Talk to us Risks to Watch

Stoicism can leave organizations vulnerable to cyber-crime

What is Stoicism?
Every human mind has different nature of thinking process. Each aspect of our life is influenced by our tendencies, habits, preference of comfort zones and … we all wish to avoid risk factors. We always tend to take up safe and easy ways for survival. The Greek philosophers originated the idea of stoicism who analyzed and explained this concept with the philosophy of the military professionals who strive in the battlefield against the enemies till their last breath. Even in adverse conditions when the opponent almost ensures the victory, a true military leader shows the path of survival by assuring that everything would be alright. The end result of the battle is secondary in this aspect, but the act of concealing the fear and danger with positive assurance is the stark reality of stoicism.

How is it relevant to IT security?

Any massive data breach incident in any renowned organization draws a lot of negative attention from customers and governing authorities — and even investors nowadays. Typically, data breach affected organizations try to hide their security negligence and loss by downplaying the incident. Here lies the significance of stoicism as discussed above (ideation of the military leader). They rush to say that all is well and nothing to worry about.

Organizations get goosebumps thinking about the financial and reputational consequences of any data breach. Hence, those organizations portray the cyber incident as one of the stray incidents which do not have much impact on the business process. That is how stoicism is relevant to IT security today. And ultimately, it badly impacts the security posture because this adamant attitude bars any scope for IT security enhancement.

How to ensure stoicism does not create upheaval in IT infrastructure
There are several effective ways organizations can follow to overcome the effect of stoicism. While the growing number of cyber incidents is prompting global organizations to up the ante for better security posture, the psychological blockage of stoicism is an ignored aspect. This can be controlled by implementing the following measures:

  • Frequent audit of the IT security infrastructure
  • Developing and following a robust IT security policy that would help the security and risk management team to comply with ascribed IT industry security mandates
  • Harnessing a mindset within an organization about what is expected and what is to be avoided to promote safe browsing
  • Refraining from any activities that might increase risks of uncontrolled access in the network
  • Staying abreast with the latest IT security vulnerabilities

ARCON is a leading enterprise risk control solutions provider, specializing in risk-predictive technologies. ARCON | User Behaviour Analytics enables to monitor end-user activities in real-time. ARCON | Privileged Access Management reinforces access control and mitigates data breach threats. ARCON | Secure Compliance Management is a vulnerability assessment tool.

Resistance to cultural change plays spoilsport to strengthen enterprise IT security (Part – 2)

How can we overcome cultural resistance?
In our previous blog (posted on 30th August 2019) we discussed how resistance to IT cultural changes can obstruct organizations from strengthening their enterprise security posture. In this blog, we are going to discuss five ways how this crisis situation can be handled effectively by assuaging the workforce’s fear and misconceptions.

Meeting/ Brief Training: It is extremely important for an organization to provide details about the changes employees are going to face. Each and everyone working in the team should be aware of the IT security risks, do’s & don’ts of the action, what restrictions should be taken while accessing privileged accounts, what IT administrators should minitor. Today, organizations can’t depend only on Anti-Virus or Firewalls to prevent data theft; instead robust risk preventive and risk predictive solutions like Privileged Access Management (PAM) is required for advanced security. Most of the times it is seen that organizations ignore this training part and directly announce the functional changes which creates ambiguities among the employees.

Assurance for betterment: At any cost, organizations should provide complete assurance about the benefits of the changes to the employees. Which role would be excluded/ included; what would be the advantage; which new system they will have to adapt to – all these factors should be made clear so that the employees should be assured about their work and career. Once new IT security solution is implemented by the security team, organizations should ensure a session on the advantages of the solution and how it can ensure betterment of the entire IT operations. Not only that, the administrative efficiency which can be enhanced by the deployment of new IT security solution (like PAM), should be explained to the employees in details so that they know the importance of a change.

Resolve Confusion & Conflicts quickly: It is highly imperative to inculcate a good team spirit among the employees which can erase conflicts and confusions in a better way. During the transition period, the personal anxieties that arise among the employees can be resolved in an effective way if the other members (who have understood the benefits of transition) in the team take initiative to make things clear. Frequent team meetings and team bonding sessions help to understand and appreciate each other in a better way, especially if the transparency of the transition is conveyed systematically.

Remain Positive, Supportive & Trustworthy: It is highly essential for organizations to support and edify a positive leader who inspires free thoughts, galores creativity and encourages honest communication for the development of the team. Employees normally expect team leaders or managers to handle the functional changes. Inspirational positive leaders create a habit where changes are accepted as challenges and the zeal to perform germinates. It even increases the confidence among the employees that the changes would offer better security to the enterprise assets.

Inculcate a Learning Attitude: Everything in the world changes. It is inevitable and unavoidable. Thus, resisting changes is indirectly resisting the reality. Organizations can take initiative to inculcate the learning attitude among the employees which can eventually help them to accept anything new. Thus it is said, “When a surfer gets tense riding a wave, he falls; when a leader gets tense adapting to change, he fails.” Hence, a learning mindset is the key.

Counselling: This would require during extreme situations where employees resist changes in a nasty way and it influences the rest of the operations badly. In a way, organizations should take the initiative of changes in a logical pattern so that this situation does not arise at all. The suggestions mentioned above once implemented can refrain the organization from falling into such situations when counselling would require.

Bottom Line: Resistance to changes is prevalent in human blood. Changing this notion is almost a herculean task. Hence, instead of allowing the employees to reach that state of mind, organizations should concentrate on the above mentioned steps to smoothen the business processes and ensure the security of enterprise assets.

ARCON is a leading enterprise risk control solutions provider, specializing in risk-predictive technologies. ARCON | User Behaviour Analytics enables to monitor end-user activities in real time. ARCON | Privileged Access Management reinforces access control and mitigates data breach threats. ARCON | Secure Compliance Management is a vulnerability assessment tool.