Security Magazine logo
  • Sign In
  • Create Account
  • Sign Out
  • My Account
  • NEWS
  • MANAGEMENT
  • PHYSICAL
  • CYBER
  • BLOG
  • COLUMNS
  • EXCLUSIVES
  • SECTORS
  • EVENTS
  • MEDIA
  • MORE
  • EMAG
  • SIGN UP!
cart
facebook twitter linkedin youtube
  • NEWS
  • Security Newswire
  • Technologies & Solutions
  • MANAGEMENT
  • Leadership Management
  • Enterprise Services
  • Security Education & Training
  • Logical Security
  • Security & Business Resilience
  • Profiles in Excellence
  • PHYSICAL
  • Access Management
  • Fire & Life Safety
  • Identity Management
  • Physical Security
  • Video Surveillance
  • Case Studies (Physical)
  • CYBER
  • Cybersecurity News
  • More
  • COLUMNS
  • Cyber Tactics
  • Leadership & Management
  • Security Talk
  • Career Intelligence
  • Leader to Leader
  • Cybersecurity Education & Training
  • EXCLUSIVES
  • Annual Guarding Report
  • Most Influential People in Security
  • The Security Benchmark Report
  • The Security Leadership Issue
  • Top Guard and Security Officer Companies
  • Top Cybersecurity Leaders
  • Women in Security
  • SECTORS
  • Arenas / Stadiums / Leagues / Entertainment
  • Banking/Finance/Insurance
  • Construction, Real Estate, Property Management
  • Education: K-12
  • Education: University
  • Government: Federal, State and Local
  • Hospitality & Casinos
  • Hospitals & Medical Centers
  • Infrastructure:Electric,Gas & Water
  • Ports: Sea, Land, & Air
  • Retail/Restaurants/Convenience
  • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
  • Industry Events
  • Webinars
  • Solutions by Sector
  • Security 500 Conference
  • MEDIA
  • Videos
  • Podcasts
  • Polls
  • Photo Galleries
  • Videos
  • Cybersecurity & Geopolitical Discussion
  • Ask Me Anything (AMA) Series
  • MORE
  • Call for Entries
  • Classifieds & Job Listings
  • Continuing Education
  • Newsletter
  • Sponsor Insights
  • Store
  • White Papers
  • EMAG
  • eMagazine
  • This Month's Content
  • Advertise
Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
Security Education & TrainingCybersecurity News

Educating Employees to Build Better Cyber Security

By Ron Woerner
Education feature image
December 1, 2012

To err is human, to prevent err is IT info-security’s job.

Dealing with the weakest link in the IT security chain – people – has its challenges. But they’re not exclusively or even necessarily technical ones. No info-security team is going to neglect the basics of installing spam filters, firewalls, user access controls and all the other accoutrements it has at its disposal to protect corporate networks and company data.

Info-security groups always have been good at putting in place the technology speed bumps that remind employees to slow down. Those protections sure come in handy when those “moments of mindlessness” take over. That isn’t meant as an insult. It’s just a statement of the fact that everyone, at one time or another, stops thinking, and that’s when bad things can happen that put the organization or its people at risk. Those moments occur in our daily lives – like when we realize we’re not sure what route we just took to the supermarket parking lot – so it shouldn’t be a surprise that it happens in our work lives, too.

Many info-security leaders and their teams need to focus more on creating an environment where the users themselves take greater responsibility for security in those “moments of mindfulness” that characterize most employees’ working days. IT security must empower their co-workers with the information they need to stay safe, encourage their questions and even their criticism, and connect with them on the human level to make the path to a secure workplace an easier one to walk.

 

Spread the Security Word

There are reasons why it’s challenging to help colleagues become stronger links in the IT security chain. One of them is that creating a workplace of universal participation in security requires conducting an active and unending awareness campaign. Many IT and security leaders have heard before that they need to talk up security, and many of them think they’re doing just that with occasional email reminders about things like not giving out sensitive information to strangers. These items are important yet only part of the solution.

Security needs to promote a security mindset amongst all employees to reduce the “weakest link” factor. When it comes to security awareness, you want to market it to your employees as aggressively as a fast-food franchise going after the toy-hungry kid demographic. You’ve got to make them want security as much as you do – or at least want it enough to change any risky practices they might engage in.

