This metaphor could apply to a drive on an icy winter day, but it also could describe a naive employee using the Internet without giving a thought to cybersecurity.
The goal of a good cybersecurity official is to make employees aware “that I can protect them up to the point of ‘this,’” he said, noting that point will be different for every organization. “As long as you’re doing 25 mph on an icy road and you give yourself plenty of time to stop, you’re good to go. The minute you want to push it up to 90 mph — throw caution to the wind — I got nothing, you’re on your own. But they need to know when they’re on their own. They need to know that if I click this link or if I do ‘this’ that I’m accepting that risk.”
BONUS: Join FCC CIO David Bray for an exclusive webcast on Dec. 16, in which he will describe how a contractor owned and operated model aided the agency in IT management and transition. Register here.
The best cybersecurity officials can do is set the rules of the road and make sure everyone is aware of the consequences, according to Barloon.
That’s not an easy thing to do, particularly for technical experts that spend most of their time dealing with these things and see them as second nature.
Rather than browbeating employees into practicing good cyber hygiene, Barloon suggested explaining the risks and limitation of the agency’s cybersecurity posture. He used the driving analogy to bring the point home.
“Our users — my users — they really don’t care about the things we go through as cybersecurity professionals to do our job,” Barloon said. “When they wake up in the morning, they expect email to work, they expect being able to surf the Web to work.”
The key to good cybersecurity is finding that balance and communicating it clearly to the users.




