Story image

Why you should let employees step forward in fight against cybercrime

07 Aug 2017

Employees may be one of the biggest security risks, but also an organisation’s major strengths.  Many firms don’t realise that employees can help mitigate risk.

Familiar names such as CryptoLocker, DDoS, botnet attacks and ransomware are now commonplace in the common world. Manuja Wijesekera, pre-sales solutions architect - Fortinet, Wavelink, says it’s about taking a multi-dimensional approach to protecting organisations.

“Given the explosion of hacking related security outbreaks in the past couple of years and the damage it can do to organisations, it is becoming more important than ever to remember that no matter what technology or security measure is in place, more often than not employees are the first line of defence,” Wijesekera explains.

He says risks can come in the form of mistakes, being unable to identify a suspicious link or email, connecting unsecure devices to the network, or even insider threats, this should all be considered when coming up with a mitigation strategy.

 “Employee mistakes are a common cause for security breaches and hackers are using the emotional aspect when trying to entice us to click on a link or open an infected file, hence the need for organisations to foster an environment where an employee can ask questions without being reprimanded or ask for help if they think they’ve made a mistake that might have put sensitive data at risk.” 

He says that organisations should make employee engagement as part of their workplace culture, from the onboarding and induction process, as well as regular exercises and awareness campaigns throughout the year. Those in charge of security should also be certified.

That may not be so easy for small- and medium-size businesses. They don’t have the dedicated resources, and are ‘setting themselves up for a breach’.

“The other issue is that many smaller organisations are not willing to invest at all until they have suffered a breach, which is often too late. Their network may even have already been penetrated without them knowing it because they don’t have the systems in place to track it,” Wijesekera explains.

He says that it’s less of an issue because security involves CEOs and other high-level executives, especially when they are being held accountable for protecting sensitive information.

“Ultimately, all organisations need to look at making security part of their overall culture, and move away from the notion that having a single security device at the edge will make them secure. They should look for solutions and partners that can offer a fabric of security technologies with the importance given to technologies that are able to share intelligence. They also need to have a good governance program in place to maintain and monitor security in real time and an awareness program that includes all employees,” Wijesekera concludes.

Cloud application attacks in Q1 up by 65% - Proofpoint
Proofpoint found that the education sector was the most targeted of both brute-force and sophisticated phishing attempts.
Singapore firm to launch borderless open data sharing platform
Singapore-based Ocean Protocol, a decentralised data exchange that promotes data sharing, has revealed details of what could be the kickstart to a global and borderless data economy.
Huawei picks up accolades for software-defined camera ecosystem
"The company's software defined capabilities enable it to future-proof its camera ecosystem and greatly lower the total cost of ownership (TCO), as its single camera system is applicable to a variety of application use cases."
Barracuda expands MSP security offerings with RMM acquisition
Managed Workplace delivers an RMM platform with security tools and services, such as site security assessments, Office 365 account management, and integrated third-party antivirus.
Flashpoint: APAC companies must factor geopolitics in cyber strategies
The diverse geopolitical and economic interests of the states in the region play a significant role in driving and shaping cyber threat activity against entities operating in APAC.
Expert offers password tips to aid a stress-free sleep
For many cybersecurity professionals, the worries of the day often crawl into night-time routines - LogMeIn says better password practices can help.
SolarWinds extends database anomaly detection
As organisations continue their transition from purely on-premises operations into both private and public cloud infrastructures, adapting their IT monitoring and management capabilities can pose a significant challenge.
Adura launches new SOC and MSP in Singapore
The new SOC focuses on the needs of businesses to gain insight into their organization’s security posture and increase their ability to react promptly.