've said it before, and I'll say it again: The horrible state of Internet security is due to an epidemic of ignorance. But companies can't just sit back and accept this lack of knowledge. Let's look at some simple steps your organisation can take to dispel this ignorance.

Ignorance is not bliss
One of the most prevalent problems with security is that most users are completely unaware of the risks of insecurity. And this problem will not fix itself.

It's a simple fact that most people who use a computer have little understanding of — nor are they interested in learning — the details of how their computer works. In fact, I would argue that the only times most people become interested about the operation of their computer system is when it stops working.

Developing end-user education opportunities in the corporate environment — and encouraging employees to attend them — is one way for companies to diminish computer illiteracy. Providing incentives for attending classes and for keeping a computer updated and virus-free are additional options to consider.

Helping those who help themselves
Those of us who are computer-savvy enough to install and update antivirus software and click Windows Update each week aren't doing enough to help ourselves. Even if they're not in an official support position, I bet the majority of readers have found themselves helping co-workers, family, and friends fix something on their computer or helping them recover from a virus or worm.

The old saying about teaching a man to fish has never been more valid. Helping one person and telling him or her to pass along the knowledge you shared does more in the long run to improve Internet security overall.

Consider setting up an informal mentoring program to encourage more computer-savvy employees to share their knowledge with their coworkers. Setting up a bulletin board for posting tips and hosting a lunchtime training session about security are also low-maintenance ways your organisation can promote security awareness.

Focus on your users
We are all aware of the current security problems wreaking havoc. However, while IT pros often enjoy discussing the various security challenges, these conversations do nothing to educate the average user.

The average user uses Microsoft Windows, and Windows is where the battle against insecurity and ignorance needs to start. The sheer extent of the threat to the Internet from insecure computer systems using Windows justifies taking the time to educate as many people as possible about how to secure their systems.

Jonathan Yarden is the senior UNIX system administrator, network security manager, and senior software architect for a regional ISP.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
40 out of 80 people found this useful


Full Talkback thread

1 comment

  1. I couldn't disagree more with the opening sentence... Scott Marlowe

Related Jobs

Support Engineer

Support and maintenance of the CSIS domain Software including: UNIX and Microsoft OS, SAN, Exchange, SQL and Antivirus software. Support Engineer - ...

SAP HR & LMS Super User - Aberdeen - 35,000

LMS areas Participate & lead as necessary regional training workshops for global HR teams in relation to all new SAP processes developed Identify & ...

Hardware Break/Fix Engineer

ESG provides hardware support in the form of COTS Integration and Installation, and Break/Fix services to EDS Defence Projects based mainly in Hook. ...

Vista Upgrade Blog

Microsoft's pre-modern message puts a...

Over at ZDNet.com, Ed Bott reports a first sighting of Microsoft's eagerly awaited $300 million ad campaign. Already the cause of much speculation, the consensus is that this will be... More

7 comments

A $40 CONSUMER-class router has create...

Believe it or not I don't work in IT, haven't for 7 years. Yes I work with Microsoft's Windows XP Embedded and as a result I have to know a lot about the OS, the kernal, Win API calls... More

Post a comment

Sick Puppy Redo

I generally follow a dispassionate investigative process when trying to discern what happened when a project goes bad. Although its a low priority item, it gets done simply because... More

Post a comment

Discussions

David Long David Long

Defragging: Merits?

Thursday 24 July 2008, 10:30 AM

12 posts