The Cyber Security Review | Monday, November 14, 2022
Identifying the lines along which a company is lacking in its cyber security saves time, costs, and confidential data.
FREMONT, CA: Human risk poses a threat to security. Companies can only partially take care of human risk but can focus on larger and more specific areas to maximize security. Measuring the company's vulnerable areas can lead to personalized solutions and strategies to adapt to risks.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Organizations implement security programs based on the following.
Human risks: Companies must identify areas that are the most vulnerable to human risks. A data-driven process to find solutions to areas of concern must integrate departments within security, such as incident response, security operations, cyber threat intelligence, or risk management teams.
Solutions: Organizations should choose efficient measures to implement solutions that derive maximum benefits. An efficient plan ensures lower costs and a better follow-through rate.
Implementing change: The organization’s human risks should be reviewed and updated consistently as technology, threats, and business requirements change. Solutions need to be updated, and employees need to evolve with changes in the security landscape.
Human risk creates vulnerabilities that leave a company's data insecure. Within each threat, identifying key risks allows officials to prioritize risk management. The metrics for measurement are;
Training: Cyber attackers can adapt to phishing controls and bypass them. Calculating human susceptibility to phishing attacks is important. Employees need to identify phishing attacks and report them.
Click rates: The security department must record the click rate of the organization. In training sessions, reduce the click rate by providing simpler phishing templates. Increase the complexity of templates to maintain a rate of 2 to 3 percent.
Repeat click rates: Repeat clickers pose a security threat as they cannot reduce their click rate.
Reporting rates: Organizations must train their employees to identify potential phishing emails.The key practice of reducing phishing incidents is for the security team to receive reports as soon as suspected incidents are reported to manage the risk as quickly as possible.
Secure passwords: Weak passwords allow for breaches in an organization. Strong and secure passwords make it difficult for cyber attackers to infect the system through new and improved tactics, techniques, and procedures.
Multi-factor authentication (MFA): MFA is important for sensitive data. Data must be limited to only those who have the authority to access it, such as those who deploy the MFA, lead Identity and Access Management, and officials of Security or Operations.
More in News