{"641487":{"#nid":"641487","#data":{"type":"news","title":"Building a Culture of Cybersecurity","body":[{"value":"\u003Cp\u003EEvery day, cybersecurity becomes more important than the day before. As organizations increasingly rely on digital software to house data and run systems, cyber-attacks in turn become progressively threatening. This widespread digitalization gives cyber attackers more surface area to work, and resulting attacks could yield devastating consequences.\u003C\/p\u003E\r\n\r\n\u003Cp\u003EDespite this trend, cybersecurity continues to lag as a priority in many organizations, leaving them vulnerable to such attacks.\u0026nbsp;\u003Ca href=\u0022https:\/\/pe.gatech.edu\/blog\/remote-work\/transition-to-remote-work\u0022 rel=\u0022noopener noreferrer\u0022 target=\u0022_blank\u0022\u003EAs entire workforces shift to remote work\u003C\/a\u003E, here are a few insights from cybersecurity experts at Georgia Tech, including current trends and practices that professionals can use to support the development of a culture of cybersecurity within their organization.\u003C\/p\u003E\r\n\r\n\u003Ch2\u003EVulnerabilities as a Result of COVID-19\u003C\/h2\u003E\r\n\r\n\u003Cp\u003ECOVID-19 has compounded the complexity of cybersecurity. Shelby Allen, research engineer and instructor for Georgia Tech Professional Education\u0026#39;s (GTPE)\u0026nbsp;\u003Ca href=\u0022https:\/\/pe.gatech.edu\/certificates\/cybersecurity-certificate\u0022 rel=\u0022noopener noreferrer\u0022 target=\u0022_blank\u0022\u003ECybersecurity Certificate\u003C\/a\u003E, notes three major vulnerabilities that organizations face more because of the pandemic: phishing attacks, more unique and\/or unpredictable cyber-attacks, and general exhaustion among employees and IT staff. \u0026ldquo;The technology will keep running,\u0026rdquo; Allen explains, \u0026ldquo;but we need to keep it updated and deployed, and we need to keep everyone educated and vigilant.\u0026rdquo; Additionally, the\u0026nbsp;\u003Ca href=\u0022https:\/\/pe.gatech.edu\/blog\/industry-trends\/remote-work-cyber-threats\u0022 rel=\u0022noopener noreferrer\u0022 target=\u0022_blank\u0022\u003Enature of remote work simply provides more leverage for a cyber-attack\u003C\/a\u003E. More operations and data are online, and, because employees work from their own laptops and homes, IT security measures are less consistent.\u003C\/p\u003E\r\n\r\n\u003Ch2\u003EThe \u0026quot;People\u0026quot; Component of Cybersecurity\u003C\/h2\u003E\r\n\r\n\u003Cp\u003EEvery cybersecurity program requires three components: people, process, and technology. Anant \u0026ldquo;Jimmy\u0026rdquo; Lummis, chief information security officer at Georgia Tech, emphasizes that while technology gets the most attention, people may be the most important. \u0026ldquo;People\u0026rdquo; does not only refer to cybersecurity professionals, it also means the holistic network of employees that create the culture of the company. \u0026ldquo;Cybersecurity professionals can do a lot to help secure an organization, but they will always be outpaced by the many people in an organization that do things every day,\u0026rdquo; Lummis explains. \u0026ldquo;If the culture in the organization doesn\u0026rsquo;t understand their responsibility with respect to cybersecurity, bad things will continue to happen.\u0026rdquo; Only through this professional culture can cybersecurity become a top priority and reliable defense for any organization.\u003C\/p\u003E\r\n\r\n\u003Cp\u003EOver the 15 years that Lummis has spent in the cybersecurity field, he has seen a promising shift toward prioritizing cybersecurity. In a recent\u0026nbsp;\u003Ca href=\u0022https:\/\/www.gartner.com\/en\/newsroom\/press-releases\/2020-10-20-gartner-survey-of-nearly-2000-cios-reveals-top-performing-enterprises-are-prioritizing-digital-innovation-during-the-pandemic\u0022 rel=\u0022noopener noreferrer\u0022 target=\u0022_blank\u0022\u003EGartner survey of CIOs across the country\u003C\/a\u003E, 61% of respondents reported that they were increasing digital business spending directly related to cyber threats. However, cybersecurity measures cannot fully protect an organization without the support and cooperation of the entire organization. The main challenge in cybersecurity today is imparting the responsibility of cybersecurity to all levels of an organization, not just the top.\u003C\/p\u003E\r\n\r\n\u003Ch2\u003EBuilding a Culture of Cybersecurity\u003C\/h2\u003E\r\n\r\n\u003Cp\u003ERaheem Beyah, Ph.D., vice president of research for Georgia Tech and executive director of the\u0026nbsp;\u003Ca href=\u0022https:\/\/pe.gatech.edu\/degrees\/cybersecurity\u0022 rel=\u0022noopener noreferrer\u0022 target=\u0022_blank\u0022\u003EOnline Master\u0026#39;s of Science in Cybersecurity program\u003C\/a\u003E, has outlined a few simple steps to build a successful incident response team and increase the culture of cybersecurity in your organization. First, be thoughtful in how you build your team. While having the right technical expertise is important, it is ideal to complement the skills of your team members with the abilities of the leader. Then, ensure your team is a comprehensive and inclusive representation of the organization they protect. Finally, teach yourself and others to embrace change. When technology changes, business processes will have to change, which means that management will also have to change to bring your team through the change successfully.