Firewalls, encryption software, passwords and other security measures are essential for businesses. But keeping confidential data safe requires more than advanced technological tools. As is so often the case, such tools are only effective if used consistently – and only when coupled with good security habits on the part of users.
There have been enough news reports about workers leaving company laptops in taxis or losing flash drives filled with sensitive data to suggest that people are the weak link in the security chain for many companies. This does not have to be the case, however. By raising your staff’s awareness of data safety issues and encouraging them to make a few simple changes in their behavior, you can close any potentially serious gaps in your company’s data security system.
Password protection
In choosing passwords, many people opt for easy-to-remember nouns, such as the name of their high school, family pet or first child. The problem with this practice is that hackers use password-cracking software, easily downloaded from the Internet and try any word in the English language for a fit, including proper nouns. It’s essential, therefore, that you encourage your employees to adopt passwords that mix letters, numbers and symbols in a random code.
There’s an unfortunate downside to this practice, however – most of us have trouble remembering strings of nonsensical characters. As a result, your employees may engage in another habit that undermines security: posting their passwords on desktop monitors or taping them to the underside of keyboards.
This, of course, defeats the purpose of having secret passwords. Ask your staff to memorize their passwords. If this is not feasible, suggest they keep their passwords in a locked drawer or on their person at all times.
Work-space security
Lack of work-space security is a significant problem for many companies, particularly those with open floor plans and cubicles without doors. Fortunately, employees have a great deal of control over their individual spaces. The key is to get them to exercise this control consistently and completely. Consider these safe-workspace practices:
• Don’t let co-workers log on at your workstation or use your access codes or passwords.
• Log off your desktop when you are away from your desk for an extended period – even if it’s a one-hour break for lunch.
• Don’t leave confidential paper files lying on your desk. Keep them in locked desk drawers or file cabinets. Similarly, do not leave portable devices, such as PDAs or USB drives, in the open or in unsecured drawers.
To encourage compliance, you might offer a prize – perhaps a gift certificate or a modest one-time cash bonus – to employees who keep their workspaces secure.
Loose lips sink companies
The indiscrete mention by employees of confidential or privileged information in e-mails, social networking sites, chat rooms or personal blogs is another area you may need to address. Online employee activity can be easily monitored at the office – it’s what happens away from the workplace that can undermine security.
For this reason, you may want to develop rules that clearly spell out the types of information that employees may not share – either with colleagues or with contacts outside of the company. To ensure that employees understand what constitutes a security breach, offer hypothetical examples, such as the forwarding of e-mails that contain sensitive information or blogging about new product development or competitive data.
The rules should also address what will happen if employees deliberately or inadvertently divulge confidential information about the company or its employees, clients or customers.
Remote control
Discourage employees from logging onto the company intranet from public computer terminals, such as those in cafes or airports. Hackers can follow them onto such terminals, “skim” their passwords and infiltrate the company’s network.
Regarding the use of portable devices, such as laptops, PDAs and flash drives, instruct employees to consistently follow these guidelines:
• With PDAs, use encryption and passwords, and disable the automatic wireless connection function.
• Use only USB drives with built-in encryption to minimize data exposure if the device is lost or stolen.
• Add password-only access and encryption software to notebook computers. Employees should also lock down the USB ports on their laptops to prevent a digital thief from plugging in a flash drive and siphoning away confidential files.
In some cases, it may be easier to limit employees’ access rather than try to change their behavior. To this end, you may want to implement a comprehensive electronic communications policy that manages staff access to files, databases and corporate networks, as well as their use of electronic communication devices. The policy should also contain guidelines about the downloading of company files to portable USB drives or other devices, and specify the consequences of unauthorized access.
It typically takes time to effect across-the-board behavioral changes within organizations, particularly when it comes to habits around data protection. But the old saying, “an ounce of prevention is worth a pound of cure,” is apt when addressing security issues. By taking the time now to help your employees adopt better cyber practices, you will help your company avoid problems and you will enjoy greater peace of mind. •
Luke Howarth is a regional manager for Robert Half International.
No posts to display
Sign in
Welcome! Log into your account
Forgot your password? Get help
Privacy Policy
Password recovery
Recover your password
A password will be e-mailed to you.













