
27.11.2021
The user as the biggest risk In our last blog post, we already highlighted how important the technical security of IT systems in companies is. An equally important component, often underestimated by companies, is people. IT security is only as good as the people who operate the systems. The best technology is useless if […]
The user as the biggest risk
In our last blog post, we already highlighted how important Technical security of IT systems in companies is. An equally important component, and one often underestimated by companies, is the human element. IT security is only as good as the people operating the systems. The best technology is useless if users are not educated about the dangers and do not act in a security-conscious manner. The IBM Cyber Security Intelligence Index shows that more than 90% of all security incidents are due to human error. To minimise the risk posed by employees, it is essential to create security awareness within the company.
What is Security Awareness?
Security awareness means „security awareness“. This is to be brought about by appropriate training measures (security awareness training), which explain topics such as data protection and data and information security. These can take place both in „frontal teaching“ in classrooms or meeting rooms, as well as in the context of online training. Employees must learn to deal with the dangers of today's globally connected world. They are provided with the necessary know-how, which ideally is aligned with the company's guidelines and processes, as well as the requirements of the respective department.
Why is security awareness so important?
The IT world's development isn't just about opportunities, but also about threats to businesses. Hackers are developing ever more undetectable malware and finding new ways to access company data and blackmail victims. Often, it's not even malware like a virus that helps attackers infiltrate a company, but so-called social engineering. A popular form of social engineering is so-called phishing, where users are specifically manipulated by criminals posing as a superior, a trusted tradesperson, a bank employee or the fire brigade via email. The perpetrators try to gain trust and thereby obtain sensitive data. While spam filters can filter out some emails, they are powerless against targeted threats. Therefore, it is crucial to strengthen the company's „human firewall“ as much as possible.
The effort put into social engineering attacks is sometimes enormous. Company structures are spied upon, revenues analysed, and so on. Once the extortion amount has been determined, a targeted, manual attack is usually carried out on an individual. In the worst-case scenario, this person possesses a privileged (admin) account and also has access to data backups.
Risk factors emanating from employees
Mismanagement of fraudulent emails
A major risk factor is the improper handling of fraudulent emails, often resulting from staff ignorance or a fear of missing out. While spam filters can block many, they cannot filter out all such emails. Users who rely solely on technical security measures may accidentally click on links in seemingly legitimate or familiar emails, thereby opening the door to malware. In the worst-case scenario, these emails are then forwarded within the company for discussion. In many cases, a threat then emerges simultaneously for multiple users. This automatically increases the likelihood that an attacker can hijack an account with elevated privileges.
Simple, outdated or insecure passwords
In fact, passwords, which are supposed to be used for security, are also huge risk factors. This includes a password that is too simple (e.g. 12345), for which the company should develop password guidelines (minimum number of characters, upper and lower case, special characters, etc.). However, even if the same password is used over a longer period of time or in different places, you still offer cyber criminals points of attack. It can also be said that simple protection is simply not enough for such an important asset as company data. Two-factor authentication is a good way to improve security. Although this has been common practice in many companies for years and is also becoming increasingly present on social networks, some companies still do not have this type of protection in place. Here, the identity of the user is checked by two different and independent factors when logging in. Similar to action films (opening a „top secret door“ is only possible with a magnetic card, access code, eye and fingerprint scan, etc.), this also works here. When logging in, not only is the user's password requested, but a unique, dynamically generated password is also sent to a second, independent component (SMS, e-mail, authentication app, etc.). The login is finalised when this code is entered on the first component. This is also referred to as multi-factor authentication - namely with the factors knowledge (password) and possession (app on smartphone).
