Users say to IT: It’s none of your business what I do

Opinion
Jan 8, 20074 mins

* Users really do ignore IT authority, according to Cisco report

It’s not unusual for IT professionals to feel like the end user community doesn’t listen to them. Now comes confirmation from Cisco that it’s not all in your head; users really do ignore your authority.

Following a 2006 international study of remote workers and their online behavior, Cisco issued a report revealing that these workers don’t think the IT department should be telling them what to do. This is disconcerting for companies that are concerned about risky online behavior that has the potential to compromise enterprise security.

That’s not to say that remote workers completely shun authority. They may not believe that IT has the right to tell them what they can and can’t do online, but many at least will follow their own managers’ directions.

These revelations are part of a “one-two punch” set of studies commissioned by Cisco a few months ago. The first punch comes from a study which took an in-depth look at what kinds of online behavior remote workers engaged in. Pow! There it is in black and white – users are doing everything that is contradictory to good security guidelines. The second punch comes from a follow-up survey of the workers that looks at their perceptions of IT’s role in protecting them. Wham! Workers don’t think IT has the right to dictate what workers can do online with company resources, regardless of the security implications.

Let’s start at the beginning. Cisco commissioned InsightExpress to survey remote end users from a variety of businesses in ten countries. The purpose of the study was to learn more about remote workers’ awareness of security needs and their actual online behavior. The results, to put it mildly, aren’t pretty. While most users believe they are security-conscious, they often engage in online activity that can put their own computer or the company systems at risk.

What kinds of activities are we talking about? Here’s a sampling:

* Using their own personal computer to access company resources.

* Sharing their company-issued computer with other people, such as family members.

* Browsing Web sites that are not work related.

* Using a neighbor’s wireless network.

* Opening suspicious e-mails and attachments.

* Using the business computer for non-business activity.

As you can see, some of these activities can be prevented with the smart use of technology. For example, you can force remote workers to use a VPN and strictly limit what devices can access your network via the VPN. That way you eliminate the worry of remote workers using just any old PC to access work resources.

As for the other activities, many could be curtailed if users were more aware and observant of strong security guidelines and policies. For instance, perhaps a regular reminder about the risks of opening e-mail attachments might cause a few people to think twice instead of blindly opening every attachment.

Jeff Platon, Cisco’s vice president of Security Solutions Marketing, says this is where IT organizations and chief security officers can take a proactive stance to improve security for remote workers, “IT must play a more strategic role, and to do that they need to develop stronger relationships with users to prevent threats from sabotaging efficiency and personal identities,” says Platon.

Based on a follow-up survey with these remote workers, IT better develop strong relationships with the workers’ business managers, too. This study found that, in six of the 10 countries where the survey was conducted (including the United States), more remote workers felt their managers had the authority to control their behavior than IT organizations. In France, more remote workers said it is no one’s business what they do online than those who agreed that IT had authority for oversight of online behavior.

Cisco Chief Security Officer John Stewart says this is an opportunity for IT to establish itself as a trusted advisor on security. He says that education and awareness are keys to reducing security risks.

What is your organization doing to make users more aware of security risks? Is your awareness campaign working? Let me hear from you, and I’ll publish your great ideas to share with others.