Share

Strong firewall? Don't feel so secure

Stellenbosch - Most companies are focusing primarily on physical cyber security barriers like firewalls, while forgetting the potential risk posed by their employees' behaviour, says Gundu Tapiwa of the Sol Plaatje University in Kimberley.

"Humans hold the keys for cyber criminals to unlock the door to your company that you think you have locked sufficiently," he cautioned during a presentation at the 14th International Conference on Cyber Warfare and Security, hosted by the University of Stellenbosch and the CSIR.

Curiosity killed the cat

Research shows that about 49% of employees would fall into the "naïve" category, Tapiwa said.

Furthermore, he added, his own research found that many employees who indicated during a cyber awareness campaign that they would act in the appropriate manner to avoid a cyber security breach, still went ahead and took risky actions under test conditions.

For instance, when he placed random software in plastic bags at a business, almost all the employees ended up inserting the flash discs into the company computers to see what they contained.

"You cannot totally eliminate risk, but you have to try to limit it to an acceptable extent," he said.

His research further showed that the effectiveness of a cyber security awareness campaign – aimed at giving employees knowledge only – would still be questionable.

Non-compliance by employees still persisted even after they had completed the campaign, he found.

Get around the human factor

"Companies should, therefore, find ways to get the human factor to behave in a cyber secure way," said Tapiwa.

"Employers should not just assume that employees will follow the prescribed behaviour. I tested them and, although their intentions sounded good, in the end their actual behaviour was different – risky."

That is why, in his view, there should be some form of consequence for employees who put the company at risk with their cyber interactions. It could even include impacting their salaries, he believes.

"My research showed the cyber challenges caused by employee behaviours – whether they behaved in a cyber risky way knowingly or unknowingly.

"And even if they were aware that they were behaving in a cyber risky way, it seems many still might not want to change their behaviour," said Tapiwa.

We live in a world where facts and fiction get blurred
Who we choose to trust can have a profound impact on our lives. Join thousands of devoted South Africans who look to News24 to bring them news they can trust every day. As we celebrate 25 years, become a News24 subscriber as we strive to keep you informed, inspired and empowered.
Join News24 today
heading
description
username
Show Comments ()
Rand - Dollar
19.07
+0.5%
Rand - Pound
23.60
+1.0%
Rand - Euro
20.32
+0.3%
Rand - Aus dollar
12.24
+0.5%
Rand - Yen
0.12
+0.4%
Platinum
943.20
-0.8%
Palladium
1,035.50
+0.6%
Gold
2,388.72
+0.4%
Silver
28.63
+1.4%
Brent Crude
87.11
-0.2%
Top 40
67,314
+0.2%
All Share
73,364
+0.1%
Resource 10
63,285
-0.0%
Industrial 25
98,701
+0.3%
Financial 15
15,499
+0.1%
All JSE data delayed by at least 15 minutes Iress logo
Company Snapshot
Editorial feedback and complaints

Contact the public editor with feedback for our journalists, complaints, queries or suggestions about articles on News24.

LEARN MORE
Government tenders

Find public sector tender opportunities in South Africa here.

Government tenders
This portal provides access to information on all tenders made by all public sector organisations in all spheres of government.
Browse tenders