Users Hate Security

Opinion
Dec 11, 20072 mins

Computer security administrators and security consultants tend to forget how users feel about security: users don’t think about security unless they actively hate security at that moment. This attitude makes the job of security administrator more psychological than technical, but not one in 1000 security admins understand this.

How Dangerous User Behavior Puts Networks at Risk certainly ranks high on the scary tech story scale, but the real problem is poor management in many companies. Too often, users discount the rules about computer security because they think some unknown “them” dictates suffocating rules designed to slow users down, not provide security.

Small companies have an easier time explaining to users who makes the rules and why the rules are in place. Unfortunately, lack of trained security administrators in small businesses means the users don’t violate strict user controls because there aren’t any strict user controls. The problem, opposite from the large companies, is that small companies have little or no security.

Getting users to understand security rules takes a careful touch. Explaining why rules are in place helps. Explaining consequences helps even more.

When I used to set up passwords for users, I warned them not to share passwords, but I could tell they weren’t listening to the technical explanations of why sharing passwords was a bad idea.

Then I found a way to explain it the users understood: If you give someone your password and they do something wrong, we’ll come arrest you first. That seemed to make an impression.