If you’re in the habit of checking the news online you will have noticed that almost daily now there are reports of data breaches by attackers. Cyber security headlines are all too frequent and alert us to the skill and persistence of hackers.
Many organisations still rely on traditional security controls in the form of technology such as anti-virus software and firewalls, etc. to protect their critical assets but it is now clear that this is not enough. The increasing importance of employee security awareness is often overlooked with companies providing little or no basic awareness training.
Personnel and processes are often disregarded when it comes to improving security, partly because the security risk they pose to an organisation is difficult to measure and track.
These days, this a crucial issue with cyber security, but businesses that (very sensibly) put in place IT software security often struggle to get senior management to address a risk that they haven’t been able to quantify, or even prove exists.
The problem is that as the technical, on-line security of organisations increases, attackers are looking instead to a much weaker area: employees.