Dealing with human risk in cybersecurity

Issue 9 2020 Training & Education

With the worldwide information security market predicted to reach $170 billion in 2022, this is obviously an area of significant risk to organisations and individuals. Organisations need to address these risks by considering all the areas that contribute to cyber risks. Unfortunately, the human element in cyber risk is often ignored while the systems are focused on.


Some of the major areas of human risk that could easily be considered and addressed, according to Jenny Reid, CEO of iFacts, are the following:

Onboarding of employees

During induction, the company policy regarding the misuse of company devices for personal use should be discussed and the following areas highlighted:

• Personal banking.

• Personal emails.

• Personal social media.

• Filing of personal information.

• Use of personal passwords.

• Installation of personal software.

These are just some of the issues that many people believe they have the right to do when working at a company and feel that they may use the company equipment for personal use. Unless the company policy is brought to their attention, they may not understand the risk they bring to the company.

Understanding information security

The average employee has a very limited understanding of information/cyber security and believes that is something that happens at a very high level and will never affect them. You merely need to read a magazine or watch a TV programme to see how easily people ‘give’ their money away and do not understand they have been scammed.

This should be highlighted in the induction process and there should be ongoing awareness training of the risks employees could be exposed to. Some of the areas to consider discussing are:

• Connecting devices to company computers, e.g. USB sticks.

• Phishing emails.

• Using unsecured networks.

• Storage of sensitive data.

Highlighting employee risk

Any company should have an employee screening policy to address the various levels of risk in an organisation and this should include integrity assessments to highlight the level of integrity of an individual coming to work in the organisation. An integrity assessment will assess the intention of an individual as opposed to verifying information about the individual’s past.

Employee screening should not be limited to pre-employment but should be an ongoing part of an employee’s life in the company. Risks change, from both a company perspective and an individual’s perspective, and various forms of lifestyle audits should be done on an ongoing basis.

Companies should also consider integrity training as a crucial part of their employee lifestyle as people are exposed to many levels of crime and corruption, and differentiating right from wrong can become a blurry issue for many.

Remember, where there are people, there is risk. Address it effectively.


Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Organisations fear AI-driven cyberattacks, but lack key defences
Kaspersky Information Security News & Events Training & Education
A recent Kaspersky study reveals that businesses are increasingly worried about the growing use of artificial intelligence in cyberattacks, with 56% of surveyed companies in South Africa reporting a rise in cyber incidents over the past year.

Read more...
ONVIF launches new online learning initiative
Training & Education Surveillance News & Events
ONVIF has released the first course in a new online learning initiative designed to promote greater knowledge and understanding of ONVIF's workings. The first “Introduction to ONVIF” course is now available.

Read more...
Unique fire detection challenges in hospitals
Securiton Fire & Safety Healthcare (Industry) Training & Education
Africa’s healthcare sector is a growth opportunity for business as new hospitals bring better health for millions, and the fire safety industry has a key role to play by ensuring these long-desired new hospitals do not go up in flames.

Read more...
South African youth robotics team takes world title
News & Events Training & Education
A South African youth robotics team recently won the 2024 FIRST Tech Challenge (FTC) World Championships. FTC is an international robotics competition designed to ignite high school students' passion for STEM (Science, Technology, Engineering and Mathematics).

Read more...
SMARTpod talks to The Risk Management Forum
SMART Security Solutions Editor's Choice News & Events Security Services & Risk Management Videos Training & Education
SMART Security Solutions recently released its first SMARTpod podcast, discussing the upcoming Risk Management Forum Conference 2024, which will be held on 26 September 2024 at the Indaba Conference Centre in Fourways, Johannesburg.

Read more...
How to securely manage your digital footprint
Information Security Training & Education
Managing your online presence is critical to safeguarding your privacy and security. It is imperative to take a proactive approach, including using robust cybersecurity best practices.

Read more...
Cybersecurity fatigue: A growing risk with AI-driven social engineering attacks
Information Security Training & Education
Despite the significant amounts of time and money invested in cybersecurity training and awareness, employee carelessness and ignorance remain the most vulnerable parts of the average enterprise’s security posture.

Read more...
Tips and tools for trade businesses
News & Events Training & Education
ServCraft brings together trade industry associations and corporations to launch blox, a digital content platform and community impacting lives, businesses and industries across hundreds of thousands of trade business SMEs.

Read more...
Africa Online Safety Platform launched in SA
Training & Education News & Events
Impact Amplifier, with the financial support of Google.org, launched its African Online Safety Platform (AOSP), a platform providing a rich repository of research, education content, funding opportunities and ways to seek help after an online crime.

Read more...
South African Keiron PRO laser target system
News & Events Training & Education
Jacstech, based in Cape Town, South Africa, has been appointed to supply a complete Keiron PRO laser training system to the SIRT Academy. The SIRT Academy is a firearms and tactics training facility in Perugia, Italy.

Read more...