"Who, Me?"

In the past two weeks I’ve taught three different security seminars at three different organizations, each time for their security staff. A common trend I’m seeing and that continues to surprise me, and was confirmed at all three events, is that most employees still do not realize they are a target. I thought with all the media attention, both in peoples’ lives and at work, they would realize they have value, bad guys are after them. Based on what I’m seeing that is not the case.That does not bode well when securing the human element. To change peoples’ behaviors we need to engage them, and we will never achieve that first step until they realize they are a target. If you are looking to secure your employees, contractors and staff, the first question you have to answer is do they even realize they are a target? If not, then do not even bother trying to teach them how to secure themselves. Instead explain to them who is targeting them, how and why. Once you have …

Reposted from SANS. View original.