Crafting a stronger security chain starts with building a stronger communication chain with them. This isn’t an area that most info-security people know much about, though, because much of relates to employing some marketing and advertising savvy. And marketing and advertising classes don’t usually go hand-in-hand with a Master of Information Science (MIS) or computer science degree. Security teams may think people will be annoyed by hearing too many messages on the same topic too many times, but marketers and advertisers know that people need to hear things five to nine times before they sink in.

However, what marketers and advertisers also know is that the human species likes variety, entertainment and connection. There are plenty of ways info-security can play to those innate desires, thanks to the multimedia- and socially-rich Web world we live in today.

Many companies are starting their own Facebook-like social and collaborative ecosystems for business purposes, for example. There’s no reason why info-security can’t get involved with those initiatives, using these environments as another forum for getting its messages across.

Leveraging corporate video channels or even posting some clips up on YouTube that employees can be invited to view can be another positive step that drives positive employee behavior. Just make sure it’s not a dry and long security walk-through video, and make sure that’s clear in the invite so that people actually check it out.

Perhaps, for example, present a 3-minute video clip with the top three vulnerability findings of a recent security survey and quick tips about how to avoid falling into each trap. Work with HR to present the videos at employee meetings as well.

Don’t forget other real-world possibilities, too. Loose lips that could have sunk ships during WWII were sealed because of a widely distributed poster cautioning against being a blabbermouth. It doesn’t cost anything to make up a few flyers to post near coffee machines, bathrooms, or conference rooms with similarly pithy “stay-safe” tips. The military calls it OpSec (Operations Security), and it’s just as important for businesses.

 

Invite Scrutiny

In addition to making key points about ensuring IT security in as many ways as possible, another to-do item is to make it easy for employees to get answers to security questions right when they have them. That isn’t usually the result when the road to information requires them to search for and read through online documents on the corporate intranet.

Internal social networks, on the other hand, also can be a very efficient answer here, so put them to work in that way, too. Also, refresh IT security’s presence on the corporate website so that it takes fewer clicks for employees to get the results they want.

In addition to inviting general security questions from co-workers, employees should be encouraged even to question the info-security team’s operations if they see reason to: How effective a security practice is; whether more security efforts are needed in a particular area; or if something has changed in the environment that they should be aware of. That’s just part and parcel of making everyone feel they are involved in security, as they should be.

Encouraging workers to be probing about events that seem even a little unusual takes on even greater urgency, given how great a threat social-engineering attacks present to organizations.

The Social Engineering Capture the Flag (CTF) contest run at Defcon every year makes the threat plain: Contestants spend just half an hour conducting online research about the 15 companies that agree to participate, and then half an hour on the phone with an employee of each organization asking questions in the hope of eliciting private information. Every year, 14 or even all 15 of the companies are considered breached because of the information leaked by their employees.

The reason social engineering hacks are so successful is that most people like to be helpful, and so they’re responsive to a caller who seems friendly and has just enough data to sound legit. I myself have learned not to be surprised at how much information my students are able to get from strangers when I ask them to do a little experiment in elicitation at their local hangout: Just asking someone over a beer what they do for a living can open the floodgates.

In other cases, social engineering hackers use name-dropping and intimidation to squeeze information out of employees. Whatever the approach, IT security leaders need to cultivate a workforce of employees that know enough to question and verify before they disclose anything to unfamiliar sources. Those who feel that curiosity and critical thinking are encouraged by info-security in the workplace are quite likely to be more apt to check their assumptions of authenticity or authority in other circumstances, so that information security stays intact.

 

Next On The List

Taking these steps to build a more cautious and participatory employee base is great for making the weak human link in the security chain stronger. And it’s even better when that can be backed up with the appropriate application of security technologies and policies – as well as by the authority to see requirements are enforced.

A couple of things to remember on these points is that the technology speed bumps put in place to keep mindless mistakes from happening shouldn’t become roadblocks that make it unnecessarily hard for people to do their jobs. Then it’s easy for them to justify finding ways around the obstacles, with all the implications that has for security.

Also, your processes should be realistic. A bad example sis telling hundreds or thousands of employees not to write down their passwords. That’s a common requirement, but there’s no way IT security actually can police that. Also, the violators are often high-ranking management. A better approach is to have policies that make people responsible for their actions. So, a policy can say that written-down passwords must be kept in a secure place, and that if a breach can be traced back to failure to follow that rule, there will be consequences. To that end, it’s also important that security leaders have the authority to match their responsibility.

