12:51 PM

Office Workers Know About Your Security Policy. But Are They Following It?

Hey IT managers, your office workers might say they are following security procedures. But get someone to ask them that question anonymously. Their answers might surprise -- and upset -- you.

Hey IT managers, your office workers might say they are following security procedures. But get someone to ask them that question anonymously. Their answers might surprise -- and upset -- you.RSA, the security division of EMC, recently published a survey tantalizingly titled, "The Confessions Survey," thanks to the way the research was conducted, in on-the-street interviews, providing its respondents with anonymity. About a third of the respondents were from small to midsize companies.

According to eWeek, "53 percent of respondents who work for the private sector access work e-mail via a public computer such as at an Internet caf, airport kiosk, hotel or the like."

Moreover, "sixty-eight percent of enterprise workers leave work carrying a mobile devicesuch as a laptop, smart phone or USB flash drivethat holds sensitive job-related information, including customer data, Social Security numbers or company financials."

The kicker is that in response to the survey question: Are you familiar with the IT security policies of your company?, a full 81 percent of business workers answered yes. Furthermore 69 percent of business workers answered yes to the question: Does your company follow training about the importance of following security best practices?

InformationWeek's John Soat flips the percentage and focuses on the 31 percent of those companies that do not provide the necessary training on the significance of following their security practices. While that is almost a third, it doesn't account for all those employees who are familiar with their company's security policies, know about their importance, and continue to flout those rules.

Perhaps that can be explained in the employees' answer to this question in the survey: "Do you ever feel the need to work around your company's established security policies and procedures just to get your job done?" A full 35 percent of business workers said yes.

Obviously security policies need to be implemented and enforced in small and midsize businesses but Soat's quote from RSA acknowledges that there is also a working reality and calls on IT managers to take that into account when establishing security policies:

"Organizations can mitigate this risk by developing information-centric policies that acknowledge and align with the needs and realities of the business. Once such policies are in place, companies should constantly measure actual user behavior against established policy and use what they learn to inform smart policy changes that minimize risk and maximize business productivity. When security is as convenient as possible for end users, they are less likely to work around security policy."

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
Printers: The Weak Link in Enterprise Security
Kelly Sheridan, Associate Editor, Dark Reading,  10/16/2017
20 Questions to Ask Yourself before Giving a Security Conference Talk
Joshua Goldfarb, Co-founder & Chief Product Officer, IDDRA,  10/16/2017
Why Security Leaders Can't Afford to Be Just 'Left-Brained'
Bill Bradley, SVP, Cyber Engineering and Technical Services, CenturyLink,  10/17/2017
Register for Dark Reading Newsletters
White Papers
Cartoon Contest
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
The State of Ransomware
The State of Ransomware
Ransomware has become one of the most prevalent new cybersecurity threats faced by today's enterprises. This new report from Dark Reading includes feedback from IT and IT security professionals about their organization's ransomware experiences, defense plans, and malware challenges. Find out what they had to say!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.