Newsletter:

Skip Navigation LinksHome > News > Security > Untrained users highlighted as security risks

Untrained users highlighted as security risks

By Phil Muncaster
31 March 2008 01:12PM
Tags: untrained | highlighted | security | risks

Businesses are giving users greater freedom with corporate IT systems, according to a recent report, but many of those users lack the necessary security training.

The study, conducted by a consortium, led by PricewaterhouseCoopers, on behalf of the Department for Business, Enterprise & Regulatory Reform (BERR), found that firms are placing greater trust in their staff.

Seven out of eight firms now have information security policies in place according to newly released findings from the annual Information Security Breaches Survey (ISBS). Those policies are loosening controls over users.

Fifty four percent said they allow staff to remotely access systems – a rise of 19 percent from last year's study – while the number of businesses restricting internet access to some staff only has nearly halved from 42 percent to 24 percent.

Training staff in security basics is an essential part of any information security strategy, argued Martin Smith, chief executive of The Security Company. "The industry is dominated by technology and technologists … but I've never seen a computer commit a crime, it's always people," he argued.

Smith added that long term behavioural change programmes are the best way to mitigate risk in this area, but most firms are unable to find budget to support such initiatives because "they're hard work and fairly intense"

The importance of security awareness was also highlighted in new figures from security certifications organisation ISC2. The 2008 ISC2 Global Information Workforce Study, set for full release in April, asked 6,523 certified professionals about the importance of certain skills. It found that 90 percent said a good understanding of security and communication skills are the most important.

itweek.co.uk @ 2008 Incisive Media

   


Ads by Google





Product Reviews

Star Rating
The ForeScout CounterACT was the device which took the most time to install and configure.
Star Rating
The Aventail EX-1600 is a high-end SSL VPN designed for the needs of medium to large enterprises.
Star Rating
The Sophos NAC Advanced product is a well-designed offering which balances the need for ease of...
Star Rating
The Kerio WinRoute Firewall is an interesting product for this category.
Star Rating
The BiGuard S6000 extends the network to the remote user with features such as Network Extender, Transport...
ITNews NetSeminars
TopTopics
(18146) -  iphone
(5926) -  telstra
(5879) -  broadband
(4812) -  online
(4458) -  australia
(3878) -  accc
(3451) -  government
(2709) -  hack
(2702) -  computer
(1956) -  microsoft
(1794) -  information
(1696) -  smartphone
(1633) -  security
(1531) -  data
(1516) -  apple