Improving Security by Reducing Human Error

Security breaches are most commonly caused by human error. To improve security, I believe every company should offer a baseline security training focusing on the most common points of failures. This training should be completed before an employee is able to access the companies database. Companies should also have security policies in place that should be briefed before access. With the knowledge of best practices and possible consequences of failure to comply, employees will likely be mindful of their computer ettiquette knowing they will be held accountable for misconduct.

  As a baseline, common phising and social engineering attacks should be identified and their should be several examples available were employees are required to discern possible attacks to real life inquiries. Securely logging in and off of personal accounts and databases should also be priority. Computers within areas of public traffic should require badges or practice need-based logging in.  Lastly, a formula for making secure passwords should be instilled. Passwords should not be predictable or easy to guess. Policy should require a minimum of 12-16 characters and include lower case letters, upper case letters, special characters and/or numbers for safe practice. In addition to strong, secure passwords companies should aim to require passwords be changed every “X” amount of months.

You Missed