Private end devices on the company network
External end devices brought in by employees can also pose a threat as they fall outside of the company's IT management. For example, the employee's private end device may already be infected with malware and read login information when logging into the company network and then leak, falsify or delete important data, passwords, etc. Outdated operating systems (missed updates or inconsistent system statuses in contrast to the company's end devices) and apps in use offer further potential for intrusion. For example, the authorisations requested by the apps could access confidential data (such as contact data or address books). It is therefore also advisable to create security awareness and define a policy for this. The employee's privacy should of course be protected, but there should also be transparency in order to secure the company. However, these guidelines not only need to be recorded and displayed, but also enforced and compliance monitored. A BYOD (bring your own device) strategy that is not fully thought through and structured can weaken the IT security of the entire company.
Carefree internet use
Insecure or misleading websites, accidental downloads, and many other entry points for Trojans, worms, and the like – the internet holds several dangers. And it makes no difference whether for business or private use. Therefore, it is important to raise employees' awareness of potential risk factors and to foster security-conscious behaviour (security awareness).
Cover-up of cyber-attacks
Companies should teach their employees that lying or concealing things is utterly pointless and only makes the impact of a cyber incident worse. It's not uncommon for employees who caused such an incident to try and shift the blame or cover up the dilemma – this is fatal! It only makes things worse, as the malware can spread in the meantime. The sooner the malware can be dealt with, the better – this needs to be made clear to employees. Because the cyber attack will be noticed anyway.
The Security Awareness training mentioned covers precisely this topic:
– which people are to be informed,
– what processes need to be initiated,
– what procedures must be followed,
when incidents occur that are relevant to the organisation's IT security.
Training must be refreshed regularly and, in companies with high staff turnover, conducted at regular intervals. Ideally, such security awareness training should take place continuously via an awareness platform. There are numerous providers for this (e.g. KnowBe4), compiling training materials in different languages and addressing current threats and behaviours. Employees are usually invited automatically. Then, e-learning sessions are held. Their completion is logged and they take place on an ongoing basis. Furthermore, there are attack simulations, which allow employees to be trained not only in a situation-specific manner. It is also possible to gain an overview of users' knowledge levels through attack simulations and, if necessary, to provide further training.
Security Awareness in the Company: Training for Employees
In security awareness training, it is important not to confront employees with any IT gobbledygook. You have to pick them up where they are with their current level of knowledge and explain it to them in an understandable way. Not everyone has the same prior knowledge. Some people deal with IT topics in their free time or are naturally tech-savvy, while others have nothing to do with it at all. This is precisely why it is all the more important not to hold standardised „IT lessons“ so as not to over- or underchallenge employees. Practical, tangible examples (such as real phishing emails that have arrived at the company) train users to recognise such threats themselves in future. This gives them an understanding of the threats a company is exposed to and the consequences they could suffer from an attack. Fun elements (such as a quiz) can also be incorporated to spur employees on and liven things up a little. Additional motivation can be provided by certificates that employees receive when they pass security awareness training. Employees must also be made aware that they can contact experts (IT department or person responsible, IT service provider) in the event of suspicious emails. Users should not feel left alone, but should know how and to whom they can turn in the event of dubious emails, payment requests, etc. and that this is not a burden, but a relief for the company. In order to test employees, phishing simulations can be carried out via the aforementioned awareness platform to inform employees. If they fall for the simulation, they will be redirected to learning websites when they click on the link. Another measure could be the implementation of a phishing button, which employees can use to report suspicious emails.
Staff are not just a danger
Although we've painted a rather dismal picture in this blog post of what can happen when users don't know how to deal with the dangers and challenges of the digital world, the opposite is also true. Employees don't always have to be risk factors. Well-informed and trained employees who are aware of the dangers and have competence in this area can make an important contribution to company security.
To be at least as well positioned as the attackers
These days, companies are exposed to a number of dangers. And as harsh as it may sound, organisations must be at least as well-prepared as their attackers and keep pace with their developments. This means that all components that can contribute to IT security must be considered and continuously optimised. However, it is not enough to focus exclusively on a stable and secure IT infrastructure. Because, contrary to what many might think, human expertise in IT security can be at least as valuable as technical capabilities. In expert circles, this is referred to as a „Human Firewall“.

Arrange an initial consultation