Nearly half of entry-level employees, 46 percent, don’t know if their company has a cybersecurity policy, according to a new survey from Clutch, a B2B research firm.
Research also suggests that more communication and training on cybersecurity policies are needed for employees.
Threats Are Real
In addition, the survey finds that employees at all levels of an organization are probably unaware of the IT security threats their companies potentially face.
Nearly two-thirds of employees surveyed, 63 percent, say they don’t know if the quantity of IT security threats their companies face will increase or decrease over the next year. Additionally, among entry level employees, 87 percent say they don’t know if the number of threats will shift in the next year.
IT security experts are quick to point out that employees’ lack of awareness puts companies at risk for IT security breaches.
“Attacks will be more frequent, more voracious, and more sophisticated in breaking through any protection you can put in place,” said Steve Scott-Douglas, CIO of Ciklum, a global software engineering and solutions company.
Lack of Awareness
The survey also finds that employees are less likely to recognize IT services as the primary area of security vulnerability at their company. Instead, they cite theft of company property as the primary threat to company security, ahead of unauthorized information and email phishing scams.
To increase awareness of IT security issues among employees, experts recommend that all companies maintain a “top-down” cybersecurity policy.
Employee awareness of IT security issues should be driven by a company’s executive leadership. When company leaders emphasize and communicate IT security throughout their organization, their employees are more aware and prepared for threats.
“The sheer act of taking the time to put a policy in place is the first step in going from the unconscious incompetence debate around [security] to then build up your competence and become aware of the threats and take those threats very seriously,” said Scott-Douglas.
Empowering Employees
According to Clutch, employees of companies with a cybersecurity policy are more likely to:
- Feel prepared for a cybersecurity threat
- Accurately survey the number of IT security threats their company will face
- Understand IT services as the primary security vulnerability for their company
One way companies can drive awareness is through security training during new employee onboarding. Companies tend to offer IT security onboarding programs to higher-level employees only, which may account for the greater awareness and feeling of preparedness this group has regarding IT security threats.
Providing IT security onboarding for all employees can narrow the IT security knowledge gap between entry-level and higher-level employees and help ensure organizations as a whole are more aware and prepared for security issues.