* Employees continue to contribute to data leakage
endif; ?>“Why don’t employees just PAY ATTENTION and FOLLOW OUR RULES?!?” Doesn’t that sound like the cry from the heart of security managers the world ’round? Well, there’s hope. Follow me today and next time on an excursion into current research findings and I’ll show you a simple principle that will change the way you implement security awareness.
“Why don’t employees just PAY ATTENTION and FOLLOW OUR RULES?!?”
Doesn’t that sound like the cry from the heart of security managers the world ’round? Well, there’s hope. Follow me today and next time on an excursion into current research findings and I’ll show you a simple principle that will change the way you implement security awareness.
In 2008, Cisco released an extensive research study on data leakage conducted by Insight Express using 2,000 respondents in 10 countries. The objectives are summarized in a presentation (quoting), to:
• Explore employee use of company devices, including communication services and devices used, personal activities conducted and the extent to which technology and information is shared.
• Assess IT’s perception of employee use of non-IT approved programs and applications, concern for security issues and actions taken to prevent or uncover potential security breaches.
• Understand whether workers are concerned with security as well as how much they perceive themselves exposing their company-issued technology devices to risk.
In the report on the study entitled, “Data Leakage Worldwide: Common Risks and Mistakes Employees Make”, the authors concluded that employee mistakes contributing to data leakage included the following (quoting):
• Unauthorized application use: 70% of IT professionals believe the use of unauthorized programs resulted in as many as half of their companies’ data loss incidents.
• Misuse of corporate computers: 44% of employees share work devices with others without supervision.
• Unauthorized physical and network access: 39% of IT professionals said they have dealt with an employee accessing unauthorized parts of a company’s network or facility.
• Remote worker security: 46% of employees admitted to transferring files between work and personal computers when working from home.
• Misuse of passwords: 18% of employees share passwords with co-workers. That rate jumps to 25% in China, India, and Italy.
Stefanie Hoffman, writing for ChannelWeb, analyzed the results in a conventional way, concluding that the key issue is a lack of understanding:
“Overwhelmingly, failure to comply with company regulation resulted from lack of communication. The study found that when IT communicates policies to employees, they often use non-verbal – and subsequently unmemorable – means, such as e-mail, IM and voicemail. As a result, 11 percent of employees said that IT never communicates or rarely educates them on security policies.”
There’s lots more discouraging information in the report, but it all confirms that users simply are not getting it when we yammer at them about security. So what’s a security officer to do?
In the next article in this two-part report, I’ll look at some instructive research from the scientists at Carnegie Mellon University.




