Partner Article

65 per cent of companies use in-house resources for IT security training

Kaspersky Lab today reveals that most companies assign their own Tech Support Department to train company employees in matters of IT security, rather than hiring outside IT consultants or security professionals. This is according to the B2B International and Kaspersky Lab, Global Corporate IT Security Risks 2013 survey, carried out among companies located all over the world.

Effective IT security training for employees is a key component of any strategy to combat cyber threats – according to the survey, four out of five of the most common internal security incidents recorded in the past 12 months were directly linked to staff actions:

  • 32 per cent of respondents reported accidental leakages of confidential data
  • 30 per cent of respondents reported employees losing corporate mobile devices with critical data stored on them
  • 19 per cent of companies encountered intentional staff-facilitated data leakages
  • 18 per cent of companies had dealt with incidents when confidential data got into the wrong hands due to the improper use of mobile devices (via a mobile email client, text messages, etc.)

Research repeatedly shows that unintentional staff errors are behind a significant proportion of critical data leaks and IT security incidents. The key to addressing this challenge lies in ensuring that end users are adequately informed of IT security risks – and how best to avoid them.

While this clearly illustrates the importance of employee education in IT security, the question remains: who exactly should provide that training?

As B2B International’s experts determined, most companies believe that an organisation’s in-house IT Department should train company employees in IT security matters — even though staff education is not one of the key functions of an IT Department. This additional workload affects performance: respondents noted that IT Departments have other important tasks and typically do not have time to educate their co-workers. Obviously, this can have a negative impact on the quality of training. A better outcome can be delivered by commissioning a third-party IT consultant with the requisite training expertise. However, only 12 per cent of respondents reported having done so.

The HR Department is involved in employee training at 8 per cent of the companies that took part in the survey. A similar number of companies delegate this matter to an Employee Training and Development Department. Roughly three per cent of respondents reported that they commission an outside corporate training provider.

These figures are more or less the same across regions, with some minor differences: for example, the highest percentage of companies assigning IT security training to their in-house IT Departments are countries located in the Middle East (73 per cent), Japan (72 per cent), and North America (71 per cent). External IT consultants are most often hired to train company employees in South America (16 per cent) and Asia-Pacific.

In general, the importance of employee education in IT security is acknowledged by the overwhelming majority of companies — only four per cent of survey respondents stated that their companies do not train their staff in IT security at all. However, the quality of corporate education is open to question; after all, employee awareness about cyber threats has a direct impact on the extent to which a company’s IT security policies are followed and, as a result, on the overall degree to which a company is protected against cyber threats. Presently, the extent to which policies are being enforced is relatively low, with approximately 39 per cent of survey participants indicating that company employees do not always respect or diligently adhere to corporate IT security rules.

Education: one component of a broader security strategy

Incidentally, no matter how alert and well-informed the staff, the risk of a successful cyber-attack against a company remains high, and the use of advanced corporate IT infrastructure security solutions is critical

Kaspersky Lab’s flagship corporate solution, Kaspersky Endpoint Security for Business — in addition to providing reliable protection against malicious programs, network attacks, targeted attacks, spam, and phishing — also includes a number of functions facilitating the effective management of a corporation’s IT infrastructure. Kaspersky Endpoint Security for Business helps to maintain an inventory of workstations, promptly update installed software, manage and limit access rights to different components of the IT infrastructure, set up and oversee the enforcement of security policies, encrypt confidential data (for example, if a corporate device was lost or stolen), and can also be used to perform several other operations necessary to ensure that a corporation enjoys a high level of IT security.

Another technology offered in Kaspersky Endpoint Security for Business that works to prevent incidents stemming from employee errors: Dynamic Whitelisting. This technology prevents malware from launching. Whitelisting solutions are based on the program’s own database of trusted applications, and permit the operating system to launch only those programs included in the Whitelist database. This makes it extremely difficult to launch a successful attack against a company even with highly complex malicious programs that might not yet even be known to antivirus solutions.

At the same time, it is crucial that the Whitelisting database in the solution is large enough to encompass the maximum number of applications used by a company without creating problems for legitimate programs. For example, Kaspersky Lab’s Dynamic Whitelisting database currently contains over 700 million unique files, and is regularly updated with new files. The results of independent testing of this solution earlier this year have shown that this database size is sufficient for maintaining effective protection. Kaspersky Lab’s solution underwent all tests without producing any false positives, and was capable of detecting almost 100% of files found in applications commonly used by corporations and home users. B2B International’s study has shown that Whitelisting solutions are among the measures most frequently taken by companies to protect their IT infrastructures: nearly 45 per cent of respondents noted that their organisations use these solutions. This represents a significant change from last year, when Whitelisting solutions were rarely used, if at all.

Kaspersky Endpoint Security for Business can also be integrated with Kaspersky Lab’s other specialised solutions. These include corporate mobile device security and management solutions, such as Kaspersky Security for Mobile, solutions protecting virtual servers, and a number of other products that help protect even the most complex and atypical corporate IT infrastructures.

-ENDS-

About Kaspersky Lab

Kaspersky Lab is the world’s largest privately held vendor of endpoint protection solutions. The company is ranked among the world’s top four vendors of security solutions for endpoint users*. Throughout its more than 15-year history Kaspersky Lab has remained an innovator in IT security and provides effective digital security solutions for large enterprises, SMBs and consumers. Kaspersky Lab, with its holding company registered in the United Kingdom, currently operates in almost 200 countries and territories across the globe, providing protection for over 300 million users worldwide. Learn more at www.kaspersky.co.uk

* The company was rated fourth in the IDC rating Worldwide Endpoint Security Revenue by Vendor, 2011. The rating was published in the IDC report “Worldwide Endpoint Security 2012–2016 Forecast and 2011 Vendor Shares (IDC #235930, July 2012). The report ranked software vendors according to earnings from sales of endpoint security solutions in 2011.

This was posted in Bdaily's Members' News section by Alice Collins .

Enjoy the read? Get Bdaily delivered.

Sign up to receive our popular morning National email for free.

* Occasional offers & updates from selected Bdaily partners

Our Partners