Is the phrase cyber security a turn off?

Is the phrase cyber security a turn off?

People find the subject fascinating but is the phrase cyber security a turn off?

The events Holly and I have been running on cyber security awareness seem to get a really good reaction. The engagement is high, the questions keep coming and the commitments to make changes afterwards seem genuine. So what more could we want? Well, getting more of them to come in the first place would be good.

Once someone has come to one of our events they tend to be very enthusiastic and either encourage others to come or look for more opportunities where we can run the workshops. And that works, because their recommendations persuade others to do so. 

Barrier to attendance

But we are increasingly coming to the conclusion that the expression cyber security is currently more a barrier to attendance than an encouragement. This is perhaps less the case at founder/ceo level because they are starting to realise this is something they need to get to grips with. But even then, many assume it is someone else’s job or just one thing too many for them to be able to deal with.

When it comes to other roles, the appetite to engage with cyber security seems more limited. Maybe everyone thinks it is the IT department’s problem?

Yet we know the greatest cyber security weakness in any organisation is the likelihood of human error. This article by Info Security Magazine suggests 90% of data breaches in the UK in 2019 were a result of mistakes by end users. By contrast, staff who understand the basic principles, have robust policies to follow and operate in a positive cyber security culture are likely to be an organisation’s greatest line of defence. 

We need people to engage with cyber security

So we need to get people to engage with cyber security as enthusiastically as possible, but our suspicion is that for too many the phrase cyber security sounds… boring/ complicated/ overwhelming etc etc. 

So what can we do?

Sadly we don’t have an easy fix for this. But at our latest event for staff members, we pitched as many ideas as possible in the context of helping them stay safe in their non-working lives. More along the lines of avoiding online scams and protecting their money, identity etc. Of course, the very same principle apply in work, so our hope is that they will take these ideas into their professional lives too. 

Avoiding the latest online scams?

Cyber security is new and sounds complicated. But we all know about scams. They’ve existed as long as humans have wanted something they don’t have. Maybe by presenting things like phishing attacks as nothing more than the latest version of the age-old practice of scamming, we can get people more engaged and improve their cyber security know-how without them even realising it?