Talk to us Risks to Watch

Resistance to cultural change plays spoilsport to strengthen enterprise IT security (Part – 1)

Recently, while interviewing some of the global CIOs and CISOs in an event regarding the reason of extensive privileged account compromise, we came across a very interesting point of view, which was highlighted by a few of the respondents. Work culture and employee mindset can be a big barrier in establishing a robust IT security framework in enterprises. Let us see how it can play spoilsport while strengthening enterprise IT security.

While the competency of Privileged Access Management (PAM) is widely acknowledged by the management, it often gets stuck due to dislike from IT administrative staff. More than dislike, people presume that it might increase their workload extensively. As a result, successful implementation of PAM project faces hurdles and adoption of new technology gets stuck. While the top management (CIO, CISO) prefers it from security & compliance perspective, resistance from IT administrative staff hinders the change of security policies and procedures.

Changes are inevitable in every sphere of life. However, humans, by nature, are never comfortable to any changes in their life/ work, thinking of the apparent hidden challenges. People react to changes in different ways – some may respond with fearful acceptance while others respond with complete denial. This can definitely be controlled if we can get to know the reasons behind this resistance. Be it individual change or organizational change, there are a number of reasons why people resist changes.

  • Employment security: It is a very common concern which most of the employees have in any organization. Any implementation of new technology forces the employees to presume that their job might be at stake.
  • Lack of communication: Many times, changes happening in organizations are not communicated properly, which creates lots of confusion among the employees. Deployment of PAM thus inherently creates a notion that the change won’t be suitable.
  • Extent of change: Employees remain unsure about the extent of technological changes that are going to occur in the system once a PAM is implemented. Thus, they can not be apprehensive.
  • Fear of losing control: Employees get scared of losing the grip of work skills if the changes are technologically advanced and require less human interference.
  • Influence of group decision: This happens in most of the organizations. Along with the management, even if some of the lower admin staff is apprehensive about any change, he/she changes his/ her mind if the peers or rest of team stick to the resistance.
  • Competence concern: If anyone is highly compatible to any particular workflow, then he/ she can resist changes because of performance worry. They remain indecisive because they fail to acquire knowledge of how PAM can ensure better security and not affect anybody’s performance.
  • More work pressure: Employees presume that introducing PAM would increase their work-load.

All the above points, as we observe, are mostly human presumptions which dominate the hindrance of technological progress. Today, cyber threats are getting sophisticated in nature and it requires a highly advanced solution to secure information assets from malicious actors. While organizations have no other option but to strengthen their IT security infrastructure with a robust and advanced risk-control solution, resistance to changes stops it from any kind of development.

(In the next part of this blog we will share how to overcome this situation… keep posted)

ARCON is a leading enterprise risk control solutions provider, specializing in risk-predictive technologies. ARCON | User Behaviour Analytics enables to monitor end-user activities in real time. ARCON | Privileged Access Management reinforces access control and mitigates data breach threats. ARCON | Secure Compliance Management is a vulnerability assessment tool.

Securing Enterprise Data – The Soul of any Business

In a continuously evolving technological landscape, global organizations are coming across new challenges to store and protect a huge amount of business data generated every day. While data being the core of any business, it plays the most important role in maintaining business continuity in any industry. While many organizations go all the way to protect tons of data generated every day, few are partially concerned about the security and the remaining stay least bothered about the security of their data assets.

Types of Data and why it is important

Numerous types of data are generated and accumulated in organizations both from outside and internally every day. The amount of data varies according to industry and it continuously changes its volume, shape and pattern. As water is the most essential element of human body for survival, similarly data is the “water” for organizations to survive in business. As we never question the importance of water, similarly the importance of data is never questioned. Organizations consider it to be a treasure which is generally classified as below:

  • Financial Data
  • Accounting Data
  • Sales Data
  • Business Contracts
  • Customer Information
  • Ongoing and Upcoming Project Blueprints
  • Employee Details
  • Payrolls
  • Operations Records
  • Other types of Confidential Information

Depending on the industry, this list is apparently never ending. In addition, if we think critically, every data captured, processed or distributed are crucial for any organization. Under any circumstances, this data deserves utmost security to ensure business continuity. If this data is affected by any means, it can lead to huge financial loss, reputational damage or even lock-down of business. Hence, organizations have no other choice apart from taking adequate security measures to prevent any kind of breach.

Why & How Data is Vulnerable?

Today organizations spend millions on evolving technologies, research & development, modern devices etc. but most of the time IT security measures are ignored which secures the business from multiple risk factors. Cyber crooks are always in search of lucrative data which is easy to hack and can be sold in dark web easily. They are getting technologically more advanced who target enterprise network, databases and applications. Most of the time, they pose as barriers to organizations’ overall growth and prosperity. Instances have been found where a single hacker affected more than 40 companies across the globe from retail, e commerce, manufacturing, BFSI and hospitality industry in a span of 2 months time. This shows the extent of damage a hacker can incur to exploit data assets.

Organizations on the other hand are quite oblivious about the importance of data security most of the time. Due to their scant attention, hackers find in easy to dig into the mine of data with their anomalous activities. It is imperative for organizations to start giving adequate attention to the security of inner peripheries and restructure security and control mechanisms to avoid any possible disaster. It is also important for the organization to create an arch over the network which can continuously monitor the user activities and prevent anything suspicious. Simultaneously, upgrading those security measures regularly is also important because the pattern of cyber threats are getting sophisticated day by day.

Bottom line: Data, being the soul of any business, should be protected with robust IT security measures to predict and prevent possible cyber threats before it’s too late.

ARCON is a leading enterprise risk control solutions provider, specializing in risk-predictive technologies. ARCON | User Behaviour Analytics enables to monitor end-user activities in real time. ARCON | Privileged Access Management reinforces access control and mitigates data breach threats. ARCON | Secure Compliance Management is a vulnerability assessment tool.