Myth Busted: People aren't the Weakest Link in Cyber Security
CIOREVIEW >> Security >> NEWS

Ilmarinen Mutual Pension Insurance Company

Teijo Peltoniemi, Director, Digital Transformation and Cyber Security

Myth Busted: People aren't the Weakest Link in Cyber Security

Teijo Peltoniemi, Director, Digital Transformation and Cyber Security
Teijo Peltoniemi, Director, Digital Transformation and Cyber Security, Ilmarinen Mutual Pension Insurance Company

If your employer keeps telling you that people are the weakest link in cyber security, it may indicate immaturity and lack of adequate investment. Security must be made easy for workers and organizations must take responsibility rather than downplay the issue as merely a “people problem”.

Cyber security is of utmost importance during times like these. It’s a joint effort where everyone is a stakeholder. We live in a networked world with ubiquitous connections — and cyber security needs to be built together. Vulnerable points may expose the entire ecosystem and eventually impair the resilience of society.

Citizens and workers need to be aware and act cautiously, but we cannot outsource cyber security to them. Organizations must carry their responsibility and build secure services for their users and this way contribute to securing society.

In fact, repeating the weakest link mantra may have counterproductive effects. In the worst case, it leads to excessive security stress which in turn may lead to complacency, reduced engagement, and eventually increased risk exposure.

People can react to cyber security overexposure in different ways. For example, those working in information intensive sectors are often overburdened with a plethora of digital systems and their work has become fragmented. Adding security-related tasks will not only further decrease the productivity but may lead to overwhelmed users who are increasingly prone to mistakes.

  ​Repeating the weakest link mantra may have counterproductive effects. In the worst case, it leads to excessive security stress which in turn may lead to complacency, reduced engagement, and eventually increased risk exposure  

Stakeholders may also become estranged and unwilling to engage if the communication on cyber security is one-sided and too frequent. This may create an atmosphere of cynicism whereby people begin to question the importance of cyber security, or their ability manages it.

This type of cyber fatigue can be encountered on various levels of an organization, from the trenches to the board. Workers may begin to discard secure ways of working and executives may lose their commitment and begin to question investments.

How to make cyber security easier for users? It’s a good idea to evaluate their tasks and working processes and then map out adequate and automated controls. You will find that establishing a baseline doesn’t require rocket science. For example, users shouldn’t need to memorize several passwords and change them every other day. Neither should they be allowed access to any assets they don’t need. In other words, you may wish to begin with identity and access management and single sign-on.

Also, an environment pervaded by technical debt and vulnerabilities indicates that the organization isn’t investing adequately in cyber security. If the house isn’t kept in order, the workers may not be able to save the day even though fully complying with security policies.

For the board level cyber fatigue, you may consider turning the narrative from a business blocking compliance exercise to a business enabling and value adding joint effort which spans the entire organization. CISOs often struggle to sell their plans to the executive level, but sometimes this is because they are perceived to operate from an ivory tower, which alienates the stakeholders. The actual root cause is, however, the lack of common language between cyber security folks and senior leaders.

Let’s not deny that people have a role in cyber security — it’s important that everyone is aware and acts responsibly. However, organizations should make cyber security easy for their users and keep their house in order. They also need to engage users in a positive way. Rather than claim that people are the weakest link, they should emphasize that cyber security is a joint effort requiring everyone’s participation.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.