HRreview 20 Years
This field is for validation purposes and should be left unchanged.
Subscribe for weekday HR news, opinion and advice.
This field is hidden when viewing the form
This field is hidden when viewing the form
Optin_date
This field is hidden when viewing the form

Employees are the new line of defence in cyber security strategy

-

Many organisations are worryingly complacent when it comes to information security assuming that “it won’t happen to me,” while individuals often tend to think “it is someone else’s problem.” But a report from PricewaterhouseCoopers LLP (PwC) explores how organisations should be making employees the first line of defence against damaging security incidents.

Security awareness: Turning your people into your first line of defence suggests that the response of organisations to improving protection and reducing risks has historically been strongly biased towards further investment in technology. In essence, they have been solving what are perceived to be technical issues with technical solutions.

Craig Lunnon, OneSecurity, PricewaterhouseCoopers LLP (PwC), thinks this approach is misguided:

“Technical solutions are too frequently being prescribed for people problems. Although technical defence is vital, systems are inherently vulnerable to both negligent and malicious acts by people. Ignorance, confusion, anger or even curiosity can all give rise to incidents.”

HRreview Logo

Get our essential weekday HR news and updates.

This field is for validation purposes and should be left unchanged.
Keep up with the latest in HR...
This field is hidden when viewing the form
This field is hidden when viewing the form
Optin_date
This field is hidden when viewing the form

 

The report considers whether information security has currently got the right focus, and is backed up by PwC’s 2010 Global State of Information Security Survey, which shows that only 48% of organisations questioned in the UK have an employee security awareness programme, falling behind global leaders – the US (64%) and India and Australia (59%).

Efforts to improve security often create cumbersome processes that get in the way of people doing their jobs. Consequently, they can be tempted to by-pass security controls, so the human element of technical solutions often diminishes the desired effect.

What is required, suggests the report, is a new approach in which an investment in understanding and influencing the behaviours of all those concerned is balanced against continued investment in technology.

The difficulty large organisations often face is that security functions tend to be autonomous, fragmented and isolated while ignorance can provide a false sense of security among a workforce. PwC recommends that better engagement between security teams and the business is needed as well as higher levels of engagement between organisations and employees.

The solution is to invest in people. Make them the first line of defence – rather than the cause – of security incidents. Thus, the return on investment from a strategy that leads people to exhibit new behaviours around information security will exceed misdirected investment in technology-based solutions.

Craig Lunnon, OneSecurity, PricewaterhouseCoopers LLP, said:
“The goal is that all those working for an organisation are alert to risks, will want to act to protect information and will be actively supported in doing so. As the first line of defence, security-aware employees are often best placed to identify a potential breach or weak link. Equally, they can prevent and reduce the impacts of incidents when they do occur.”
Investment in security awareness measures pays for itself many times over and can help in:

  • reducing incidents of theft, loss and fraud;
  • avoiding breaches of law and/or regulation;
  • ensuring continuous availability of business-critical information;
  • protecting brand and reducing the potential for reputational risk; and
  • enabling the use of security as a positive marketing differentiator.


Paul Gray is an entrepreneur and digital publisher who creates online publications focused on solving problems, delivering news, and providing platforms for informed comment and debate. He is associated with HRZone and has built businesses in the HR and professional publishing sector. His work emphasizes creating industry-specific content platforms.

Latest news

Felicia Williams: Why ‘shadow work’ is quietly breaking your people strategy

Employees are losing seven hours a week to tasks that fall outside their core job description. For HR leaders, that’s the kind of stat that keeps you up at night.

Redundancies rise as 327,000 job losses forecast for 2026

UK job losses are set to rise again as redundancy warnings hit post-pandemic highs, with employers cutting roles amid rising costs and economic pressure.

Rise of ‘sickfluencers’ and AI advice sparks concern over attitudes to work

Online influencers and AI tools are shaping how people approach illness and employment, heaping pressure on employers.

‘Silent killer’ dust linked to 500 construction deaths a year as 600,000 workers face exposure

Hundreds of UK construction workers die each year from silica dust exposure as a new campaign calls for stronger workplace protections.
- Advertisement -

Leaders ‘overestimate’ how much workers use AI

Firms may be misreading workforce readiness for artificial intelligence, as frontline staff report far lower day-to-day adoption than executives expect.

Cost-of-living pressures ‘keep unhappy workers in their jobs’

Many say economic pressures are forcing them to remain in jobs they would otherwise leave, as pay and financial stability dominate career decisions.

Must read

Charlie Walker-Wise: How to excel as a leader in business

"The best leaders aren’t always those with the most experience."

Dr Rodrigo Rodriguez-Fernandez: Addressing men’s mental health in the workplace

As cost-of-living pressures, extreme weather-related events and geopolitical tensions persist, many employees are feeling mental health strain.
- Advertisement -

You might also likeRELATED
Recommended to you