The most popular and comprehensive Open Source ECM platform
Security: People Continue to be the Weakest Link
A recent spate of hackings and breakins, including highly secure organizations like the Pentagon, EMC’s RSA and Lockheed Martin, has clearly shown that every organization is vulnerable. Often it’s not the technology, the encryption and authentication methods or the firewalls which are the problem. While having security technologies in place is essential for cyber-protection, but more often than not, security lapses are the result of human error.
Much of the problem is that users are often not properly trained on security. A survey by certificate management company Venifi found that few companies do regular training with their employees on security best practices. In fact, the report found that few companies were following five of the best practices for ensuring secure operations:
- Perform quarterly security training with employees. [77 percent of companies are not doing this.]
- Encrypt all cloud data and cloud transactions. [64 percent of companies are not doing this.]
- Use encryption throughout the organization. [10 percent of companies are not doing this.]
- Have a business continuity plan in place should security certificates be compromised. [55 percent of companies are not doing this.]
- Rotate SSH keys every 12 months. [82 percent of companies are not doing this.]
Rich Mogull, security editor at TidBITS and former Gartner research vice president, said that “People, by nature, are unpredictable and susceptible to manipulation and persuasion. Studies show that humans have certain behavioral tendencies that can be exploited with careful manipulation. Many of the most-damaging security penetrations are, and will continue to be, due to social engineering, not electronic hacking or cracking.”.
“People, by nature, are unpredictable and susceptible to manipulation and persuasion. Studies show that humans have certain behavioural tendencies that can be exploited with careful manipulation.
“Many of the most-damaging security penetrations are, and will continue to be, due to social engineering, not electronic hacking or cracking,” said Mogull.
Security Editor at TidBITS













