SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Security Products, Practices and Infrastructure

Cisco CSO shows how to foster security savvy

Cisco CSO shows how to foster security savvy

By:  Howard Solomon  On: 10 Mar 2008 For: Network World Canada Creator

John Stewart says he knows most employees tune out when the IT department discusses policies to protect the network. Lessons from the vendor's own education program

Security is too important to leave solely to the IT department, say Cisco System officials.

That’s why the company hired a number of communications specialists to get out the message to its 60,000 employees to avoid risky behavior online either in the office or when using company-owned network devices. It’s a strategy Cisco advised organizations to consider in a Webinar this week.

“Security guys have got to stop talking in technology terms,” said John Stewart, the company’s chief security officer, because employees just tune them out.

Instead, security messages have to be crafted around simplicity, a few inexpensive giveaways and rewards for good behavior.

After realizing the efforts of Stewart’s team of Cisco staffers weren’t reaping the changes in behavior the company wanted, it recruited media relations specialist Mia Bradway Winter to be its senior manager of corporate security with a mandate to get people to take security more seriously.

Among other things Winter and Stewart suggest is establishing local “security champions” in branches to oversee overall messages and strategies set at corporate headquarters. However, regions also have the power to ensure messages, images and colours in printed or online materials reflect local sensibilities.

In the U.S., Cisco found, posters warning of security practices don’t work, but they are effective in Europe.

Stewart credits Winter for allowing security leaders to talk about staffers’ mistakes rather than hiding them as a way of putting a personal face on security without identifying the offender. Too many people read news reports of security breaches at other companies and think, ‘It can’t happen here,’” he said.

While Cisco’s security strategy was spread over several years, it sometimes took only a little bit of money to get employees’ attention. For example, the company found US$2,000 for laptop security screens for senior executives to “seed the audience.” Other staffers found the devices were “cool” and began buying them themselves, becoming what Stewart called a “badge of honour.” Now Cisco makes the screens mandatory on all new PCs it buys.

Sometimes rewards help – such as giving a certificate for attending a security training course, or urging staffers to nominate colleagues who show exemplary security activity, who are then publicly thanked by managers.

Ultimately, Stewart suggested, organizations want staffers to caution each other about improper behavior on the theory that you’re more likely to listen to a colleague than a manager.

Organizations aiming to set up a security strategy should get buy-in from upper management, said Winter, and appoint the right person to lead the charge. Extensive research is necessary not only to define the different audiences in each organization, but also to find the right vehicles for communicating messages.

What’s important in crafting any strategy, Stewart suggested, is simplicity: Spell out three or so rules for working online – what management forbids staffers from doing, what it really appreciates them not doing, and things it merely recommends them not doing.


Sign up for our Newsletters












Print |  Views: 1222   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Howard Solomon Howard Solomon I'm assistant editor of ComputerWorld Canada covering network infrastructure, communications and government IT issues. An IT journalist  since 1997, I've written ... more

Related Content

Cisco launches Virtual Office
Cisco launches Virtual OfficeVirtual Office bundle includes an 800 series Integrated Services Router and a 7900 series IP phone. A Forrester analyst says the security features are critical for home office users.
RSA unveils File Security Manager 2.2
RSA unveils File Security Manager 2.2EMC’s security division said its new RSA File Security Manager will reduce costs and mitigate risk by providing IT managers with encryption and access control capabilities for their Windows and Linux-based data.
Fortinet brings HP ProCurve to the table
Fortinet brings HP ProCurve to the tablePrivately-held Fortinet has named ProCurve Networking by Hewlett-Packard to its global alliance partner program. This is good news for Fortinet. It should help HP, too.
SecTOR helps spawn IT Security Week
earlier this year i wrote about a local firm, toronto-based cms consulting, which is planning to host
BitDefender launches 2009 security suite
antivirus software and data security provider bitdefender released the latest version of its security software suite, bitdefender total security 2009, earlier today.new enhancements to the 2009 package include an online backup service for preserving sensitive information and instant messaging en
Yes, you can ... making a VPN gateway support the iPhone
everybody wants an iphone ... but what about the security issues? jamey heary, a security consulting engineer at cisco, gets into the geeky details of how to cisco's ios and asa lines play well with apple's smart phone on the cisco subnet.got some hands-on advice for th
blog comments powered by Disqus