Showing posts with label employee security training. Show all posts
Showing posts with label employee security training. Show all posts

Thursday, June 11, 2009

Corporate data security: You’re gonna need more than a policy

An alarming number of employees are ignoring data security policies and are routinely engaging in activities that could put their employer at risk, according to a survey released by Ponemon Institute Wednesday.

According to survey results, the most frequent data security offenses were employees copying secure data to USB drives, turning off security settings in mobile devices like laptops and sharing passwords. All offenses that have the potential to put a company’s data at risk.

Of the 967 IT professionals surveyed, around 69% said they copied confidential company data to USB sticks, even though they knew it was against the rules. Still worse, some employees admit that they lost USB sticks housing company data, but failed to report it immediately.

Another disturbing trend is the amount of workers engaging in online activities that raise the risk of infecting company computers with malicious software.

About 31% of respondents engaged in social-networking practices on the Web from work PCs and around 53% said they downloaded personal software on company PCs, increasing the risk of spreading malware in the workplace, according to the research.

“Mobile technologies that let employees do more while on the road are contributing to the issue, said Larry Ponemon, chairman and founder of Ponemon Institute, in a blog entry. As the use of mobile devices grows, the inability to enforce data security policies could increase the possibility of data breaches. "I’m seeing a confluence of conditions that appear to be contributing to this challenge to data integrity," he said.


Over half (58%) of the IT professionals surveyed put the blame on companies for failing to provide employees with adequate data security awareness and training. About 57% also said their company’s data protection policies were ineffective and 43% said there was poor communication and enforcement of data security policies.

“The Ponemon Institute believes these results show overall lack of urgency by companies on the need to address data security. Unfortunately, our studies have also shown that it often takes a data breach incident before an organization will finally get their wake-up call and take data security seriously.” (Dr. Ponemon’s blog)


Like the survey results showed, it’s going to take more than just a policy to ensure that your company’s data is secure and protected. Read some of these past posts for more information on not only setting up a data security policy, but also training employees on how to keep your company safe:

Employee anti-phishing training, one scam at a time


Six tips for setting up a computer security policy


Employee security training: Spam 101

Employee security training: How to catch ‘phish’

Disgruntled Chrysler employee fired after Internet post

Tuesday, March 24, 2009

Employee safety tips from AIG corporate security

After receiving a bailout worth billions of dollars in taxpayer money, every move by U.S. financial institutions has been under the watchful eye of an extremely critical audience.

The conversations on blogs and other social networking sites, along with recent protests outside the doors of AIG corporate offices, have become so heated that AIG corporate security is worried for employees’ safety.

Gawker, the online gossip site, claims to have gotten their hands on a leaked AIG memo that includes advice for employees on responding to perceived threats and taking personal security precautions.

The post, titled “AIG Corporate Security's Tips for Surviving an Angry Mob,” features a copy of an AIG document that outlines “certain protective measures all employees can take in order to increase their overall safety and security.”



Employees are advised to call 911 at the very onset of a perceived threat and report any suspicious behaviors or questionable activities to AIG building security. A few of the security guidelines and employee safety tips include:

  • Avoid wearing anything embroidered with the AIG logo
  • Ensure AIG security badges are not visible when leaving the office
  • Do not engage in public conversations regarding the company
  • Walk in pairs and park in well-lit areas


Whether the document is legitimate or not remains a mystery, but the document does back AIG chairman Ed Liddy’s warning message that the company’s “public flogging” may be putting his employees’ safety at risk.

While it's unlikely that your organization will ever have to go through anything quite as public as AIG, employee safety training in dealing with disgruntled customers and the public has become a growing issue since the recession started.

Though overall workplace violence rates have dropped over the past ten years, homicides from customers and clients has steadily grown from 25 in 1997 to 74 workplace murders in 2007.

Workplace violence experts warn that there may be a rise in attacks as the economy continues to struggle. The violence is less likely to come from an angry laid-off employee, but more from an angry public. The employees that work directly with the public must be trained to deal with extremely angry customers and clients.

As the threat grows, so does the importance of building safety and employee training. Read more about how to recognize the risks of violence in the workplace and how to make positive changes to reduce that risk in “Heading off workplace violence: Keep employees safe with practical workplace safety tips” from our TrainingTime Learning Library.

Tuesday, February 3, 2009

Employee anti-phishing training, one scam at a time

Could your employees spot a phishing scam if they saw one? Would they know what to do if a suspicious email landed in their inbox?

Why not try what the U.S. Department of Justice (DOJ) recently put together to train their employees? Send them a test.

To train their employees on the danger of phishing scams, the DOJ designed a scam of their own and recently sent it out as a test for employees.

Michael Santo, Editor-in-Chief of RealTechNews, covered the internal scam in a recent blog post, stressing the importance of employee training to guard your company against online scams.

The DOJ's fake phishing email was written in regards to the Thrift Savings Plan (TSP), a retirement savings plan, that many civilians employed by the U.S. government and uniformed service members use. The savings plan has recently fallen victim to the economic downturn.

