1. Do you agree or disagree with the author's assertions
regarding seasonal employees and cybersecurity risks in
the work place? Why?
I agree with the author, Bonderud (2021), that seasonal
employees pose as a potential insider threat to an employing
organization. However, they pose same amount of threat as any
employees that are not vetted properly or disgruntled. As
Bonderud states, seasonal employers should be treated the
same as regular employees, and given the proper training then
access necessary to complete their assigned tasks. For instance,
at Padgett-Beale, a temporary or seasonal employee hired at the
front desk, should only have access to a computer with guest
check-in and check-out information, as well as handling of
customer credit cards. The IT team should practice strict access
control for seasonal employees, and only give access to
information systems necessary to complete their jobs. By vetting
the employees, keeping moral high, and proper use of access
control, the threats posed by seasonal employees should be
limited.
2. What steps can (should) managers take to reduce security
risks associated with hiring seasonal or temporary
employees? (Consider whether or not the Secure Computer
User training course would be appropriate for these
employees.)
Managers first should exercise proper vetting process in hiring
temporary employees. All employees should go through
background checks to eliminate potentially problematic
employees from getting hired. Another step to reduce risk is to
train the employees on cybersecurity threats and insider threats
(Marcucci, 2018). Giving the awareness of potential threats such
as ransomware, spam, and phishing. Though training is necessary,
Secure Computer User training would not be appropriate for
temporary employees. Managers should ensure that their
employees have proper access to complete their tasks, and
coordinate with the IT team for employee access control, and
account(s) disable dates.
3. How can managers show leadership in the area of
cybersecurity defenses and best practices?
The best way managers can show leadership in cybersecurity is
coming up with the process of cybersecurity. Good
organization’s cybersecurity process will define organization’s
assets and protect them from unauthorized access modification,
disclosure, and destruction (Marcucci, 2018). Managers are
responsible in setting the scope and the framework in setting
the organizations cybersecurity policy and incident response.
References
Bonderud, D. (2021, August 31).
Seasonal Employee Security
Risks: Present Danger, Proactive Defense
. Security Intelligence.
https://securityintelligence.com/seasonal-employee-security-risks-
present-danger-proactive-defense/
Marcucci, P. (2018, May 9).
An Integrated Cybersecurity
Strategy: Policies, People, Processes, & Tech.
Coranet.
https://www.coranet.com/integrated-cybersecurity-strategy/