You’ll often hear the phrase ‘people are the weakest link’ when it comes to cybersecurity. After all, it’s people who click those dodgy links, right … “if only they’d stop and think”!
Don’t the statistics support this view? With almost half of all businesses in the UK falling victim to a cyber breach or attack*, raising to 75% for large businesses, a massive 86% of these are caused by phishing attacks. These use social engineering to lure people into clicking links which then allow the attacker to steal user credentials, credit card details, or to install malware.
But here’s the thing, phishing works because we’re human. We spend our busy and productive days clicking perfectly harmless links from colleagues all the time, and phishing uses tried and tested social engineering techniques, similar to the 'nudges' we see in advertising. We’re all prone to falling victim to these increasingly clever scams, especially when:
- There's some urgency
- They’re directed at you personally
- There’s a threat if you don’t act quickly, or a reward if you do
- It appears to be from someone in a position of authority
- It’s related to a current event, like covid
Incredibly, a third of businesses take no action after a breach, but if you want to reduce any business risk, including cyber security risk:
- How you manage people’s adoption of new technologies, policies, or processes matters.
- How you train them on the awareness of the risks matters.
- How you nurture the right risk management culture matters.
Sysdoc uses aviation principles in all we do, and where risk management is concerned it’s these principles that have made flying the safest form of transport. We can help you reduce your cybersecurity risk by:
- Understanding how Human Factors influence behaviours and decision-making.
- Using Experiential Learning techniques to provide safe learning environments simulating real-world environments and challenges.
- Establishing a blame-free, Just Culture, changing behaviours to encourage and recognise openness and transparency.
- Learning from Experience to ensure continuous improvement.
- Recognising the value of clearly documented and communicated End-to-End Processes and your role in making it work
- Enabling Data-Driven Decisions, providing an evidence base enabling more dynamic, confident decision making.
Why not get in touch to see how we can help reduce your cybersecurity risks before you become one of the statistics.
*Data from DCMS's Cyber Security Breaches Survey, 2020
Latest blog postsSee all blog posts
Sysdoc listed in the Financial Times UK's Leading Management Consultancies 2021
It was a superb February surprise to find out that we had been mentioned not just once, but twice, in the Financial Times UK Leading Management Consultancies 2021.
Excel, we need to talk, it’s not us, it’s you
We have all had our up’s and down’s with Excel and although this may sound like a break-up, it is more of an evaluation of the relationship. Excel has undoubtedly served many of us well and it is continuing to do so. However, have we become too reliant on its familiar layout and easy set-up? Is the prospect of upgrading to a more complex software delaying teams from making the switch? As with most technology and software, it is a question of utility, not usability.
Placing people at the heart of change
OCAI Accreditation for Sysdoc’s People and Culture Capability. Sysdoc’s People and Culture Capability recently completed the OCAI practitioners course as part of its ongoing work to support organisations on their cultural journey. The OCAI assessment is a cornerstone of Sysdoc’s People and Culture capability toolkit as it provides the foundation in helping leaders understand the current culture and defines what the preferred culture needs to be to accomplish the cultural and behavioural objectives.