ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Data Breaches

Don't blame 'stupid users' for data breaches

Andrew Donoghue ZDNet.co.uk

Published: 02 Apr 2008 14:30 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security breaches that can be traced back to the actions of one individual are not the fault of one "stupid" employee but rather a failure to educate and engage the whole workforce around the importance of good security practice, according to a leading academic.

Speaking at the Cyber Warfare 2008 event in London this week, Debi Ashenden, senior research fellow at the Defence College of Management and Technology at Cranfield University, said most companies overlook the importance of employee behaviour when it comes to securing their IT and information systems.

"Lots of organisations claim to have a culture of information security but in most cases I would say that this is not true and unfounded," she told an audience made of military and civilian IT security specialists. "We need to get end users on side. We can't ignore them anymore. We need to move away from command and control and interact with them."

IT security managers do not like the idea of empowering the end users and would prefer to be able to "lock them down" in the same way employees' PCs can be locked down, said Ashenden

Ashenden's speech made reference to several recent high-profile security breaches, including the exposure of 25 million individual's records by HM Revenue & Customs (HMRC) in November last year, and the loss of an MoD laptop containing the records of some 600,000 defence personnel.

Ashenden claimed that although breaches such as HMRC had led to a new focus on IT security, based around improving processes and technology, the incidents were down to human factors. "We need to find a way to make people streetwise and question core beliefs so they question this kind of behaviour before it's carried out," she said.

Read this

Feature
Special report: The top five internal security threats

What should an employer watch out for?

Read more +

A survey from PriceWaterhouseCoopers (PwC) released this week appears to back up Ashenden's assertions. The results show the proportion of companies that have an information security policy has quadrupled over the last eight years.

However, one of the report's authors, PwC's Chris Potter, said having a security policy alone does not magically improve security awareness among staff. "What companies are realising is that increasing security awareness is only part of the answer. The critical issue is changing the behaviour of their people."

There has been a spate of high-profile security breaches dating back to mid-2007, which has led the government watchdogs to demand action be taken against organisations and individuals who fail to safeguard data and information. In a document submitted to government in January this year, information commissioner Richard Thomas called for the Data Protection Act (DPA) to be amended to include a penalty for data controllers "knowingly or recklessly failing to comply with the principles" of the DPA.

Ashenden claimed there has to be a fundamental shift in the behaviour of senior IT security professionals towards end users and the importance of understanding social interaction within companies.

"Most information security managers didn't come into the profession to get involved in cultural change and to talk to end users. They came in because they have an interest in technology," she said. "But we have to measure values, attitudes and perceptions of end users and aggregate the information to craft cultural change."

In response to those IS professionals who suggested there are no hard quantitative approaches to the analysis of attitudes and behaviour of employees, Ashenden claimed there are recognised ways to tackle this kind of analysis of end-user behaviour that are already used in social-science disciplines.

Responding to a question about the failure of software makers to build user-friendly security systems, Ashenden agreed that approaches such as pop-up warnings in operating systems were ineffective, as users eventually become conditioned to ignore them. She also referenced a quote that claims hackers often pay more attention to the human link in the security chain than security designers do.

The PwC survey is part of the 2008 Information Security Breaches Survey created on behalf of the Department for Business, Enterprise and Regulatory Reform. The final report will be launched in London at the Infosecurity show on 22-24 April.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
5 out of 5 people found this useful


More in this Special Report

The top five internal security threats

The top five internal security threats

It's widely known that internal staff are the biggest threat to IT security, but what specifically should an employer watch out for? more

US gov't: Treat personal data 'like toxic waste'

US gov't: Treat personal data 'like toxic waste'

Computer scientists in the US have advised organisations to be extremely cautious when handling information that can be used to identify individuals more

Home Office laptop and disc 'bought on eBay'

Home Office laptop and disc 'bought on eBay'

IT repair technicians near Manchester have found an encrypted Home Office CD under the keyboard of a laptop, apparently purchased recently on eBay more

Data breaches cost an average business £1.4m

Data breaches cost an average business £1.4m

The vast majority of lost data is accidental rather than a result of any criminal activity, researchers claim more

ICO: Data-breach spate 'no worse' than normal

ICO: Data-breach spate 'no worse' than normal

The Information Commissioner's Office has said the recent surge of data-breach reports does not indicate a rise in security lapses more

PGP: Encryption alone no cure for data breaches

PGP: Encryption alone no cure for data breaches

In the fight against security breaches, PGP chief executive Phil Dunkelberger cautions that encryption by itself is not the answer more

Keeping mobile data from going walkabout

Keeping mobile data from going walkabout

Mobile email is no longer the preserve of upper management but providing access to company information on the go has its risks more

Public gets more savvy about data security

Public gets more savvy about data security

An ICO survey has found people are taking more care with their personal information, suggesting the recent spate of high-profile data breaches has had an impact more

ICO urges gov't to retain data-theft laws

ICO urges gov't to retain data-theft laws

The watchdog has warned it is vital the government resists pressure to water down laws that could jail people selling stolen personal details more

Don't blame 'stupid users' for data breaches

Don't blame 'stupid users' for data breaches

A defence researcher claims companies need to move away from the idea of command and control of their employees and get them on side when it comes to improving IT security more

Symantec, RSA call for unified data-breach law

Symantec, RSA call for unified data-breach law

At the RSA security conference the vendors argued the case for a single US federal data-breach notification law, echoing similar demands last year in the UK more

How to avoid liability for a data breach

How to avoid liability for a data breach

Data breaches can be costly not only for customers but for the business involved. Implementing certain measures, however, can limit liability more

Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

SAP ABAP-HR /Technical SAP HR Expert (HR, HCM, ABAP, ESS/MSS, Web DynPro, JAVA, ECC6, Netweaver)

Specialising in the areas of Finance and Human Capital Management (HCM/HR), their business model is designed around providing niche expertise in ...

The Head of Information Security and Privacy Incident Response

The Head of Information Security and Privacy Incident Response is a senior member of the Vulnerability Management team with primary responsibility ...

Behaviour Engineer

Experience in 3D Animation and synthesising physical human behaviour is also beneficial. My client is seeking a candidate to create and optimize ...

Sentry Posts Blog

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Google sponsors open source security p...

Google has announced it is to sponsor oCERT, an open source computer emergency response team. In a blog post on Monday, Google security engineer Will Drewry said that one of the... More

Post a comment

Indian officials accuse China of cyber...

China is actively engaged in mapping India's computer networks, according to the Times of India. China is mounting "almost daily" attacks against Indian Government computer systems,... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation