CYBERSECURITY REVIEW8 AUGUST 2024IN MY OPINIONOctober is the month dedicated to Cybersecurity Awareness, an initiative launched by the Cybersecurity and Infrastructure Security Agency (CISA) and the National Cybersecurity Alliance (NCA) back in 2004. The idea behind the month is to provide continuous awareness to the public and businesses on how to protect themselves and their data from being compromised. This is a great initiative and one that needs to continue, but, we need to take all the effort we put into this month and continue the awareness indefinitely. Cybersecurity Awareness Forever.Statistics continue to show that `we', the human component of cybersecurity, continue to be one of the weakest links. One of the most recent statistics I like to reference is from the Verizon 2022 Data Breach Investigation Report (DBIR) that states "82 percent of breaches involved the Human Element, including Social Attacks, Errors and Misuse." This is extremely alarming and should be enough data to realize that we have a serious problem at hand, and we need to do a lot better as cybersecurity professionals to continue to raise awareness. On the flip side, we also need to continue to improve our cybersecurity posture with strategies like Zero Trust Architecture (ZTA) that uses a multi-layer security approach.Because of this, we need to reassess our cybersecurity awareness, training, and testing programs. Traditionally, this type of program may not have existed, may have been a one-time onboarding requirement, or a one-time annual event because of an audit requirement. Unfortunately, this is not good enough and we need to evolve our user awareness, training, and testing programs to a much higher standard. This program should be its own THE EVOLUTION OF CYBERSECURITY AWARENESS, TRAINING, AND TESTINGMark DunkerleyBy Mark Dunkerley, Chief Information Security Officer, The Coca-Cola Company
<
Page 7 |
Page 9 >