Artwork

Tom Stafford에서 제공하는 콘텐츠입니다. 에피소드, 그래픽, 팟캐스트 설명을 포함한 모든 팟캐스트 콘텐츠는 Tom Stafford 또는 해당 팟캐스트 플랫폼 파트너가 직접 업로드하고 제공합니다. 누군가가 귀하의 허락 없이 귀하의 저작물을 사용하고 있다고 생각되는 경우 여기에 설명된 절차를 따르실 수 있습니다 https://ko.player.fm/legal.
Player FM -팟 캐스트 앱
Player FM 앱으로 오프라인으로 전환하세요!

Are cybersecurity sanctions effective? A conversation with Dr. Mikko Siponen

33:32
 
공유
 

Manage episode 442011058 series 2978622
Tom Stafford에서 제공하는 콘텐츠입니다. 에피소드, 그래픽, 팟캐스트 설명을 포함한 모든 팟캐스트 콘텐츠는 Tom Stafford 또는 해당 팟캐스트 플랫폼 파트너가 직접 업로드하고 제공합니다. 누군가가 귀하의 허락 없이 귀하의 저작물을 사용하고 있다고 생각되는 경우 여기에 설명된 절차를 따르실 수 있습니다 https://ko.player.fm/legal.

Most organizations use sanctions as a way of enforcing cybersecurity policies and encouraging sound security behaviors. But few organizations ever test whether these sanctions are effective. Often they aren't; in fact, when used improperly sanctions can backfire. In this episode of Cyber Ways, Tom and Craig talk about sanctions and their effectiveness with Dr. Mikko Siponen of the University of Alabama's Culverhouse College of Business. Dr. Siponen is among the world's leading scholars when it comes to understanding the effects of sanctions on cybersecurity behaviors. Listen and learn how your organization can use sanctions more effectively.

Guest bio:

Dr. Mikko Siponen is Professor of Business Cybersecurity and Management at the University of Alabama's Culverhouse College of Business. He holds advanced degrees in Software Engineering, Information Systems, and Philosophy. A leading scholar in Information Systems, he ranks among the top 30 worldwide based on publications in premier journals. Professor Siponen is the only Finnish IS professor invited to join The Finnish Academy of Science and Letters. His expertise spans cybersecurity management, IS development, and philosophical aspects of IS. He has extensive experience as a visiting professor, consultant, and research leader internationally, with a particular focus on cybersecurity management.

Key Topics Discussed:

Sanctions and Cybersecurity Policies:

  • Effectiveness of Sanctions:
  • Sanctions can work even without prior direct experience.
  • Firsthand sanction experiences may enhance effectiveness.
  • Can backfire if perceived as unjust, leading to resentment.
  • Employees' Awareness and Knowledge:
  • Typically lack detailed knowledge of cybersecurity policies.
  • Inadequate training contributes to confusion and non-compliance.
  • Policies often conflict with practical organizational needs (e.g., link clicking).

Training and Effectiveness:

  • Deficiencies in Training:
  • Often generic and check-the-box nature, hence ineffective.
  • Rarely measured for effectiveness by providers.
  • Recommendations for Improvement:
  • Demand effectiveness metrics from training providers.
  • Training should reduce cybersecurity risks significantly.

Practical Implications and Recommendations:

  • Sanctions as a Deterrent:
  • Active Sanctions:
  • Monitored closely but can backfire if perceived as unjust.
  • Passive Sanctions:
  • Applied only when necessary, safer from backlash.
  • Communication and Awareness:
  • Clear, effective communication of cybersecurity policies and sanctions is crucial.
  • Must bridge the gap between policy and practical enforcement.
  • Balancing Fairness and Consistency:
  • Consistency across departments is vital to ensure fairness.
  • Fair sanctions are essential to prevent demotivation and resentment.
  • Sanction Implementation Tips:
  • Consider firm culture and employee perspectives.
  • Pilot test sanctions; gather employee feedback.
  • Obtain management support and recognize the impact of unions.

Understanding Employee Behavior:

  • Psychological Impact:
  • Sanctions can have long-term negative effects on employee perception.
  • Need for research on the psychological impact, especially for rule-breakers.

Current Research:

  • Dr. Mikko Siponen working on:
  • Understanding and prevention of cybercrime through offender-victim communication.

Industry Trends:

  • Increasing sophistication of threat actors, potentially enhanced by AI.

Takeaways for Security Managers:

  • Sanctions need careful, context-sensitive application.
  • Ensure policies are known, understood, and perceived as fair and justified.
  • Training must be specific, engaging, and measured for effectiveness.

