1 / 3100%
With every year that passes, the risks associated with e-
commerce hit new highs. Due to “evolving targets[,]… impact[,]…
[and] techniques”, businesses are rightfully moving towards an all-
hands-on-deck approach to cyber security (Accenture Security,
2019, p. 6). The only other option that leadership has is to allow
the theft of company and customer data, which would surely be
accepting the unavoidable end of the brand altogether. As history
has shown, those who have been able to look towards the future
have had the most success staying relevant through the changing
times, whereas those who chose to only look at their past and
present did not fare as well.
Douglas Bonderud (2019) wrote an article stressing the
importance of including seasonal employees in cybersecurity
training and practices, which the value can be expanded to
include all short-term associates. While Padgett-Beale, and the
hospitality industry as a whole, is no stranger to the extreme
need for extra help during times such as holidays, spring break, or
large events and productions, short-term employees are regulars
throughout the entire year. Interns and contractors flow in and
out of the offices month in and month out, accessing a wide
range of data types. It is dire to company security that anyone
who has any sort of electronic responsibilities, regardless of
status or position, receives the proper training before ever being
allowed on the company network.
According to a study conducted by Tessian, a security firm, and
Stanford University, almost 90 percent of cybersecurity incidents
resulted from human error (CISOMAG, 2020). So, whether or not
an employee is around for the long haul, they still pose a
significant threat against the security posture of the company.
The average cost of a cybersecurity incident rose twelve percent
between 2017 and 2018, reaching $13 million (Accenture
Security, 2019), and didn’t just stop there. Bonderud’s key point
in how to get seasonal employees to become part of your
security solution is simple: treat them as you would any other
employee (2019). That means from recruitment to off-boarding,
they need to feel that they belong and are valued. When people
truly feel included, they typically want to contribute to efforts
that will benefit them and the company. Put as much into them
as financially and logistically feasible, for training, orienting, and
development, so that they have the tools to not only perform
their job, but to also “think… with security in mind” (Accenture
Security, 2019, p. 9). As for Secure Computer User course,
companies might want to consider an initial assessment during
onboarding that may help indicate who would greatly benefit
from such training. Depending on the financials of each individual
company, it might not be practical to want every trainee to go
through it.
In order to get all staff members to believe in and act in support
of the security program, company executives and managers need
to lead by example. They have to be seen following the policies,
encouraging the correct behavior, and retraining their team
members when necessary. And they must be open to being
addressed if they stray from best security practices themselves.
If temporary employees see the importance of the program being
modeled day after day throughout all levels, they will begin to
emulate the same behaviors.
As demonstrated by the ongoing SolarWinds cyber incident
investigation, decisions that temporary employees make can have
critical impacts on business operations. Where an intern’s lack of
security regarding passwords may have led to a U.S. government
data breach (Fung & Sands, 2021), is it really the fault of the
employee or more so on SolarWinds’ policies, practices, and
oversight? The more that company leadership does to mold
security behaviors, even for those around for only a short time,
the better the chance that the employee becomes part of the
solution rather than the problem.
Accenture Security. (2019).
The cost of cybercrime: Ninth annual
cost of cybercrime study
. d d d d d d d d d d d d d
https://www.accenture.com/_acnmedia/PDF-96/Accenture-2019-
Cost-of-Cybercrime-Study-Final.pdf
Bonderud, D. (2016, November 2).
Seasonal employee security
risks: Present danger, proactive defense
. Security Intelligence.
https://securityintelligence.com/seasonal-employee-security-risks-
present-danger-proactive-defense/
CISOMAG. (2020, September 12).
“Psychology of human error”
could help businesses prevent security breaches
. EC-Council.
https://cisomag.eccouncil.org/psychology-of-human-error-could-
help-businesses-prevent-security-breaches/
Fung, B. & Sands, G. (2021, February 26). Former SolarWinds
CEO blames intern for ‘solarwinds123’ password leak.
CNN
.
https://www.cnn.com/2021/02/26/politics/solarwinds123-
password-intern/index.html
Students also viewed