Posts

Workplace information security awareness

Image
With a final dash for the finishing line, July's awareness module on workplace information security was successfully completed on time.  If you've been tracking this blog, you'll have a pretty good idea what it's all about.   The listing below shows the variety of awareness materials in three parallel streams for three target audience groups: That's another 85 Mb of awareness content in the bag, including two brand new and two updated model policies, rounding out our policy suite:  With 70 model policies in the set, and over 60 awareness topics in the portfolio, it's getting progressively harder to think of new angles on information security to cover - difficult but not impossible.   August's topic will be a brand new one for us: cyberinsurance . Although we've been quietly exploring it in the background, I'm looking forward to diving right in and immersing full in in the new topic. Truth is, I've had enough of workplace infosec. It was an intere...

More than 5 years of ransomwareness

Image
We are in the final stages of preparing July's awareness materials on "Workplace information security".  Six cool new poster designs have come in from the art department so the staff/general employee stream is practically finished, aside from proofreading.  We're working hard to complete the management and professional briefings and tying up a couple of loose ends, leaving just the newsletter left to prepare, right on cue. As usual, we've left it to the very end of the month to make the newsletter, and in fact the whole module, as topical as humanly possible. The latest ransomware outbreak all over the news this week is a classic illustration of the value of our innovative approach to security awareness.  We've covered malware at least once a year since 2003, several times in fact since malware often crops up in awareness modules covering related topics such as social engineering, identity theft, phishing, fraud, email security and cybertage. Every time throu...

Branding security awareness

Image
I find brands fascinating. We are immersed in a heavily branded world, surrounded and constantly bombarded by brands. They are thrust at us through advertisements and emblazoned on product packaging. Many are really quite crude and obvious - childish graphical logos in bright primary colors, simplistic tag lines, annoying jingles and endless endless repetitition. Others are far more subtle and sophisticated. The very best take subtlety to the point that we no longer appreciate we are being coerced, be we are, oh yes we are.  Brands go well beyond the logos, jingles and taglines, taking in very diffuse perceptions about the organizations and their products in general - myriad aspects such as quality, price, reliability, innovation and, most of all, trustworthiness. Most of us are loyal to certain brands while avoiding others (brands can be liabilities as well as assets), spreading branding's influence into the social sphere as we demonstrate and discuss our preferences with friends....

Laptop ban [UPDATED]

Image
One of the workplace information risk and security issues worth discussing with management is the possibility of a total ban on portable ICT devices such as laptops, tablets and smartphones by airlines, and perhaps other forms of mass public transport. At present, some ICT devices are banned from the cabin by some airlines on some routes, but it is not inconceivable that the ban might be extended given escalating terrorism and safety threats. I presume the only reason we are still allowed to take our explosive battery packs on board at all is the inconvenience and customer dissatisfaction that would follow if portable and wearable devices were completely banned - a typical risk-reward trade-off. As far as the security awareness program goes, whether and how a ban is extended is inconsequential: the point is to prompt the audience to think about how they would deal with that situation. It's a theoretical exercise at this stage, based on a credible scenario. What effects would it hav...

Order from chaos

Image
My physical workplace is, as usual at this time of the month, becoming cluttered with printouts and notes about the new module, vying for space with all the normal desk chaff - receipts and expenses claims, IT stuff, music CDs, crockery from lunch al-desko, and more.  It's much the same with my virtual workplace too as my mind fills to the brim with thoughts, many part-formed, some tantalizingly close to crystallising out while others remain chaotic. This is a curiously appropriate representation of my brain right now - or at least it would be if it were constantly shifting about: It's time to focus on completing the materials, discarding half-baked ideas and letting go of threads that aren't likely to mature in time.  It's not entirely wasteful though as the notes, threads and other memories will be there the next time we work on a related security awareness topic.  In infosec terms, there are risks in our way of working. We're on the critical path now, so any inci...

Weaving news into awareness

Image
Today I'v e been searching for news items to illustrate the awareness materials on workplace security, particularly incidents involving corporate information.  At first I thought maybe we have over-estimated the risks: Googling for, say, "office security" brings up stacks of news about MS Office but not so much on traditional office break-ins, fires and the like. "Commercial burglary" was a more productive search term but still not exactly overwhelming. Likewise searching for "theft from vehicle" leads to a plethora of brief police incident logs and the occasional news piece about laptops and other IT gizmos stolen from parked cars - seemingly just opportunistic thefts by druggies. Digging a little deeper, though, I realized that those police incident logs indicate a level of crime so widespread and commonplace that it is barely newsworthy any more. Tot up all those little incidents involving theft of computers, laptops, iPads, smartphones and the like...

Phishing myopia strikes again

Image
A piece in the Redmond Magazine Protecting Office 365 from Attack  caught my eye today - specifically this chunk on "User-Awareness Training" [sic]: "One of the most effective but underutilized strategies for defending your network against malware such as Osiris/Locky is user-awareness training. Because it's impossible to catch all malware, your users are the last line of defense for your network, and they should be trained as such. Accordingly, you should implement the following user-awareness training strategies: Threat awareness: Have your users take refresher courses on how to identify a phishing attempt and the importance of their participation in the fight to defend resources against malware once every quarter. Specifically, they must learn not to engage with any suspicious e-mail, report suspicious e-mail, and ensure that their endpoints are protected with anti-malware software and effective backups. It might sound simple, but many users still aren't aware...