Watching Your 1’s and 0’s
The recent announcement by Marriott that the Starwood reservation system appears to have been compromised for about 4 years serves as a useful reminder that, as unexciting as it may seem, you need to get your people to take cybersecurity and data protection seriously.
Whether it’s doing online security training, installing updates, or following the rules about about attaching personal phones and flash drives to company computers, cyber security is often a low priority for everyone but the IT team. So how do you get people to do what needs to be done to protect your systems?
Well, how do you get people to do anything?
You can try telling them, setting requirements and directing them to follow them. Chances are, though, you’re already doing that; how is that working out for you? To make this work, you probably need some sort of punishment associated with lack of compliance. This method isn’t going to get people to be compliant because they want to or even feel they need to, but instead, they’ll be compliant just to avoid having their network privileges revoked or whatever punitive action you take. Still, maybe that’s enough; what you want is for people to follow the rules, and you probably don’t much care if they enjoy it.
Another method is to persuade them by showing what happens to companies when systems get compromised. A 2017 cyberattack that seemed to get out of control ended up costing Maersk shipping around $300 million, while other companies saw losses approaching a billion dollars. Maersk had identified security vulnerabilities but the proposed upgrade was not included in the IT department’s KPIs and subsequently never happened, proving to be a very costly mistake. When people see the potential impact on them personally — for example, the chance their employer could go out of business and they could lose their job — they may be persuaded to take this more seriously.
You might consider trying to inspire them to comply. Maybe you won’t have cheerleaders running around to get everyone excited about cybersecurity (or maybe you will), but consider how small prizes or some kind of gamified process could get people more motivated to follow through on what you need them to do. When your employees see some kind of direct benefit to themselves, they attach more importance to the effort. You may feel like you shouldn’t have to offer incentives for people to do what you need them to do, but if you want people to see something as a priority, then you need to make it a priority too, and your actions will always speak louder than words.
Finally, consider how you could collaborate with your team to find a way to get everyone on board with your requirements. Instead of just telling people “this is what you have to do,” consider instead saying, “here’s the requirement, how do you think we can meet it the best?” When people have an input into a process they tend to feel a sense of ownership of that process, and finishing it satisfactorily becomes more important to them. When you get people to collaborate in terms of how they do their regular job, you can see the difference between getting someone’s best effort and getting the bare minimum. When it comes to your cyber security and data protection, it may be the difference between having them do it or having them not do it.
Different leadership and communication styles are useful in different situations. The ideas above can be applied to any aspect of work, not just the cyber and data protection stuff. But for the moment, with all the news about breaches and their impact, you may want to focus a bit on keeping your networks secure.
By the way, if you have stayed at a Starwood property in the last 4 years, you may want to check out their website for responding to the hack.
- Posted by
Designing Leaders - Posted in Management
Dec, 17, 2018
Comments Off on Watching Your 1’s and 0’s
Categories
- Book Reviews
- Change
- Communication
- COVID-19
- Creativity & Innovation
- Culture
- Diversity & Inclusion
- Employee Development
- Ethics
- Free Agents
- Health and Balance
- Leader Development
- Leading
- Management
- New Leaders
- Planning
- Recruiting and Retention
- Uncategorized
Archives
- August 2020
- July 2020
- June 2020
- October 2019
- September 2019
- August 2019
- July 2019
- June 2019
- May 2019
- March 2019
- February 2019
- January 2019
- December 2018
- November 2018
- October 2018
- September 2018
- August 2018
- July 2018
- June 2018
- May 2018
- April 2018
- March 2018
- February 2018
- January 2018
- December 2017
- November 2017
- October 2017
- September 2017
- August 2017
- July 2017
- June 2017
- May 2017
- April 2017
- March 2017
- February 2017
- January 2017
- December 2016
- November 2016
- October 2016
- September 2016
- August 2016
- July 2016
- June 2016
- May 2016
- April 2016
- March 2016
- February 2016
- January 2016
- December 2015
- November 2015
- October 2015
- September 2015
- August 2015
- July 2015
- June 2015
- May 2015
- April 2015
- March 2015
- February 2015
- January 2015
- December 2014
- November 2014
- October 2014


Dec, 17, 2018