The email directed employees to visit a fake phishing site and asked them to enter their account information by the end of the month.

Some employees spotted the scam right away, some were warned by other employees, but it created enough worry that the TSP actually put a warning message up on their website.

Last week, Ted Shelkey, assistant director for information systems security, sent the worried employees a memo explaining that the savings plan email was a hoax and that the email was just a test.

Everyone and every business is vulnerable to a phishing attack "simply because we humans are naturally programmed to respond to things that are perceived as important to us," according to Linda Musthaler at Nework World.

If a phishing scam were to hit your company, it could cause serious damage to your bottom line including financial loss, customer data breaches, and even intellectual property theft. Because of such risk, every corporate security program should include thorough user awareness training.

“Although we have shown that we can teach people to protect themselves from phishers, even those educated users must remain vigilant and may require periodic retraining to keep up with phishers' evolving tactics,” wrote Lorrie Faith Cranor, director of the Carnegie Mellon University CyLab Usable Privacy and Security Laboratory, in the article How to Foil “Phishing” Scams.


We’ve covered the dangers of phishing scams and how employee security training is your first line of defense in an April 2008 post. As a review, here are some tips to avoid being snared by a phishing scam at the office and at home:

  • If a message lands in your inbox asking for personal or financial information, do not reply or click on any links.
  • Don’t trust phone numbers either. Some scams involve calling a phone number to update account information. It may seem legitimate, but it’s just a part of the scam.
  • Use anti-virus and anti-spyware software, along with a firewall. Make sure they are updated regularly.
  • Never email personal or financial information.
  • Closely watch credit card and bank statements for any unauthorized purchases.
  • Call your HR department or whoever is responsible for your company’s online security at the first sign of a phishing scam and report it immediately.


Courtesy of the creative team at Common Craft, here’s a short guide to recognizing and avoiding phishing scams:

Friday, January 9, 2009

Are your employees trained on the new Form I-9?

U.S. employers have less than a month to ensure their organizations are in compliance with the new changes to the Employment Eligibility Verification process (Form I-9).

The U.S. Citizenship and Immigration Services (USCIS) published the new I-9 changes to streamline the work eligibility process on December 17, 2008. The new I-9 form reflects several changes including new employment verification guidelines and a redefined list of acceptable proof of identification documents.

Beginning February 2, 2009, all employers are required to use the revised Form I-9 for verification of new employees and re-verification of existing employees. It is each employer’s responsibility to ensure all employees involved in the hiring process are trained on the latest changes to the new document.

The new Form I-9 includes several modifications that you should cover in your Form I-9 compliance training, including:

  • Using expired documents as proof of identification or work authorization is no longer acceptable.
  • Three documents were eliminated from List A of the List of Acceptable Documents: Temporary Resident Card, and older versions of the Employment Authorization Card/Document.
  • Foreign passports with machine-readable visas for certain citizens of the Federated States of Micronesia (FSM) and the Republic of the Marshall Islands (RMI) were added to List A.
  • The new U.S. Passport card was added to the list of acceptable employment eligibility verification documents.
  • Revisions to the employee attestation section of the Form I-9.

Employers who fail to use the revised I-9 form by February 2, 2009 may be subject to violation fines. Keep your company in compliance by ordering the updated Form I-9 today.

Thursday, November 13, 2008

Employee security training: Spam 101

Security researchers estimate that cyber criminals send between 3,000 and 10,000 unique pieces of malware - viruses and other types of malicious code - a day. The number of attacks on businesses is growing, with the amount of spam in the workplace expected to increase 300% from 2007.

Spam management costs U.S. businesses more than $71 billion annually in lost productivity, about $712 per employee, according to a study released last year by Nucleus Research.

With the rate at which cyber criminals develop malware, security software “really isn’t blocking a heck of a lot,” said Gartner Analyst John Pescatore in a Wall Street Journal article.

As soon as software developers find a way to protect businesses from spam, cyber criminals quickly find a way to get around it.

Until security software works perfectly, there’s only one surefire way for businesses to adapt to internet security problems - training employees on the dangers of spam.

“Make sure individual workers fully understand the value of the data they work with day in and day out, and the techniques that cyber criminals use to try to steal those data. Until then, security software will just be a Band-Aid on a gaping wound,” advises Ben Worthen in a WSJ blog.


Sophos, a developer and vendor of security solutions, advises businesses to follow a set of best practices to defend against viruses, spyware and adware:

  1. Use anti-virus software. Install anti-virus software on every computer in the office and ensure virus definitions are kept up to date. Also remember to protect computers used by employees working from home.

  2. Set filters. Set email filters to block files that often contain malicious code, including EXE, COM, PIF, SCR, VBS, SHS, CHM and BAT file types. Block files with multiple extensions, for example LOVE-LETTER-FOR-YOU.TXT.VBS. Route any code sent to your organization through your IT department to check and approve that the files are safe.

