I agree that temporary/seasonal employees bring a significant
amount of Cybersecurity risk to any organization who utilizes
them. The sudden influx of new employees creates a larger attack
surface for the organization as there will be an increase in the
number of employees who will have/need access to company
information systems. This type of hiring is often done quickly and
in large numbers, which can have a negative impact on security if
measures are not taken in advanced. If precautions are not taken
by the organization, a bad actor could find their way into the
organization and cause a Cybersecurity incident. Even in the
hospitality industry, employees will have access to business assets
such as computers, networks, and sensitive information (UMGC,
2020). Appropriate measures need to be taken to protect the
company.
The first step in mitigating the risks posed by a
seasonal/temporary workforce begins at the application/hiring
stage. Hiring practices need to be “consistent” (Bonderud, 2016)
as if the employees hired were full time. There should be some
type of background check in place to ensure the company is
hiring trustworthy people right from the start. Subsequent
interviews can further help to vet employees. With a way to vet
the candidates, managers should implement an information system
training program, and a user agreement to help protect the
company. The training program does not need to be as in depth
as the Secure Computer User training course, in the hospitality
industry seasonal/temporary employees should in no way be
allowed to perform the functions outlined in it. The training
program should instead consist of proper usage of company
information systems, ways to recognize various Cybersecurity
attacks (phishing emails, not plugging in unknown devices, social
engineering, etc), and PII protection (customer addresses, credit
card numbers, etc). After completing this training, the employee
should be required to sign a user agreement, which will give the
company legal protection in the event of a Cybersecurity incident.
In addition to the policies outlined above, there are also a number
of steps managers can implement within the information systems
to limit Cybersecurity risks. Temporary/seasonal employees have
no legitimate need to make system changes to information
systems, or have full access to them. Temporary/seasonal
employees should have only standard user accounts with no
possibility of obtaining elevated privileges. Access to information
systems should be limited to the “roles of the individual”
(Department of Labor, 2022) for example, a front desk clerk to a
hotel should not be able access the server where payroll
information is stored. Accounts should be audited on a regular
basis; both for privileges and to ensure that only accounts of
active employees exist. When seasonal/temporary employees are
released from their contracts their accounts should be disabled
immediately and deleted after a predetermined amount of time.
These are but a few system level examples of what managers
should do to ensure the best Cybersecurity practices are in place.
From a leadership perspective, it needs to be emphasized that
Cybersecurity is the responsibility of everyone from the CEO
downwards. Every employee has a role and responsibility when it
comes to Cybersecurity with no exceptions. Company leaders at
all levels need to have a positive attitude towards Cybersecurity
measures to encourage subordinates that they are a part of the
process as opposed to the process being forced upon them.
Company leaders need to take an active role in ensuring that any
implemented Cybersecurity measures integrate well with the in
place processes of the business. Cybersecurity should not be
implemented in a vacuum, management needs to ensure
communication and cooperation between security and the
business itself.
Seasonal/Temporary workers do present a Cybersecurity risk to a
business if measures are not taken. In the hospitality industry this
is especially a concern due the large volume of such employees.
Protecting the company begins during the hiring process with
background checks and training, and carries over into the way
user accounts and privileges are managed. Company leaders need
to encourage employees that they are an active part of protecting
the company from Cybersecurity incidents, as opposed to
guidelines just being another set of rules to follow. Every
employee is responsible for Cybersecurity, from the CEO all the
way down, and that includes seasonal/temporary employees.
Citations
Bonderud, D. (2016, November 2).
Seasonal employee security
risks: Present danger, proactive defense
. Security Intelligence.
Retrieved March 15, 2022, from
https://securityintelligence.com/seasonal-employee-security-risks-
present-danger-proactive-defense/
Department of Labor. (2022). CYBERSECURITY PROGRAM BEST
PRACTICES. Department of Labor.
University of Maryland Global Campus. (2020).
CSIA 300: Why do
businesses need security?
Adelphi, MD: Author.