Jump directly to main content
Digitization

Cyber-Security: Why Creating Awareness is Key

Cybersecurity starts with people: Is the human factor getting enough attention in IT security planning?

Erik Marangoni Portrait - WU Executive Academy
Wrtitten by

Is the danger of human mistakes sufficiently taken into account?

There is a fil rouge that connects a good number of cyber-incidents that have recently affected companies world-wide: the role of human beings in cyber-security incidents. It´s no mystery that big corporations have increased their budgets for cyber-security protection in the past years. The risk deriving from the absence of such a protection is too big in terms of financial, reputational, and regulatory consequences and thus, cyber-security experts have seen their own positions within the organizational chart (and their resources) boom. The question is: did companies put the necessary effort to tackle human mistakes as well?

The Human Weaknesses

If big corporations have increased the resources for their cyber-security programs, it is questionable whether they have at the same time improved the human aspects of cyber-security. Judging from the dramatic consequences of recent cyber-attacks, with ransom sums being paid to cyber-criminals and/or large revenues lost due to downtime caused by malware, viruses, etc. the result is evident. Companies need to focus more on other aspects of cyber-security.

Human vs Machine?

From a first analysis one might consider the investment in technological capabilities (firewalls, anti-viruses, data loss prevention, etc.) as the first, and only step in reaching a satisfactory level of security. Yet, this is not always the case. You can have the best cyber-security devices ever but if you do not adequately educate your staff and all your other stakeholders (i.e. your customers), well it is highly likely that sooner or later you´ll suffer from a cyber-attack.

Eine Person in formeller Kleidung tippt auf einer schwarzen Tastatur an einem Holzschreibtisch. Auf einem Computerbildschirm wird ein Dokument mit Text angezeigt. An den Handgelenken der Person sind eine Armbanduhr und ein Armband zu sehen.-CC0 Licence ©CC0 Licence
A person in formal dress is typing on a black keyboard at a wooden desk. A document with text is displayed on a computer screen. A wristwatch and a bracelet can be seen on the person's wrists.

Training vs Education vs Awareness

Companies should start giving awareness and education the right importance. Too often, in fact, cyber-security managers see awareness programs as a tedious activity, good to thick off audit requirements. Yet, awareness is more important than that. It does not give people technical skills; it does not only train them in cyber-security competences but rather it supports them in the process of changing their behaviour, and a different behaviour might save your company from cyber-incidents. This is the first step in minimizing the human risk of cyber-security.

Creating a Company Awareness Plan

If you want to have reasonable expectations to survive the next cyber-security attack, you should start providing your staff with cyber security awareness based on the following steps:

  1. Start from where you are, what are your company´s main threats (talk with your employees, they know better where threats might come from)

  2. Try to understand why your company might be the preferred target of cyber-criminals

  3. Is the company expected to suffer from internal or external threats?

  4. Start considering how you want to change your staff´s behaviour (and your other stakeholders´)

Conclusion

Always address human vulnerabilities, not only technical. Introduce human aspects in your security programs, if you want to minimize your cyber-security risks.

Update for Leaders

Join 15,000 + professionals and get regular updates on leadership and management topics. Learn something new every time. 

Subscribe to our Newsletter

Interesting Topics

Our Key Topics provide inspiration on the big questions of our time: How can responsible leadership succeed? What role does sustainability play in business? And how do you develop a career with purpose? Discover forward-looking perspectives and practical insights for a changing world.

Find your ideal program with our AI chatbot Brainiac

Let's go!