Computer security administrators and security consultants tend to forget how users feel about security: users don’t think about security unless they actively hate security at that moment. This attitude makes the job of security administrator more psychological than technical, but not one in 1000 security admins understand this.
Small companies have an easier time explaining to users who makes the rules and why the rules are in place. Unfortunately, lack of trained security administrators in small businesses means the users don’t violate strict user controls because there aren’t any strict user controls. The problem, opposite from the large companies, is that small companies have little or no security.
Getting users to understand security rules takes a careful touch. Explaining why rules are in place helps. Explaining consequences helps even more.
When I used to set up passwords for users, I warned them not to share passwords, but I could tell they weren’t listening to the technical explanations of why sharing passwords was a bad idea.
Then I found a way to explain it the users understood: If you give someone your password and they do something wrong, we’ll come arrest you first. That seemed to make an impression.