Cyber Ways is brought to you by the Center for Information Assurance, which is housed in the College of Business at Louisiana Tech University. The podcast is made possible through a "Just Business Grant," which is funded by the University's generous donors.

https://business.latech.edu/cyberways/

  continue reading

26 에피소드

Artwork
icon공유
 
Manage episode 442011058 series 2978622
Tom Stafford에서 제공하는 콘텐츠입니다. 에피소드, 그래픽, 팟캐스트 설명을 포함한 모든 팟캐스트 콘텐츠는 Tom Stafford 또는 해당 팟캐스트 플랫폼 파트너가 직접 업로드하고 제공합니다. 누군가가 귀하의 허락 없이 귀하의 저작물을 사용하고 있다고 생각되는 경우 여기에 설명된 절차를 따르실 수 있습니다 https://ko.player.fm/legal.

Most organizations use sanctions as a way of enforcing cybersecurity policies and encouraging sound security behaviors. But few organizations ever test whether these sanctions are effective. Often they aren't; in fact, when used improperly sanctions can backfire. In this episode of Cyber Ways, Tom and Craig talk about sanctions and their effectiveness with Dr. Mikko Siponen of the University of Alabama's Culverhouse College of Business. Dr. Siponen is among the world's leading scholars when it comes to understanding the effects of sanctions on cybersecurity behaviors. Listen and learn how your organization can use sanctions more effectively.

Guest bio:

Dr. Mikko Siponen is Professor of Business Cybersecurity and Management at the University of Alabama's Culverhouse College of Business. He holds advanced degrees in Software Engineering, Information Systems, and Philosophy. A leading scholar in Information Systems, he ranks among the top 30 worldwide based on publications in premier journals. Professor Siponen is the only Finnish IS professor invited to join The Finnish Academy of Science and Letters. His expertise spans cybersecurity management, IS development, and philosophical aspects of IS. He has extensive experience as a visiting professor, consultant, and research leader internationally, with a particular focus on cybersecurity management.

Key Topics Discussed:

Sanctions and Cybersecurity Policies:

  • Effectiveness of Sanctions:
  • Sanctions can work even without prior direct experience.
  • Firsthand sanction experiences may enhance effectiveness.
  • Can backfire if perceived as unjust, leading to resentment.
  • Employees' Awareness and Knowledge:
  • Typically lack detailed knowledge of cybersecurity policies.
  • Inadequate training contributes to confusion and non-compliance.
  • Policies often conflict with practical organizational needs (e.g., link clicking).

Training and Effectiveness:

  • Deficiencies in Training:
  • Often generic and check-the-box nature, hence ineffective.
  • Rarely measured for effectiveness by providers.
  • Recommendations for Improvement:
  • Demand effectiveness metrics from training providers.
  • Training should reduce cybersecurity risks significantly.

Practical Implications and Recommendations:

  • Sanctions as a Deterrent:
  • Active Sanctions:
  • Monitored closely but can backfire if perceived as unjust.
  • Passive Sanctions:
  • Applied only when necessary, safer from backlash.
  • Communication and Awareness:
  • Clear, effective communication of cybersecurity policies and sanctions is crucial.
  • Must bridge the gap between policy and practical enforcement.
  • Balancing Fairness and Consistency:
  • Consistency across departments is vital to ensure fairness.
  • Fair sanctions are essential to prevent demotivation and resentment.
  • Sanction Implementation Tips:
  • Consider firm culture and employee perspectives.
  • Pilot test sanctions; gather employee feedback.
  • Obtain management support and recognize the impact of unions.

Understanding Employee Behavior:

  • Psychological Impact:
  • Sanctions can have long-term negative effects on employee perception.
  • Need for research on the psychological impact, especially for rule-breakers.

Current Research:

  • Dr. Mikko Siponen working on:
  • Understanding and prevention of cybercrime through offender-victim communication.

Industry Trends:

  • Increasing sophistication of threat actors, potentially enhanced by AI.

Takeaways for Security Managers:

  • Sanctions need careful, context-sensitive application.
  • Ensure policies are known, understood, and perceived as fair and justified.
  • Training must be specific, engaging, and measured for effectiveness.

Cyber Ways is brought to you by the Center for Information Assurance, which is housed in the College of Business at Louisiana Tech University. The podcast is made possible through a "Just Business Grant," which is funded by the University's generous donors.

https://business.latech.edu/cyberways/

  continue reading

26 에피소드

Όλα τα επεισόδια

×
 
Loading …

플레이어 FM에 오신것을 환영합니다!

플레이어 FM은 웹에서 고품질 팟캐스트를 검색하여 지금 바로 즐길 수 있도록 합니다. 최고의 팟캐스트 앱이며 Android, iPhone 및 웹에서도 작동합니다. 장치 간 구독 동기화를 위해 가입하세요.

 

빠른 참조 가이드

탐색하는 동안 이 프로그램을 들어보세요.
재생