{
  "title": "Should You Punish Employees for Cybersecurity Violations?",
  "date": "2020-10-23",
  "author": "Omer Kaan Aslim",
  "featured_image": "/assets/images/blog/2020/10/hanging.jpg",
  "content": {
    "full_html": "<div class=\"row mb-4\">\n\t<div class=\"col\">\n\t\tCompanies create information technology acceptable use policies to lay out what is an acceptable and unacceptable use of their systems. This protects employers, employees, and clients. So what do you do when an employee violates your security policies or makes a cybersecurity mistake?\n\t</div>\n</div>\n\n<h2>Common IT Security Policy Violations</h2>\n\n<div class=\"row mb-4 text-center\">\n\t<div class=\"col\">\n\t\t<img class=\"img-fluid blog-img\" src=\"/assets/images/blog/2020/10/piratebay.jpeg\" alt=\"Pirating\">\n\t</div>\n</div>\n\n<div class=\"row mb-4\">\n\t<div class=\"col\">\n\t\tSome of the most common security policy violations I have observed are employees pirating movies, visiting NSFW sites, abusing their admin privileges to instal unauthorized software such as games onto their work computer, using personal cloud services to store corporate files, and connecting unauthorized devices to the network. The policy violations I mentioned are often committed intentionally, the employee knows that they are violating company policy. \n\t</div>\n</div>\n\n<h2>Common Security Mistakes Employees Make</h2>\n\n<div class=\"row mb-4 text-center\">\n\t<div class=\"col\">\n\t\t<img class=\"img-fluid blog-img\" src=\"/assets/images/blog/2020/10/PhishingTrustedBank.png\" alt=\"Phishing\">\n\t</div>\n</div>\n\n<div class=\"row mb-4\">\n\t<div class=\"col\">\n\tNot all security policy violations are intentional. An employee may let their guard down and let someone into the office who isn’t supposed to be let in. An employee may accidentally access a NSFW site and a manager may not actually be aware that using an unapproved cloud storage service for their new project is a security violation.\n\t</div>\n</div>\n\n<h2>Should You Punish Employees?</h2>\n\n<div class=\"row mb-4 text-center\">\n\t<div class=\"col\">\n\t\t<img class=\"img-fluid blog-img\" src=\"/assets/images/blog/2020/10/punishment.jpg\" alt=\"Punishment\">\n\t</div>\n</div>\n\n<div class=\"row mb-4\">\n\t<div class=\"col\">\n\tSo what happens when an employee violates a security policy? Some say that punishing an employee could possibly turn them into an insider threat. They may feel resentment for the punishment and may cause more damage.\n\t</div>\n</div>\n\n<div class=\"row mb-4\">\n\t<div class=\"col\">\n\tWhat if the defendant is a repeat offender? Where do you draw the line? How many times should an employee be allowed to fall for a phishing attack? How many times should an employee be able to get away with using their personal laptop for work? What if the employee downloaded child porn onto their work computer? These are all difficult questions and there isn’t a set answer that covers all scenarios.\n\t</div>\n</div>\n\n<div class=\"row mb-4\">\n\t<div class=\"col\">\n\tDecisions on punishment or sanctions should be left to human resources and upper management. It isn’t security’s place to play judge, jury, and executioner but it is security’s job to document incidents. \n\t</div>\n</div>\n\n<h2>What Companies Should be Doing</h2>\n\n<div class=\"row mb-4 text-center\">\n\t<div class=\"col\">\n\t\t<img class=\"img-fluid blog-img\" src=\"/assets/images/blog/2020/10/training.jpg\" alt=\"training\">\n\t</div>\n</div>\n\n<div class=\"row mb-4\">\n\t<div class=\"col\">\n\tIf an employee falls for a phishing attack or unintentionally commits a security violation then the first action security should take is to provide the user with more training. You don’t need to report anything to their manager just yet as this can embarrass the employee. If they keep making mistakes like writing their password on a sticky note, letting strangers into the office, and violating security policies then you need to report the behavior to human resources as the employee is now a threat to the organization. You can provide suggestions to management such as reducing their access to resources and providing more training.\n\t</div>\n</div>\n\n<div class=\"row mb-4\">\n\t<div class=\"col\">\n\tIf an employee keeps committing security violations and is putting the organization at both legal risk and threatening business operations then it's probably best to let the employee go after they have received several warnings.\n\t</div>\n</div>\n\n<h2>Be Flexible</h2>\n\n<div class=\"row mb-4\">\n\t<div class=\"col\">\n\tThe best way to deal with security violations both intentional and unintentional is to be flexible. You want to avoid embarrassing employees and creating a disgruntled employee that becomes an insider threat. You also don’t want employees to think they can get away with everything. Most people are responsible and will take warnings seriously especially if they are given an informative explanation.\n\t</div>\n</div>\n\n",
