With every year that passes, the risks associated with e-
commerce hit new highs. Due to “evolving targets[,]… impact[,]…
[and] techniques”, businesses are rightfully moving towards an
all-hands-on-deck approach to cyber security (Accenture Security,
2019, p. 6). The only other option that leadership has is to
allow the theft of company and customer data, which would
surely be accepting the unavoidable end of the brand altogether.
As history has shown, those who have been able to look
towards the future have had the most success staying relevant
through the changing times, whereas those who chose to only
look at their past and present did not fare as well.
Douglas Bonderud (2019) wrote an article stressing the
importance of including seasonal employees in cybersecurity
training and practices, which the value can be expanded to
include all short-term associates. While Padgett-Beale, and the
hospitality industry as a whole, is no stranger to the extreme
need for extra help during times such as holidays, spring break,
or large events and productions, short-term employees are
regulars throughout the entire year. Interns and contractors flow
in and out of the offices month in and month out, accessing a
wide range of data types. It is dire to company security that
anyone who has any sort of electronic responsibilities, regardless
of status or position, receives the proper training before ever
being allowed on the company network.
According to a study conducted by Tessian, a security firm, and
Stanford University, almost 90 percent of cybersecurity incidents
resulted from human error (CISOMAG, 2020). So, whether or
not an employee is around for the long haul, they still pose a
significant threat against the security posture of the company.
The average cost of a cybersecurity incident rose twelve percent
between 2017 and 2018, reaching $13 million (Accenture
Security, 2019), and didn’t just stop there. Bonderud’s key point
in how to get seasonal employees to become part of your
security solution is simple: treat them as you would any other
employee (2019). That means from recruitment to off-boarding,
they need to feel that they belong and are valued. When people
truly feel included, they typically want to contribute to efforts
that will benefit them and the company. Put as much into them
as financially and logistically feasible, for training, orienting, and
development, so that they have the tools to not only perform
their job, but to also “think… with security in mind” (Accenture
Security, 2019, p. 9). As for Secure Computer User course,
companies might want to consider an initial assessment during
onboarding that may help indicate who would greatly benefit
from such training. Depending on the financials of each
individual company, it might not be practical to want every
trainee to go through it.
In order to get all staff members to believe in and act in
support of the security program, company executives and
managers need to lead by example. They have to be seen
following the policies, encouraging the correct behavior, and
retraining their team members when necessary. And they must
be open to being addressed if they stray from best security
practices themselves. c If temporary employees see the
importance of the program being modeled day after day
throughout all levels, they will begin to emulate the same
behaviors.
As demonstrated by the ongoing SolarWinds cyber incident
investigation, decisions that temporary employees make can have
critical impacts on business operations. Where an intern’s lack of
security regarding passwords may have led to a U.S. government
data breach (Fung & Sands, 2021), is it really the fault of the
employee or more so on SolarWinds’ policies, practices, and
oversight? The more that company leadership does to mold
security behaviors, even for those around for only a short time,
the better the chance that the employee becomes part of the
solution rather than the problem.
Accenture Security. (2019).
The cost of cybercrime: Ninth annual
cost of cybercrime study
. c c c c c c c c c c c c c c
https://www.accenture.com/_acnmedia/PDF-96/Accenture-2019-
Cost-of-Cybercrime-Study-Final.pdf
Bonderud, D. (2016, November 2).
Seasonal employee security
risks: Present danger, proactive defense
. Security Intelligence.
https://securityintelligence.com/seasonal-employee-security-risks-
present-danger-proactive-defense/
CISOMAG. (2020, September 12).
“Psychology of human error”
could help businesses prevent security breaches
. EC-Council.
https://cisomag.eccouncil.org/psychology-of-human-error-could-
help-businesses-prevent-security-breaches/
Fung, B. & Sands, G. (2021, February 26). Former SolarWinds
CEO blames intern for ‘solarwinds123’ password leak.
CNN
.
https://www.cnn.com/2021/02/26/politics/solarwinds123-
password-intern/index.html