Our tenth anniversary module
The new “Taking chances” awareness module is about identifying, assessing and dealing with information security risks and opportunities. Whereas information security and risk management professionals, as a breed, are generally risk-averse, the awareness materials this month acknowledge pragmatically that there are legitimate business reasons to accept some information security risks, to take chances deliberately: the trick is to know which ones to live with, and which to avoid, pass to someone else or mitigate. Animals deal with safety risks routinely at a subconscious level, avoiding extreme dangers instinctively, and learning to avoid other risks through teaching, by observing their parents and peers, or by trial-and-error: the ability to learn and so change our behavior is a vital survival skill. In a sense, organizations also have both instinctive and learned reactions to risks. This month’s awareness module passes-on decades of real-world experience with the manag...