2016
DOI: 10.1108/ics-10-2014-0065
|View full text |Cite
|
Sign up to set email alerts
|

The pathway to security – mitigating user negligence

Abstract: Purpose Through the use of effective training techniques and exercises, employees and users can be educated on how to make safe information security decisions. It is critical to the success of a total information security program that users are trained properly as they are a major layer of defense against malicious intent. The current methods of training people about information security are failing, and the number of user-related breaches increases every year. Design/methodology/approach By researching and … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
15
0

Year Published

2018
2018
2023
2023

Publication Types

Select...
5
2
1

Relationship

0
8

Authors

Journals

citations
Cited by 14 publications
(15 citation statements)
references
References 2 publications
0
15
0
Order By: Relevance
“…PricewaterhouseCoopers (2017) reported that current employees remain as the top source of security incidents with 30 per cent of such incidents were caused by current employees. Another report revealed that 64 per cent of data breaches were due to employees’ behaviour and system glitches (Kennedy, 2016). A survey by Kaspersky Lab (2017) showed that 59 per cent of information security incidents were caused by careless or uninformed employee actions.…”
Section: Introductionmentioning
confidence: 99%
“…PricewaterhouseCoopers (2017) reported that current employees remain as the top source of security incidents with 30 per cent of such incidents were caused by current employees. Another report revealed that 64 per cent of data breaches were due to employees’ behaviour and system glitches (Kennedy, 2016). A survey by Kaspersky Lab (2017) showed that 59 per cent of information security incidents were caused by careless or uninformed employee actions.…”
Section: Introductionmentioning
confidence: 99%
“…The consequence is that users might act to circumvent the ritual (Blythe et al, 2013). Awareness and training programmes are the standard organisational response to this (Yildirim, 2016), but the effectiveness of such drives is patchy (Banfield, 2016;Kennedy and Kennedy, 2016). Training does not work because it can not overcome a reluctance that stems from previous negative experiences with unattractive software.…”
Section: Beauty In Securitymentioning
confidence: 99%
“…Previous research has shown that well designed end-user security education can be effective in mitigating against IT infrastructure issues [91,92,93]. This could be in the form of web-based training materials, contextual training, and embedded training to enhance users' ability to avoid attacks.…”
Section: User Education and Engagementmentioning
confidence: 99%