HomeSecurityWhich employees comply with security policies?

Which employees comply with security policies?

Compliance with security policies by a company's employees is particularly important, as failure to comply with them can put the company's data at risk and leave it exposed to attacks . This is the conclusion of a study by Binghamton University, State University of New York .

workers

According to the study, different groups within an organization influence whether or not employees violate policies . For this reason, the researchers suggest that there should be a general review of the design and implementation of security policies and that companies work with their employees to find ways to ensure seamless compliance with the rules.

“The frequency, scope and cost of data breaches have increased dramatically in recent years, and the majority of these incidents occur because people are the weakest link in the security chain. Employee non-compliance with security policies is one of the most significant factors,” said Sumantra Sarkar, associate professor of management information systems at Binghamton University’s School of Management.

"We wanted to understand why some employees were more likely to comply with security policies than others in an organization.".

Sarkar, along with his research team, sought to determine how employee groups influence compliance, especially in healthcare .

“Every organization has a culture that is usually set by top management. But within that, there are subcultures among different professional groups in the organization,” Sarkar said. “Each of these groups is trained differently and is responsible for different tasks.”

Sarkar and his fellow researchers focused on three subcultures found in a hospital: doctors, nurses, and support staff.

Which employees comply with security policies?

"Physicians, who are constantly dealing with emergencies, were more likely to leave a workstation unlocked. They were more concerned about the immediate care of a patient than the potential risk of a data breach," Sarkar noted.

“At the opposite extreme, support staff rarely kept workstations unlocked when they were away, as they felt they were more likely to be punished or fired in the event of a data breach.”

The researchers concluded that employees within an organization will respond differently to an organization's security policies, making companies vulnerable to a greater likelihood of data breaches.

“Information security professionals should have a better understanding of the day-to-day tasks of each professional group and then find ways to seamlessly integrate compliance into those tasks,” said Sarkar.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS