Insider Threats, Part 1: Accidents
This is the first in a series about the different kind of Insider Threats: Accidents, Negligence and Malice. This series is itself part of our recent focus on Insider Threats.
In the cybersecurity context, accidents and negligence cause incidents which were unintentional. The different is that negligence means that someone failed to follow procedure while accidents are not failures to follow procedure.
When dealing with cybersecurity incidents you should determine what came before (the proximate cause), what was involved (the actual incident) and what comes after (the lesson or adjustment).
When dealing with accidents, the cause might be just very bad luck, which case what you learn is that sometimes bad things happen to good Cybersecurity Programs. The cause might be carelessness, in which case you need to determine if the person is chronically careless or if there was a some reasonable cause, such as the birth of one's first child. The cause might be a process or procedure which has an unnecessarily high element of risk.
In order to respond appropriately you need to be able to distinguish these scenarios. In order to keep up morale, you need to be able to distinguish these scenarios in a way that is seen to be impartial, consistent and fair.
Once you know what you are dealing with, you then select the appropriate response. Playing this by ear only works if you are great at that. And remember that you are setting precedent. People will expect consistency and they will be unhappy with inconsistency.
"Accidents happen" and "we all make mistakes" are common sayings which are not that helpful in this case. Certainly punishing bad luck is terrible for morale, but so is turning a blind eye to slapdash work.
Distinguishing these different kinds of accident is hard. We can help. Ask us how.
Comments
Post a Comment