Picture of Padlock
Businesses must to more to educate employees

Businesses fail to educate staff on security

Research says employees may be responsible, but employers are liable

Written by Tom Young

Most businesses feel the end user is more culpable than the employer for a security breach, according to research by vendor McAfee.

Some 55 per cent of respondents feel an employee should be held responsible for a personal email that spreads a virus on the company network. Similarly a stolen laptop is also seen as the responsibility of the employee by 67 per cent of those surveyed.

But although employee actions may result in security being breached, the employer is often ultimately responsible for the processes and conditions that surround security incidents.

Greg Day, security analyst at McAfee, says businesses do not set strict enough guidelines for their employees.

'Whilst many businesses make a priority of employee induction, many are failing to effectively cover a major part of any employees working life, their PC and internet usage policies,' he said.

'Companies are failing to capture the opportunity presented by new starters to instil a sense of vigilance and security into the workforce. This oversight, coupled with a clear lack of enforcement increases the risk of new employees either consciously or inadvertently breaching corporate security protocols,' said Day.

The research suggests employers vagueness over, and in some cases non-existence of, sufficient induction processes, are leaving employees unfairly exposed.

'Some businesses clearly talk the talk but are not walking the talk by building business processes in line with documented policy. When it comes to induction, some countries consider themselves to have processes in place but are often not supported by readily available policy documentation,' said Day.

Court cases in Europe, including a recent one in Germany, have resulted in hefty settlements for employers as a result of employee email messages which recipients consider defamatory or which breach confidentiality or client contract.

  • Have your say
  • Send to a friend
  • Print this
  • Share

Tags:

reader comments

related articles

Picture of John Meakin at Standard Chartered bank

UK security found wanting

UK business lags behind US on approach to data protection, says survey 22 Feb 2007

 

Security threat growing in UK

But many users are ignoring best practice advice 07 Jul 2004

Senior UK execs pessimistic about IT security

The glass is half empty for the UK's directors and chief executives 19 Apr 2006

UK banks slammed for poor IT security

Router vulnerabilities create a 'turkey shoot' for hackers, warns consultant 21 Aug 2003

Microsoft clobbers four illegal software dealers

Quartet of UK dealers caught out in Microsoft's counterfeit software crackdown 03 Dec 2009

Network Solutions suffers crippling data breach

Web hosting firm admits 570,000 credit card holders could be affected 27 Jul 2009

Warranty fraud on the rise in channel

Vendors are facing a growing threat from the relatively unknown issue of warranty abuse, according to AGMA 20 Oct 2009

related whitepapers

today's top stories

Police hunt for moles with security software

Lancashire Constabulary to monitor data input of 7,000 staff in bid to prevent intelligence leaks 09 Feb 2010

PaperlinX outsources IT and comms to Bull and BT

Paper company spends €22m on five-year deal for desktop management, helpdesk and datacentre services 05 Feb 2010

Social tools take KM to a new level

Technology expert David Tebbutt explains how – and why – organisations should integrate social networking tools into their knowledge management strategy 02 Feb 2010

EDS court defeat puts vendors on their guard

BSkyB’s victory in a long-running court case against EDS has serious implications for the IT industry 02 Feb 2010

Law firm monitors web traffic violations

Bucks declining global security appliance sales with unified threat management (UTM) platform deployment 01 Feb 2010

Advertisement

Security: The New Face of Intrusion Prevention
An outline of traditional IPS functionality, modern developments and how IPS can be deployed easily.

UK businesses’ attitudes to Cloud Computing revealed

Features results from a survey of over 200 Computing readers.

Advertisement

Keep up to date with the latest products, services and technologies from the world's leading IT companies; ITHound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

Latest poll

Internet Explorer 6

Internet Explorer 6

Following recent concerns about the security of Internet Explorer 6 are you planning to phase it out?

View poll results

Latest audio and video articles

Tony McAlisterVideo

Video Q&A: Tony McAlister, CTO, Betfair - Part one

On changing the skills development strategy at the online gambling firm - part one of a two-part video interview 05 Nov 2009

Video

Nokia shows upcoming handset technologies

Mobile phone features of tomorrow take the stage 21 Oct 2009

Latest in-depth articles

Analysis

Police hunt for moles with security software

Lancashire Constabulary to monitor data input of 7,000 staff in bid to prevent intelligence leaks 09 Feb 2010

Businessman with eye patch, dagger and tie round head, sitting at laptopFeatures

Are you sure you're not a pirate?

It is alarmingly easy for an IT leader to unwittingly exceed the scope of a software licence, and the chances of being caught out have never been greater, as technology lawyers Mark Weston and Paul Gershlick explain 09 Feb 2010

Primary Navigation