Introduction
Throughout this discussion I will address the cybersecurity risks
involved in the employment of the seasonal workforce and the
things managers may consider changing or keeping the same in
their hiring and employment practices. Consideration must always
be given to what is the minimum and maximum access needed for
employees to accomplish their daily tasks while ensuring that the
company maintains a secure posture.
Analysis (supported by readings / research and citations)
Do you agree or disagree with the author's assertions regarding
seasonal employees and cybersecurity risks in the work place?
Why?
I agree with the author's assessment of the possible risks to
cybersecurity when employing a seasonal workforce. The question
is not should companies employ a seasonal workforce, but how can
they safely and successfully train and employ a workforce in a
mutually beneficial model. d The seasonal employee could create the
highest risk to a company's finances, data, and networks when a
company has not developed a formal initial training program, a
standard for vetting and validating the required employee access by
work role (access control lists or user groups), and a transparent
onboarding process where all employees are treated equally. In
some cases managers forget that even the minimum network access
is still access, and opens the doors for the loss of vital data.
Training, accountability, and a positive work environment are all
vital to improving the cybersecurity of a seasonal workforce
(Bonderud et al., 2021). .
What steps can (should) managers take to reduce security risks
associated with hiring seasonal or temporary employees? (Consider
whether or not the Secure Computer User training course would
be appropriate for these employees.)
Managers can take several steps to reduce security risks throughout
the hiring and onboarding process. The first step in risk mitigation
would be to conduct background checks on individuals being
considered for employment prior to the interview process.
Knowing the background of a possible employee may assist in
defining what role you are willing to hire a person to fill. The next
step would be to require employees to attend a version of cyber
and information systems awareness training, either computer-based
training, formal briefings and instruction, or a mentorship program
with left seat / right seat hands on training program to name a few.
Next would be to have each individual sign a user's agreement
stating they have been trained and understand what they are
allowed and not allowed to do on company systems. Managers
should coordinate with IT managers to ensure work role-based
access containers are created to ensure each work role only has
access to the information or data that is required for accomplishing
their daily tasks. Another consideration is once the individuals are
trained and given access to the networks of data needed to conduct
daily business they must feel like part of the team. If a seasonal
employee is constantly reminded that they are only seasonal staff
their morale and work outputs can be diminished and possibly lead
to finding ways to retaliate against the employer. Insider threats
are always a concern in cybersecurity. An unhappy employee can
tear down a network just as quickly as an untrained employee.
Managers must find ways to make each person feel like they are
part of the overall team at all levels and their opinions and ideas
matter regardless of their term of employment. The feeling of
being part of the team has proven time and again to improve
employee sense of fulfilment in their job and increased loyalty to
their current employer.
How can managers show leadership in cybersecurity defenses and
best practices?
Managers can show leadership in cybersecurity by ensuring that all
cybersecurity training is completed and holding themselves and all
employees to the same standards. Managers can be at the forefront
of the training process by attending or providing the training during
onboarding on new employees and security refresher training for
permanent staff members. Managers must also hold all employee
accountable at the same levels with equal treatment among all
employees when considering rewards or reprimands.
Summary or Conclusion
In summary, cybersecurity has quickly become a primary concern at
all levels of the world economy. Companies spend millions of
dollars on software and hardware to protect their networks and
data. However, the strongest defenses are only as good as their
weakest link, which in the case of information technology and
cybersecurity is the end user. Training and understanding must be
at the forefront of the corporate training model. d It doesn't matter
how well a person understands the specific job if the systems that
support those efforts are constantly exposed to threats by unaware
or untrained users.
References
Bonderud, D. (2021, August 31).
Seasonal Employee Security Risks:
Present Danger, Proactive Defense
. Security Intelligence.
https://securityintelligence.com/seasonal-employee-security-risks-
present-danger-proactive-defense/
2018 State of Cyber Resilience, Accenture.
https://www.accenture.com/in-en/insights/security/2018-state-of-
cyber-resilience-index
Security Awareness Training Explosion, Cybersecurity Ventures,
February 6, 2017.
https://cybersecurityventures.com/security-awareness-training-
report/