Skip Links

Network World

  • Social Web 
  • Email 
  • Close

(Comma separation for multiple addresses)
Your Message:

Cisco study: IT security policies unfair

Most employees acknowledge they break rules to get their job done
By Jim Duffy , Network World , 10/28/2008
  • Share/Email
  • Tweet This
  • Comment
  • Print

Unfair policies prompt most employees to break company IT security rules, and that could lead to lost customer data, a Cisco study found.

Cisco this week released a second set of findings from a global study on data leakage. The first part dealt with common employee data leakage risks and the potential impact on the collaborative workforce.

Part two deals with the ‘whys’ of behavior that raises the risk of corporate data leakage. More than half of the employees surveyed admitted that they do not always adhere to corporate security polices.

And when they don’t, it can lead to leakage of sensitive data. Of the IT respondents who dealt with employee policy violations, one in five reported that incidents resulted in lost customer data, according to the Cisco study.

The surveys were conducted of more than 2,000 employees and IT professionals in 10 countries: the United States, the United Kingdom, France, Germany, Italy, Japan, China, India, Australia and Brazil. They were executed by InsightExpress, a U.S.-based market research firm, and commissioned by Cisco.

The study found that the majority of employees believe their companies’ IT security policies are unfair. Indeed, surveyed employees said the top reason for non-compliance is the belief that policies do not align with the reality of what they need to do their jobs, according to Cisco.

The study found that the majority of employees in eight of 10 countries felt their company’s policies were unfair. Only employees in Germany and the United States did not agree.

In Germany, even though the majority of employees felt their companies’ policies were fair, more than half of them said they would break rules to complete their jobs, the study found. Of all the countries, France (84%) has the most employees who admitted defying policies, whether rarely or routinely.

In India, one in 10 employees admitted never or hardly ever abiding by corporate security policies. Overall, the study found that 77% of companies had security policies in place.

But defiance may not be intentional. IT and employees have a disconnect when it comes to policy and adherence awareness, the study found.

IT believes employees defy policies for a variety of reasons, from failing to grasp the magnitude of security risks to apathy; employees say they break them because they do not align with the ability to do their jobs.

But IT could do a better job communicating those policies. The study found that, depending on the country, the number of IT professionals who knew a policy existed was 20% to 30% higher than the number of employees.

The largest gaps – 31% -- were in the United States, Brazil and Italy.

  • Share/Email
  • Tweet This
  • Comment
  • Print

Comments (12)
Login
Forgot your account info?

examplesBy Anonymous on October 28, 2008, 9:46 amAre there any examples of what "violating policy" is? A common one in our place would be checking your personal email from work, even though there might be a critical...

Reply | Read entire comment

Unfair?By Schratboy on October 28, 2008, 11:26 amThe premise is silly. Any well-run company takes time to educate the users regarding policies and expectations. Perhaps most companies are failing in this regard?...

Reply | Read entire comment

Checking Personal email, Listening music at work etc. etc.By Anonymous on October 28, 2008, 12:43 pmWork should be enjoyable place to go for, not a prison. If an employee feels happy, they produce more without harassing them all the time. This is the key. Companies...

Reply | Read entire comment

...and the winner is...By Anonymous on October 28, 2008, 4:15 pmOf course to allow workers to use the Internet to listen to music at work, browse YouTube, and keep their FaceBook site up to date would require more bandwidth and...

Reply | Read entire comment

Yes unfairBy Anonymous on October 28, 2008, 4:29 pmWhen security policies do not adapt to the reality of a departement or group, or when security rules are implemented before determining the tools require, the process...

Reply | Read entire comment

We shouldn't have to PAY for users to PLAY at work.By Anon on October 28, 2008, 7:34 pmI am an IT Director. At home, I play computer games, use Youtube, listen to streaming music, watch Netflix streaming, etc. At work I do not. Nor do other staff,...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed