Disclaimer: To protect the privacy of a former client, I have changed key details of this story, however the main sentiment and methods remain the same. A few years ago, I orchestrated a jewel heist. Yes, you read that correctly. While claiming a mysterious former life of crime is always intriguing, the truth is it was all in the name of compliance and I had explicit (albeit less interesting) permission from the jeweler's CEO. Don’t get me wrong, I was no Box Man in this scenario. I didn’t need to be, especially since I’d been privy to the common security inconsistencies of the jeweler in question. My job was to create, deploy, and enforce security procedures. When I’d noticed that the employees had not been following these procedures as strictly as I’d recommended...I had to try a different tactic. I made my point the day I smuggled $20,000 in inventory from the main vault. The loss was enough to constitute a termination, and somehow this made them keener to heed my security warnings. They’d made a major procedural mistake by leaving the keys and safe combo in the same location. They’d served me the keys to the kingdom on a silver platter. It was the easiest $20,000 I’d ever made and my oh my did they learn their lesson! For the record, I returned the assets, but taking them had been too easy and it troubled me. In my experience as a compliance expert, I’ve seen lax attitudes and confusion surrounding information security programs. More specifically: the policies, standards, procedures, and guidelines that make up the program. While these components are often (wrongly) used interchangeably, there are very distinct differences between them, and each one should be taken seriously to maintain security protocols and protect your organization. Clearly defining the roles of each of these components and enforcing them within your workplace are essential for upholding a strong security posture. Before we dive into differentiating these four components, we need to first understand what an information security program is and why it is critical for your overall business operations.
Another week, another shortage it seems. COVID-19 conditioned us to expect this, but the most recent shortages (such as gasoline, beef, chicken, and pork) are due to cyber-attacks involving ransomware. The UK’s National Crime Agency (NCA) details that the overall threat from cybercrime has significantly increased in the past year .
It seems people aren't the only ones facing a certain viral nemesis. Cyber-attacks are on the rise from opportunistic hackers, and Ryuk ransomware has risen to the top of the threat list.
Muahahaha the truth is out, and nothing is spookier this season of terror than lacking the knowledge you need to take on cyberthreats and stay ahead of the curve. Hackers (the ghouls in this scenario), are always developing new methods to dupe your team, which makes preparation tricky and ongoing! Don’t fall prey to social engineering or polymorphic malware! It’s time to take control of the narrative and consider investing in security awareness training. Read on to learn why this is a viable and necessary solution for your team.