1 / 2100%
The answers to this week’s discussion questions are presented
below for review. The question of whether seasonal employees
pose a risk is discussed in the first section. The final two
sections deal with the role of managers in cyber protection, both
from an activity standpoint and from a perceptional standpoint. d d
1. Do you agree or disagree with the author's assertions
regarding seasonal employees and cybersecurity risks in the
workplace? Why?
I agree that the addition of seasonal employees to the staff can
increase the probability of a cyber breach. For one, it is
plausible. d d Since there is less time to train and vet seasonal
employees during the course of their duties, extra scrutiny will be
required of those responsible for monitoring cyber. Both human
error and nefarious intent are more likely. Another reason is the
citation of the CPA Practice Advisor article which notes the 20%
uptick in fraud during the holiday period. (O’Bannon, 2014).
The Cybersecurity and Infrastructure Security Agency (CISA),
recently issued an alert noting a general increase in Cyber
attempts during weekends and holiday periods. (CISA, 2022). d d It
is likely that this activity occurs outside of normal business hours
to increase the length of time before any breach can be detected.
The additional evidence of increased cyberattacks, on top of
the risk of seasonal employees in general, highlight the need for
heightened awareness during such periods.
2. What steps can (should) managers take to reduce security
risks associated with hiring seasonal or temporary employees?
(Consider whether or not the Secure Computer User training
course would be appropriate for these employees.)
Managers should ensure the security of the environment that
seasonal employees are asked to work within. Explaining exactly
why password complexity and MFA are good countermeasures to
cyber threats may not be relevant to the job functions that these
employees are asked to perform. Ensuring that password
complexity validation and MFA are present on the company’s
systems is more important, in my opinion.
A course such as the Secure Computer User course may be
overkill for seasonal employees. Managers should definitely be
well educated in the principles outline in the SCU course. d d A
scaled-down version of the SCU course should be created by the
company for internal training of such employees.
3. How can managers show leadership in the area of
cybersecurity defenses and best practices?
Managers can lead by example to help build a secure culture
within the company. For instance, the Security Intelligence article
mentions taking steps like setting a common termination date for
seasonal employees if possible. (Bonderud, 2021). This is
something extra that a manager can require on top of employee-
level security protocols to help with cyber concerns. Setting such
a date assists SysAdmins with credential deactivation tasks, helps
threat hunters who will be scanning logs for unauthorized access,
and give peace-of-mind to owners and stakeholders in the
business that managers are educated and active in cyber
protection activity.
References
Bonderud, D. (2021, August 31).
Seasonal employee security risks:
Present danger, proactive defense
. Security Intelligence. Retrieved
March 20, 2022, from https://securityintelligence.com/seasonal-
employee-security-risks-present-danger-proactive-defense/
CISA. (2022, February 10).
Alert (AA21-243A) - Ransomware
Awareness for Holidays and Weekends
. CISA. Retrieved March
20, 2022, from https://www.cisa.gov/uscert/ncas/alerts/aa21-243a
O'Bannon, I. M. (2014, November 6).
Fraud risk increases with
temporary workers, seasonal staff
. CPA Practice Advisor.
Retrieved March 20, 2022, from
https://www.cpapracticeadvisor.com/payroll/news/12017078/fraud
-risk-increases-with-temporary-workers-seasonal-staff
Students also viewed