Douglas Bonderud’s 2016 article, “Seasonal Employee Security
Risks: Present Danger, Proactive Defense” asserts that seasonal
employees present a cybersecurity risk that require unique
mitigation efforts. I contend that applying fundamental security
education to all employees with privileged information access
will significantly mitigate the top cyber security risk in our
industry.
I agree with the author’s claim that seasonal workers present an
increased cybersecurity risk. The author cites credible data
supporting the idea of increasing fraud during holiday seasons.
However, the author’s assertation that the uptick is security
incidents are a result of malicious intent does not hold up to
scrutiny. The 2018 Coranet article “An Integrated Cybersecurity
Strategy: Policies, People, Processes, and Technology” attributes
the overwhelming majority of security incidents to human error.
Perhaps the most effective tool to mitigate cybersecurity risk is
to educate permanent as well as seasonal or temporary
employees. Employees who are better aware of the risks posed
by security breaches and who are trained to identify common
types of cyber attacks are better prepared to reduce risk to the
company. The Coranet article cites a Verizon report indicating
substantial success after implementing a similar risk mitigation
strategy.
The majority of seasonal jobs in our industry of hospitality do
not require access to sensitive customer or company information
and would therefore not be appropriate candidates for the
Secure Computer User training course (Medina, 2018). For those
seasonal employees whose duties do require access to sensitive
information, a robust training course may significantly reduce the
risk of security incidents.
Managers show leadership in cybersecurity by holding
themselves and their employees accountable for cybersecurity
incidents. A manager who demonstrates best practices through
implementing education and training will help foster a culture of
universal responsibility for security.
While human error and phishing attacks remain the main threat
vector, education and accountability will remain the most
effective mitigation routes. Proper management of cybersecurity
culture and education will reduce the threat of the most
common cybersecurity incidents.
References
Coranet (May 5, 2018). An Integrated Cybersecurity Strategy:
Policies, People, Processes, and Technology.
https://www.coranet.com/integrated-cybersecurity-strategy/
Bonderud, D. (November 2, 2016). Seasonal Employee Security
Risks: Present Danger, Proactive Defense.
Security Intelligence.
https://securityintelligence.com/seasonal-employee-security-risks-
present-danger-proactive-defense/
Medina, K. (November 8, 2018). 10 Popular Seasonal Jobs in
Hospitality. https://www.hcareers.com/article/job-search-tips/10-
popular