Don’t Dismiss the Human Element in Your Network

Analysis
Apr 17, 20123 mins

Securing the network begins after the policies have been rolled out.

How amazing to have my very first IT blog (and there’s a good chance it will even be read). During my eight years in customer/ IT support for various technology companies, I’ve encountered some interesting issues, practices and policies – and now I can share my experiences with the world. In “From the Front Lines of Support,” I’ll talk about the common problems businesses face managing their security and share funny anecdotes of technology mishaps. From time to time, I’ll also give my advice on how to overcome certain challenges or avoid mistakes I see administrators making on a consistent basis.

For my first post, I would like to talk about the human element in a network.

Don’t Dismiss the Human Element in Your Network

What we do for work often bleeds over into our personality. I know marketing people who can’t help but criticize television commercials, editors who find grammatical flaws wherever they go and IT professionals who balk at so-called “hackers” on TV.

Perhaps no group is more affected by this phenomenon than IT and network administrators. We are constantly asked by less-technical friends and family to fix their home computers – and it seems this constant demand for support has created a feeling of superiority when it comes to tech. How else can I explain why in a recent survey by Sophos, 19% of network administrators said that the worst IT offenses in their company come from IT. With 96% of respondents also noting they do not trust their end users to make sound security decisions, it seems many IT administrators aren’t taking their own security policy advice. Heck, even security journalists don’t always follow their own advice.

I work with IT teams everyday to help them get the most out of their security products and one point is always evident: even if you have the best products and the best policies, they need to be backed up with an understanding and buy-in of these policies from all levels of an organization (yes, even your boss).

The administrators I talk to all have, in my opinion, great security tools in place, and oftentimes, their issues are due to an action by an employee or misconfiguration of their tools. We in IT can sometimes become so enamored of our cool toys that we dismiss the human element in a network. But if we are smart we’ll remember any tool is only as good as the person wielding it, and threats, even unintentional ones, come from within as well.

Once your organization has finalized its security policy and rolled it out, the work is just beginning. In addition to monitoring logs and adjusting security controls, the company needs to frequently remind network users (aka employees) on policies and proper Internet behavior.

But whose responsibility is it to communicate IT policies to employees. HR? Internal comms? Another group? With 48% of IT administrators stating they fix security issues caused by end-user negligence once a week or more, it clearly affects IT productivity. Therefore, shouldn’t the responsibility fall on their shoulders?

This can be a tricky subject at some companies, but ultimately the best approach is to combine security expertise of IT with HR’s/internal communication’s ability to deliver messages effectively. Also, take advantage of online tools provided by security companies, as they do a lot of the “heavy lifting” for you. Bottom line:

Knowledge is power, and the more you share, the more powerful (aka secure) your network will be.