\u003C\/p\u003E\r\n\r\n\u003Cp\u003EThe leaders of an organization must openly promote and prioritize cybersecurity training to foster a more reliable framework of cybersecurity. \u0026ldquo;You have to have support from the C-suite team that this is a high priority,\u0026rdquo; Beyah emphasizes. \u0026ldquo;It starts by the CEO appreciating the importance of security training and other things that may not seem immediately important to the bottom line but are critical for the integrity of the organization.\u0026rdquo;\u003C\/p\u003E\r\n\r\n\u003Cp\u003EOnce the executive leadership prioritizes security, they must encourage and expect individual responsibility and accountability on all levels. \u0026ldquo;You have to tell people what you expect them to do,\u0026rdquo; Lummis says. \u0026ldquo;People\u0026rsquo;s performance should be evaluated based in part on cybersecurity, given that they have the tools for success.\u0026rdquo; Expecting cyber-secure responsibility from employees on all levels will not only strengthen your organization\u0026#39;s cybersecurity but will also communicate the individual value of every member of your organization.\u003C\/p\u003E\r\n\r\n\u003Ch2\u003EEffective Cybersecurity Training\u003C\/h2\u003E\r\n\r\n\u003Cp\u003E\u0026quot;Those expectations for success along with effective training is the most important component in ensuring a persistent culture,\u0026quot; points out Renita Folds, manager of information and cyber sciences program office and research associate at Georgia Tech Research Institute (GTRI). Because the cyber attacker is becoming more sophisticated and prevalent, it is even more important for companies to identify and address security risks before an attack occurs, especially because most data breaches are caused by human error. \u0026ldquo;On a large scale, people are easier to compromise and exploit than finding that software vulnerability,\u0026rdquo; Folds explains. Therefore, the most pressing need in cybersecurity training is increasing employees\u0026rsquo; awareness of and ability to identify cyber-threats and attacks\u0026mdash;establishing a \u0026ldquo;human firewall.\u0026rdquo;\u003C\/p\u003E\r\n\r\n\u003Ch2\u003EA Team Responsibility\u003C\/h2\u003E\r\n\r\n\u003Cp\u003EA common thread throughout cybersecurity is people. People are the greatest barrier to establishing an effective cybersecurity culture and the most vulnerable aspect of it, and yet people are the most important key to creating and strengthening it. Ultimately, cybersecurity depends on every individual in an organization, no matter what position they hold.\u003C\/p\u003E\r\n\r\n\u003Cp\u003E\u0026ldquo;It\u0026rsquo;s not just the responsibility of the IT team or your cyber team, it\u0026rsquo;s the responsibility of everyone in the organization to maintain that cyber-secure environment,\u0026rdquo; Folds says. \u0026ldquo;The bottom line is that humans are still the weakest link in cybersecurity, so we have to have\u0026nbsp;\u003Ca href=\u0022https:\/\/pe.gatech.edu\/subjects\/defense-technology\/cybersecurity\u0022 rel=\u0022noopener noreferrer\u0022 target=\u0022_blank\u0022\u003Econsistent cybersecurity training\u003C\/a\u003E\u0026nbsp;on how to recognize threats and what to do about them. As attackers step up their game, we have to do the same thing on the training side.\u0026rdquo;\u003C\/p\u003E\r\n","summary":null,"format":"limited_html"}],"field_subtitle":[{"value":" Why human firewalls and virtual tools are essential to protect your organization, information, and remote workforce"}],"field_summary":"","field_summary_sentence":[{"value":"Learn how new cyber risks stemming from COVID-19 require building a cybersecurity culture and how to ensure your employees are cyber-ready."}],"uid":"34615","created_gmt":"2020-11-20 14:52:20","changed_gmt":"2020-11-20 14:52:20","author":"Kelsey Harris","boilerplate_text":"","field_publication":"","field_article_url":"","dateline":{"date":"2020-11-20T00:00:00-05:00","iso_date":"2020-11-20T00:00:00-05:00","tz":"America\/New_York"},"extras":[],"groups":[{"id":"1258","name":"Professional Education"}],"categories":[{"id":"129","name":"Institute and Campus"}],"keywords":[],"core_research_areas":[{"id":"145171","name":"Cybersecurity"}],"news_room_topics":[],"event_categories":[],"invited_audience":[],"affiliations":[],"classification":[],"areas_of_expertise":[],"news_and_recent_appearances":[],"phone":[],"contact":[{"value":"\u003Cp\u003EGeorgia Tech Professional Education\u003Cbr \/\u003E\r\n\u003Ca href=\u0022mailto:gtpe-communications@pe.gatech.edu\u0022\u003Egtpe-communications@pe.gatech.edu\u003C\/a\u003E\u003C\/p\u003E\r\n","format":"limited_html"}],"email":["gtpe-communications@pe.gatech.edu"],"slides":[],"orientation":[],"userdata":""}}}