18
The Path to Security - Preventing User Negligence Sarah Kennedy

The Path to Security - Preventing User Negligence Sarah Kennedy

Embed Size (px)

Citation preview

Page 1: The Path to Security - Preventing User Negligence Sarah Kennedy

The Path to Security - Preventing User NegligenceSarah Kennedy

Page 2: The Path to Security - Preventing User Negligence Sarah Kennedy

Overview

How Students are TaughtHow InfoSec Professionals

TeachWhy Awareness is ImportantGoalsTools to use

Page 3: The Path to Security - Preventing User Negligence Sarah Kennedy

How Students are Taught

Page 4: The Path to Security - Preventing User Negligence Sarah Kennedy

How InfoSec Professionals Teach

Page 5: The Path to Security - Preventing User Negligence Sarah Kennedy

Let someone else handle it….

Page 6: The Path to Security - Preventing User Negligence Sarah Kennedy

Why Awareness is Important

Symantec Study states: employee negligence and system glitches account for 64% of data breaches

62% of employees think it’s acceptable to transfer corporate data outside of the company on personal devices and cloud services

Employee negligence breaches are increasing with every study performed

Page 7: The Path to Security - Preventing User Negligence Sarah Kennedy

Training Goals

Make it personalTrain for behavior changesCatchy

Marketing style awareness

Reinforcement and Repetition Make it fun!

Page 8: The Path to Security - Preventing User Negligence Sarah Kennedy

This is an Ultimate Repeatable Goal!

Page 9: The Path to Security - Preventing User Negligence Sarah Kennedy

Adam Grant - Organizational Psychologist

“Wash your hands to protect yourself”

“Wash your hands to protect your patients”

“Practice information security to protect our customers”

“Use information security to protect your family”

Page 10: The Path to Security - Preventing User Negligence Sarah Kennedy

Negative vs Positive

“Don’t or you will be reprimanded with consequences up to termination of employment.“

Don’t let someone tailgate behind you to enter the building.

Make sure you to help prevent data breaches.

Do be mindful of people attempting to follow you into the building.

Page 11: The Path to Security - Preventing User Negligence Sarah Kennedy

Analogies

Page 12: The Path to Security - Preventing User Negligence Sarah Kennedy
Page 13: The Path to Security - Preventing User Negligence Sarah Kennedy

Games!

Page 14: The Path to Security - Preventing User Negligence Sarah Kennedy

Practicing Preventative Scenarios

Page 15: The Path to Security - Preventing User Negligence Sarah Kennedy

Lock Your Computer Tag

Page 16: The Path to Security - Preventing User Negligence Sarah Kennedy

Main Goals for InfoSec Professionals

Information Security is everyone’s job requirement, Not just IT’s.

To protect the customers, It’s what we expect when we are the customer.

Remember: It’s Possible!

Page 17: The Path to Security - Preventing User Negligence Sarah Kennedy
Page 18: The Path to Security - Preventing User Negligence Sarah Kennedy

Questions?