Risk-based security: staff can play the defining role in securing assets
Marc Sollars · Network Security · 2016
Last year, US firm Ubiquiti's finance team made an urgent multi-million pound money transfer for a senior executive, only to find later that the request had been made by criminals posing as him.1 In the UK, the exposure of customer financial details held by telecomms provider TalkTalk, seemingly caused by young hackers, has led to an exit of disgruntled customers.2 Enterprises are having to put mitigating security risks at the heart of their thinking, to gain better insight into potential threats and develop a genuine and lasting culture of information security. To make this breakthrough, they will have to enlist and motivate their staff to not only follow the rules but also sound the alarm over suspicious activity. Employees are becoming the first line of defence in the new security-oriented organisation. And this change in mindset begins with new thinking on the nature of risk and potential losses from it, argues Marc Sollars of Teneo.