  3. Educate workers on the latest virus threats. Stay up to date on the latest virus threats and educate employees on the dangers of spam so everyone knows what to look out for.

  4. Use firewall protection. Every computer in your organization connected to the outside world should be protected from internet threats with firewalls, including computers used by remote workers.

  5. Install the latest software patches. Stay up-to-date on the latest patches issued by software developers that resolve security loopholes and issues.

  6. Develop a back-up system. Make regular backups of important work and company data and store it in a safe location, possibly off-site in case of a disaster.

  7. Establish an anti-virus policy. Develop a company-wide anti-virus policy as a preventative safety measure. Educate workers on the importance of following the policy and who they should go to with security questions.

For a full overview of how to protect your business from the dangers of malware and viruses in the workplace, read Sophos’ full article on ways to defend against viruses, spyware and adware.


Related posts:

Employee security training: How to catch ‘phish’

Disaster planning: Would your company sink or swim?

Tuesday, July 22, 2008

Simple training etiquette: Follow the Golden Rule

As youngsters we were all taught the Golden Rule: “Do unto others as you would have them do unto you.” But now we’re a little older and the Rule is buried underneath everything else on our ‘to do’ lists.

When it comes to employee training, the Golden Rule should be followed every step of the way, from the planning stage through to any follow-up training. By treating others how you want to be treated, your training program will be more effective and enjoyable to attend.

“In this case, ‘Do unto others…’ means don’t bore them, don’t waste their time, and don’t make them sit through a presentation you would hate,” says Barbara Jones at BizCustoms.com.

A well thought out training program will take the employees’ perspective into consideration at every point of the process. Here are some tips to implement the Golden Rule and follow simple training etiquette throughout your program or presentation:

Scheduling. Schedule employee training at a convenient time when employees are least distracted. Sit down with employees to find out the busiest time of the day or if there are important deadlines coming up. Proper scheduling will reduce the number of disgruntled attendees and increase the number of focused, engaged employees.

Location. Keep training in house and during work hours. Not only will in-house training save you from paying travel costs, it’s also less burdensome on employees. Off-site or after-hours training requires employees to rearrange their outside schedules and creates resentment. Make training as convenient as possible to attend.

Train vs. lecture. We all know how exciting it can be to listen to someone read from a slide presentation. Passive listening, like hearing a speech or lecture, usually causes boredom. Like we said last week, get your audience talking and they’ll retain more. Involve employees throughout the training process with practice exercises and conversation for more effectiveness.

Repetition. Most people don’t understand something completely until it is repeated or practiced. The more an idea is repeated, the more chance it has to be retained. Give employees something on paper to reinforce the ideas covered in the training program.

Implementation. Don’t put someone through training and assume they will have no problem implementing the new skills they learned on their own. Create opportunities for employees to practice their new skills as soon as the training is complete. If employees do not have the chance to practice, skills will be lost and your training will have been a waste of time.



When designing your next employee training program, take a step back to think about how you would feel as a trainee and how you would like to be treated. Remember those feelings during the planning process, along with some simple training etiquette, and you’ll see the difference in your employees the next time they complete training.

Wednesday, April 23, 2008

Employee security training: How to catch ‘phish’

Do your employees know how to spot phishing when they see it or even know what it is?

Phishing is a popular scam where Internet crooks spam potential victims to gain access to personal financial information. These ‘phishers’ use clever ways to lure unsuspecting victims into handing over credit card information, bank account numbers, passwords and other personal information. It is a criminal activity that can result in identity theft, financial theft or malicious computer viruses.

This type of fraud isn’t limited to sweet old ladies. Recent major scams have gone after the big fish - corporate CEOs.

Earlier this month, scammers sent emails telling CEOs that their company was being sued in federal court and to follow a link that will download the court documents. After downloading malicious software disguised as a special browser plug-in, the criminals gained access to everything on the victim’s computer.

This technique is a new form of “spear phishing” where phony emails are written as if they were coming from within the organization, or from a sender with close ties to the organization, like U.S. federal courts. Many times these emails contain believable information, complete with the victims name, company name and phone number.


How do you keep your company safe?

Make sure to provide thorough employee security training with tips on how to avoid phishing scams and what to do if someone suspects they are a victim.

The federal government created a resource, OnGuardOnline.gov, to provide the public with information on a variety of Internet scams.

They offer some tips on how not to get ‘hooked’ by a phishing scam:

  • If you receive a message asking for personal or financial information do not reply to the email or click on any links.
  • Some scams involve calling a phone number to update account information. While the phone number may look legitimate, with a correct area code, the number you call will draw you right into the scam.
  • Use anti-virus and anti-spyware software, along with a firewall. Make sure all are updated regularly. Without these tools, there could be software on your computer tracking every move you make and you wouldn’t know it.
  • Never email personal or financial information.
  • Keep a close eye on credit card and bank statements for unauthorized charges.
  • Call your HR department or whoever is responsible for online security and report the email immediately.


Brought to you by www.gneil.com