There’s one last thing I’d recommend to info-security leaders and their teams: Get out and meet the people in your company. Practice a little social engineering – for good! – on them. Read books about influence and the psychology of persuasion to help them improve their skills in this area.

First, observe co-workers to find something in common with them, whether it’s sports or parenthood or rumba dancing. From there, you’re on your way to doing what every successful social engineer aims for: Making the connection. These simple, low-cost actions will get colleagues on your side, helping you to forge more strong links in what will become a security chain of steel.  


 

This article was previously published in the print edition as "Fixing the Weakest Link in Your Security Chain: People."

KEYWORDS: cyber security information security security enterprise solutions social engineering spearphishing schemes

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Ron Woerner is a noted speaker and writer in the security industry and the Director of the M.S. Cybersecurity program at Bellevue University, an award-winning leader in educating adult learners online and in the classroom. He has 20 years of corporate experience in information technology and security, and he has worked for HDR, TD Ameritrade, ConAgra Foods, Mutual of Omaha, CSG Systems and the State of Nebraska. Ron earned his B.S. in computer science from Michigan State University and his M.S. in information resources management from Syracuse University. He is a Certified Information Security Professional (CISSP) and Certified Ethical Hacker (CEH).

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Security's Top Cybersecurity Leaders 2024

    Security's Top Cybersecurity Leaders 2024

    Security magazine's Top Cybersecurity Leaders 2024 award...
    Cybersecurity
    By: Security Staff
  • cyber brain

    The intersection of cybersecurity and artificial intelligence

    Artificial intelligence (AI) is a valuable cybersecurity...
    Logical Security
    By: Pam Nigro
  • artificial intelligence AI graphic

    Assessing the pros and cons of AI for cybersecurity

    Artificial intelligence (AI) has significant implications...
    Cybersecurity
    By: Charles Denyer
close

1 COMPLIMENTARY ARTICLE(S) LEFT

Loader

Already Registered? Sign in now.

Subscribe For Free!
  • Security eNewsletter & Other eNews Alerts
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

Security’s Top 5 – 2024 Year in Review

Security’s Top 5 – 2024 Year in Review

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Crisis Response Team
    Sponsored byEverbridge

    Automate or Fall Behind – Crisis Response at the Speed of Risk

  • Perimeter security
    Sponsored byAMAROK

    Why Property Security is the New Competitive Advantage

  • Duty of Care
    Sponsored byAMAROK

    Integrating Technology and Physical Security to Advance Duty of Care

Popular Stories

Internal computer parts

Critical Software Vulnerabilities Rose 37% in 2024

Coding

AI Emerges as the Top Concern for Security Leaders

Half open laptop

“Luigi Was Right”: A Look at the Website Sharing Data on More Than 1,000 Executives

Person working on laptop

Governance in the Age of Citizen Developers and AI

patient at healthcare reception desk

Almost Half of Healthcare Breaches Involved Microsoft 365

2025 Security Benchmark banner

Events

June 24, 2025

Inside a Modern GSOC: How Anthropic Benchmarks Risk Detection Tools for Speed and Accuracy

For today's security teams, making informed decisions in the first moments of a crisis is critical.

August 27, 2025

Risk Mitigation as a Competitive Edge

In today’s volatile environment, a robust risk management strategy isn’t just a requirement—it’s a foundation for organizational resilience. From cyber threats to climate disruptions, the ability to anticipate, withstand, and adapt to disruption is becoming a hallmark of industry leaders.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • Corporate cyber war

    4 Challenges to Address in Corporate Cyber War

    See More
  • Employees over a computer

    4 Ways to Improve IT Collaboration

    See More
  • Generic Image for Cyber Security

    Hire a Hacker: A 2013 Security Imperative

    See More

Related Products

See More Products
  • databasehacker

    The Database Hacker's Handboo

See More Products

Events

View AllSubmit An Event
  • October 22, 2012

    Industrial Control Systems Cyber-Security Conference

    ICS Cyber-Security is the conference where industrial control systems users, ICS vendors, system security providers and government representatives meet to discuss the latest cyber-incidents, analyze their causes and cooperate on solutions.
View AllSubmit An Event
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • eNewsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing

Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!