Personnel Training: A Critical Third Step in Cybersecurity

The best cybersecurity plan is only as good as the individuals tasked with carrying it out.

To get better cybersecurity results, companies have started creating dedicated departments or teams within the IT department that are responsible for cybersecurity.
To get better cybersecurity results, companies have started creating dedicated departments or teams within the IT department that are responsible for cybersecurity.
Getty

A recent ransomware attack in the US that shut down a major oil pipeline to the East Coast has highlighted the severity and outcome of these types of attacks. An AP article covering the event said that Commerce Secretary Gina Raimondo pointed to ransomware attacks as “what businesses now have to worry about,” and that she will work “very vigorously” with the Department of Homeland Security to address the problem, calling it a top priority for the administration. “Unfortunately, these sorts of attacks are becoming more frequent,” she said on CBS’ “Face the Nation.” “We have to work in partnership with business to secure networks to defend ourselves against these attacks.”

While the first step in developing a cybersecurity plan is to analyze operations and find vulnerabilities, the second step is to properly segment networks, manage their access, and create and test a recovery plan. The third step is personnel training.

According to “2021 Cybersecurity: Assess Your Risk,” a new report from PMMI Business Intelligence, “The best cybersecurity plan is only as good as the individuals tasked with carrying it out. With this in mind, manufacturers will have to decide who they want to be responsible for establishing and maintaining cybersecurity practices. In addition to allocating responsibility, manufacturers should properly train all of their employees on cybersecurity best practices, returning to instruction regularly when protocols change and to refresh employee knowledge.”

Creating a dedicated team that focuses exclusively on cybersecurity may be a step to consider. In the past, many manufacturers relied on their IT department to manage all of their cybersecurity concerns, and this is still a common model. Thirty-two percent of companies interviewed stated that cybersecurity is another responsibility left to their IT department.


Read article   Read this story on the second step to cybersecurity.


To get better cybersecurity results, companies have started creating dedicated departments or teams within the IT department that are responsible for cybersecurity. About 41% of organizations currently have a distinct IT security team with dedicated OT specialists – a model that facilitates cooperation between IT and OT while simultaneously ensuring that cybersecurity is a top priority.