Why do people protect their information
Oct 15th, 2013 by Jesper Kråkhede
As some of you may know, at least those of you that have read my CV, I´m a trained social worker and have a keen interest in psychology. I always find it interesting to understand why some organisations manage to protect their information and why some fails.
I recently came across a report describing why users protect their information:
• They have a personal connection to it
• They truly understand the risk that exposure of the information poses
• The impact of such an exposure affects them directly
What does this mean when you try to educate your users? First of all you need to include your users in the security work and have them understand the information they are working with. It is not only numbers; the information is what makes them have a living.
Second: Include them in the risk analysis so that they understand the risks that are involved. In my models I work with micro risks, a tool that captures the small risks that every user perceive in their daily work.
Third: When making the asset valuation make sure to have them understand the consequences for them if there actually is a breach. Have them understand that a breach means that there is a huge cost and a potential loss of their jobs.