Human Firewall

human firewall article image

When Cyber Security is discussed, I presume there is an assumption that we (who work in the area), focus on the technical elements of security. Whilst that is predominantly the case, it’s not wholly true.

People are key to a successful cyber security defence strategy, not only are they prime users and support elements for IT systems, they can also highlight issues and spot security vulnerabilities that need to be fixed. This is to ensure the security posture of the organisation remains as high as it can be. Humans (or people) are your first line of defence.

The human firewall is essentially what you may think it is, it’s a concept that a human can act like a technical firewall. In theory, having the ability to identify cyber threats and report/alert on them, by having the appropriate training, awareness and knowledge.

How to implement a Human Firewall

To implement a successful human firewall programme, an organisation needs to understand its scope. Generally, this should be all staff and they should understand how security fits in to their day to day working life.

The key elements of any human firewall are targeted, relevant & interesting security and awareness training. It’s vitally important that any training is suitable and interesting, as believe it or not, security can be a dry subject to many. Keeping it relevant with references to real world events and the impact it can have on personal life, identity and any financial impact, can help focus the mind. This type of training must be ongoing with continuous engagement, to be effective. The training should give the employees the tools to identify threats such as, but not limited to;

  • Phishing
  • Social engineering
  • Scammers/Fraudsters
  • Tailgating
  • Identity theft
  • Cyber Attacks
  • Ransomware
  • Vulnerable hardware/systems
  • Social media
 
Furthermore…

As well as training and empowering humans, you also need to give them the ability to report and learn from security events. Security incident management is a key element of the human firewall, as having people identify security issues without knowing where to report and act on them, is counterproductive.

Organisations also need to be committed to providing robust IT security systems, policy and processes, that are led from board level agreement and have support from senior management. Everyone in an organisation must be committed to ensure the human firewall is in place and working proactively. Security standards such ISO27001/2 give you the tools and advice to implement a security management regime, that includes a requirement for training and awareness.

 

Some of you may have seen or even attended our event ‘Life’s a Breach’ as part of Leeds Digital Festival 2021, which engaged attendees to find out who committed a cyber security crime in a small organisation.
CSP can provide help and guidance on thorough and targeted training and awareness activity, contact us here.
 

Leave a Reply

Your email address will not be published. Required fields are marked *