    "plain_text": "\n\t\n\t\tCompanies create information technology acceptable use policies to lay out what is an acceptable and unacceptable use of their systems. This protects employers, employees, and clients. So what do you do when an employee violates your security policies or makes a cybersecurity mistake?\n\t\n\n\nCommon IT Security Policy Violations\n\n\n\t\n\t\t\n\t\n\n\n\n\t\n\t\tSome of the most common security policy violations I have observed are employees pirating movies, visiting NSFW sites, abusing their admin privileges to instal unauthorized software such as games onto their work computer, using personal cloud services to store corporate files, and connecting unauthorized devices to the network. The policy violations I mentioned are often committed intentionally, the employee knows that they are violating company policy. \n\t\n\n\nCommon Security Mistakes Employees Make\n\n\n\t\n\t\t\n\t\n\n\n\n\t\n\tNot all security policy violations are intentional. An employee may let their guard down and let someone into the office who isn’t supposed to be let in. An employee may accidentally access a NSFW site and a manager may not actually be aware that using an unapproved cloud storage service for their new project is a security violation.\n\t\n\n\nShould You Punish Employees?\n\n\n\t\n\t\t\n\t\n\n\n\n\t\n\tSo what happens when an employee violates a security policy? Some say that punishing an employee could possibly turn them into an insider threat. They may feel resentment for the punishment and may cause more damage.\n\t\n\n\n\n\t\n\tWhat if the defendant is a repeat offender? Where do you draw the line? How many times should an employee be allowed to fall for a phishing attack? How many times should an employee be able to get away with using their personal laptop for work? What if the employee downloaded child porn onto their work computer? These are all difficult questions and there isn’t a set answer that covers all scenarios.\n\t\n\n\n\n\t\n\tDecisions on punishment or sanctions should be left to human resources and upper management. It isn’t security’s place to play judge, jury, and executioner but it is security’s job to document incidents. \n\t\n\n\nWhat Companies Should be Doing\n\n\n\t\n\t\t\n\t\n\n\n\n\t\n\tIf an employee falls for a phishing attack or unintentionally commits a security violation then the first action security should take is to provide the user with more training. You don’t need to report anything to their manager just yet as this can embarrass the employee. If they keep making mistakes like writing their password on a sticky note, letting strangers into the office, and violating security policies then you need to report the behavior to human resources as the employee is now a threat to the organization. You can provide suggestions to management such as reducing their access to resources and providing more training.\n\t\n\n\n\n\t\n\tIf an employee keeps committing security violations and is putting the organization at both legal risk and threatening business operations then it's probably best to let the employee go after they have received several warnings.\n\t\n\n\nBe Flexible\n\n\n\t\n\tThe best way to deal with security violations both intentional and unintentional is to be flexible. You want to avoid embarrassing employees and creating a disgruntled employee that becomes an insider threat. You also don’t want employees to think they can get away with everything. Most people are responsible and will take warnings seriously especially if they are given an informative explanation.\n\t\n\n\n"
  },
  "metadata": {
    "description": "Everyone can agree that breaking the rules should have its consequences but is punishing users for cybersecurity policy violations and  mishaps a good idea?",
    "permalink": "/should-you-punish-employees-for-cybersecurity-violations.json",
    "categories": [],
    "tags": []
  }
}