It Is Not Enough To Merely Realize The Importance Of The Human Element, You Must Be Able To Put An Effective Plan In Place.
The best approach to tackle this problem is as follows:
THE END GOAL
First, we need to consider the end goal. In the case of the human security, the ideal situation is one in which employees are no longer a liability but rather a security asset. In order to reach that goal, it seems we need to take our vulnerable employees and make them undergo a transformation. This transformation is an educational and behavioral change, with a security focus.
THE 3 STEPS TO A SECURE HUMAN
Employees must discover the danger they are in. This is the only way they will be motivated to act and learn. They will not be forced to learn from threats of losing their job, nor will they act in fear of what you tell them. They will be motivated to keep themselves and others safe. Once they see what is out there, employees will act and learn to protect themselves and others.
Employees must also be taught the right way. Content must be simple enough for everyone to understand, but detailed enough so there aren’t burning questions. Education must include rewards and consequences; good progress will be rewarded, while poor performance is punished. Employees will never be perfect, but education is about continually improving.
Finally, the piece that brings everything together, security awareness. This is where, after discovering and being educated about threats, employees start becoming a security asset. Living with an awareness of security allows employees to spot things not system would. What made employees vulnerable, being human, also makes them your best possible defense. Awareness will allow employees to act on their education.
Everything begins and ends with a human. Secure the human and you will have yourself a much more secure system than before. Security will never be perfect, but you will be much better off. Not only will your human be less vulnerable, but employees will act as an extra layer of protection.
The usually targeted, vulnerable human element is now your most valuable security asset.