As organizations struggle to keep pace with an increasingly active and complex threat landscape, oftentimes the biggest cybersecurity hazard isn’t the latest malware, ransomware extortion, or zero-day vulnerability. Rather, it’s employees who simply aren’t up to speed on security best practices.
Many users are acquainted with the growing cyber threat thanks to countless horror stories of companies caught in the crosshairs of targeted attacks. Yet most business users view cybersecurity as someone else’s problem – either IT or an enterprise security organization. As such, they are not wholly cognizant or committed to the critical role they must play in proper safeguards and governance. Moreover, users are typically hyper-focused on getting their own work done and, therefore disinclined to take any protective measures that will get in the way of productivity.
According to one research study, 91% of employees say they are frustrated by workplace tech. Ensuring user productivity is the second top challenge related to securing the modern workplace, another report found. In particular, users don’t want to guess the right process to connect, such as leveraging a VPN for one application while invoking a totally different protocol for another workflow. Nor do they want to repeat verification tasks over and over.
This lack of cybersecurity awareness and training among users opens the door to significant risk and exposure. In Foundry’s 2023 Security Priorities study, 88% of security leaders believe their organization is falling short of addressing cyber risks. The most cited cause of security incidents: non-malicious user error.
Most recent data indicates that only 24% of U.S. organizations have achieved ‘expert’ status in cybersecurity maturity while similar studies place the European Union at 39% in the same areas. The common weak spots are a lack of employee training, poor password management, outdated software, insufficient access controls, and a lack of an incident response plan. All of these are driven by insufficient investments and the absence of a cybersecurity culture.
Raising cybersecurity maturity
Organizations should consider the following steps to elevate maturity and promote cybersecurity awareness:
- Connect cybersecurity to business strategy: It’s not enough to introduce training on how to avoid phishing emails or effective password management strategies. Companies need to infuse the importance of cybersecurity into the culture, clearly articulating and routinely demonstrating how subpar practices leave the enterprise exposed to compliance, brand, and financial risks.
- Make it a shared responsibility. Companies with mature cybersecurity practices typically elevate oversight to a senior-level executive such as the CIO or CISO and reinforce practices through top leadership engagement. They also communicate the importance of a shared responsibility model that makes cybersecurity everyone’s responsibility, not just the purview of a dedicated department. Some organizations will go as far as to make cybersecurity readiness a key part of employees’ performance evaluations.
- Communication is key. Build engagement and communicate why security matters to both individuals and the business in language users can understand. Multi-channel campaigns that leverage videos or blog programs to illustrate key issues can be effective.
- Take a multi-layered security approach. Beyond raising organizational maturity, elevate cybersecurity measures through multiple lines of defense, including firewalls, antivirus software, encryption, and multi-factor authentication. In that way, if one layer is compromised, others will continue to provide protection.
Overcoming these challenges often requires a combination of ongoing education, effective communication, simplification of protocols, and the implementation of user-friendly security tools.
Click here for more information on Cisco’s security solutions.
Protect users and ignite productivity. Connect with a Cisco expert to learn about the benefits of user protection.
