Newsletter:

Skip Navigation LinksHome > News > Security > Poor HR leaves firms open to security risks

Poor HR leaves firms open to security risks

By Robert Jaques
9 March 2007 08:24AM
Tags: poor | hr | leaves | firms | open | security | risks

'Employee education gap' putting employers and employees in danger.

Small UK businesses are leaving themselves vulnerable to unnecessary IT security risks because of poor human resources practices, it was claimed today.

A poll of over 1,000 SMEs (50-250 employees) across Europe conducted by McAfee found that only 32 percent have IT security as an aspect of employee induction.

The research indicated that the UK leads the induction drive, and that British businesses are the most likely to hold induction sessions for all employees.

However, more than a third of businesses in France and Italy do not have inductions for all employees.

Some 70 percent of respondents believe that employers are more sensitive to the risks associated with new employees than they were three years ago.

However, only 39 percent of businesses have guidelines for employees on email content/language, 28 percent for the use of portable storage devices and 23 percent for laptop use.

In the majority of cases where security issues are raised, most businesses feel that the end user is more culpable than the employer, highlighting serious implications for employee and employer liability.

For example, 55 percent felt that an employee should be held responsible for a personal email that spreads a virus on the company network.

Similarly a stolen laptop is also seen as the responsibility of the employee by 67 percent of respondents.

The research warned that current approaches may be "misguided" in terms of culpability for security breaches.

Although employee actions may result in security breaches, the employer is often ultimately responsible for the processes and conditions that surround security incidents.

Greg Day, security analyst at McAfee, said: "While many businesses make a priority of employee induction, many are failing effectively to cover a major part of any employees working life: their PC and internet usage policies.

"Companies are failing to capture the opportunity presented by new starters to instil a sense of vigilance and security into the workforce.

"This oversight, coupled with a clear lack of enforcement, increases the risk of new employees consciously or inadvertently breaching corporate security protocols."

Typically, inductions are shortest in Germany where 36 percent of businesses complete full HR inductions in fewer than three hours.

At the other end of the spectrum, Spanish inductions are most likely to take more than two days (32 percent of respondents), while UK and French businesses strike a balance at half a day.

Billy Hamilton Stent, a director at consultancy LoudHouse Research which undertook the study, said: "The induction process provides an ideal opportunity to engender a vigilant response to information security for end users. 

"It is not a case of issuing a list of dos and don'ts, but more a process of establishing trust, security and clear working procedures that reduce employee and employer risk. It is unfortunate that only a minority of businesses see it in this way."

Copyright © 2008 vnunet.com

   


Ads by Google



Product Reviews

Star Rating
For this review, I decided to combine these products into a single group of their own. Please keep in mind...
Star Rating
The netVigilance SecureScout EagleBox SP 2.0 is a highly comprehensive vulnerability management product.
Star Rating
The StillSecure VAM appliance is serious vulnerability management in a single device.
Star Rating
Last year for this Group Test, we saw the software version of this product, so this year we were very excited...
Star Rating
Lumension Security's PatchLink Scan is a fairly robust vulnerability scanner.


TopTopics
(6176) -  broadband
(5314) -  telstra
(3243) -  network
(2711) -  data
(2544) -  optus
(2432) -  wireless
(2302) -  iphone
(2055) -  linux
(2031) -  internet
(1965) -  ipv6
(1965) -  isp
(1781) -  internode
(1681) -  microsoft
(1663) -  security
(1521) -  mobile