Menu

Call us on 03450 21 21 51

Handling the issue of human error
The SRM Blog

Handling the issue of human error

Ian Armstrong

Written by Ian Armstrong

12th August 2021

Share this article

human error

Effective training, education and business continuity planning is more important than ever

Discussions around cybersecurity often focus intensely on the pitfalls of software and tech, but as Cybint reports, 95% of cybersecurity breaches are still caused by human error.

Without the right information, training and education in place, even the most rigorously protective software can’t guarantee your business data’s safety. That’s why investing in the upskilling of staff to combat phishing scams, social engineering and other similar attack vectors is critical – especially now that the day-to-day working environment is very different for many employees.

Data from Google Trends shows a spike in searches for ‘business continuity’ at the start of the pandemic, then an abrupt drop-off. This in itself is an example of human error: we’re quick to adapt, but also quick to forget.

If your business continuity plan doesn’t account for the all-too-real threat of human error, it isn’t up to standard. With that in mind, here’s how to include human mistakes and deceptions in the future.

 

Train your team

The importance of effective staff training can’t be overstated. Plans should be inclusive in nature, taking ever member of staff into consideration, especially the varying levels of technological knowledge. Remember, a business is only as secure as its weakest link. For this reason it is important to create a culture of openness and an environment in which people are not afraid to stop, think and consult with the information security or IT team.

While a step-by-step guide or training manual can be a valuable point of reference, mock attack scenarios can help make things clearer for your staff, giving them real-life situations to deal with rather than an abstract set of rules. Having been through the incident response process as part of a simulation it is much easier to consolidate employees’ understanding of the relevant threats and ensure that the correct actions will be taken in a real-world scenario. This includes knowing who needs to be contacted as part of the recovery process and how to work with colleagues to identify the extent of a breach or incident.

It is important to clarify that the emphasis is never on training an attack victim to handle the issue in isolation. Indeed, that is when larger problems tend to manifest themselves. It is instead about putting a framework in place so that help is sought quickly and efficiently.

Ultimately, helping users to identify and report suspected phishing emails or social engineering attacks is one of the most effective ways of mitigating the risk to any organisation.

 

Offer a single source of information to streamline response efforts

Of course, there is no way to eliminate the risk of a cyber attack entirely. No matter how good your training and how vigilant your team members, there is always the possibility that a cyber criminal will find a way to outfox your defences. At this point, it is important to have a clear incident response and business continuity plans in place.

One of the biggest causes of confusion for team members often lies in having to gather information from multiple places and wade through piles of documentation when something goes wrong. Forcing your staff to rely on search engines for the best cybersecurity advice can lead to conflicting information, which in turn causes rash decisions in the heat of a cybersecurity scare.

So if you haven’t already created and distributed an employee-facing incident response plan, now is the time. This gives your team members a single source of clear information that they can review whenever they need to be reminded about the best way to avoid a breach. Be sure to host a workshop, staff update meeting or internal communication to announce it when it’s live.

Remember, too, that documenting an incident in real time will also help a Major Incident Manager or cyber consultancy investigate and remediate a breach much more quickly and efficiently. To assist with this, download our helpful Incident Log here.

 

Focus on the ‘human’ aspect in your business continuity efforts

Any business continuity plan you create needs to keep humans as a focus, not just human error. In the event that a breach occurs and the immediate recovery efforts have been made, it’s vital that you have an overarching strategy in place to return your team to business as usual. Not only are employees who are experiencing pressure less productive and less happy, they’re also more likely to make mistakes due to fatigue, stress or even a lack of business loyalty.

If you are looking to upskill your team and make your organisation more resilient in the face of escalating cyber threats, get in touch with the team at SRM today. Enquire here