Digital Safety
Regardless of their advantages, consciousness campaigns alone usually are not sufficient to encourage widespread adoption of cybersecurity greatest practices
01 Oct 2024
•
,
3 min. learn
![Cybersecurity Awareness Month needs a radical overhaul – it needs legislation](https://web-assets.esetstatic.com/tn/-x700/wls/2024/9-2024/cybersecurity-awareness-month.jpeg)
As we enter October, governments, non-profit organizations, cybersecurity distributors and lots of firms with company social accountability groups are all possible gearing as much as push out some helpful recommendations on staying secure on-line. With out even wanting on the official theme of this year’s edition of the campaign, I rattled off the same old recommendation to a colleague final week – use strong and unique passwords, allow multi-factor authentication (MFA), and avoid clicking on phishing links – and certain sufficient, I captured nearly all the details of this yr’s official “Safe Our World” theme.
Now, given the abundance of such well-intentioned steering circulating every October, you can be forgiven for pondering that this needs to be sufficient to assist create a secure and safe our on-line world. However is it, actually? Has this recommendation been efficient in driving significant behavioral change and in serving to handle the rising safety dangers of in the present day and tomorrow? Maybe it’s time to critically study the present strategy – and to confess that recommendation alone simply doesn’t reduce it.
Past suggestions and methods
After a decade of selling the identical steering (Cybersecurity Consciousness Month itself marks its 21st anniversary this yr), it’s time for the business to have a radical rethink and, alongside doing the speaking, legislate and implement higher cybersecurity practices, particularly the place personally identifiable info (PII) or different information of worth is at stake. I’m not sometimes a fan of fixing issues with laws and regulation, however the actuality is that we’re not seeing progress on the tempo that we have to. For instance, there are numerous widespread on-line providers and functions nonetheless don’t supply MFA, and even when they do, then it’s not enabled by default. Subsequent yr’s Cybersecurity Consciousness Month may very well be void of this subject solely if all firms storing PII are required to allow MFA on all consumer accounts by default.
Granted, there could also be accessibility considerations with MFA enabled by default, and if individuals who genuinely want to modify it off for some purpose then they need to be capable of decide out. For the remainder of the gang, nonetheless, enabling MFA by default needs to be the norm. Simply as many web sites at the moment nearly bury the choice to allow MFA, they need to equally cover the choice to modify it off.
Apple was one of many courageous firms in forcing MFA for all customers again in 2017. Did they lose customers? Did their share worth go down? After all, the solutions are “no”. When confronted with no various, customers will undertake an enhanced safety follow that retains their information and stuff secure. Give them a alternative and/or make the default off, and many individuals will take the better route, even when it could imply compromising their safety for comfort.
One other upside of switching MFA on by default for everybody is that it might considerably mitigate the dangers related to password recycling; in different phrases, a reused password backed by MFA is much less prone to trigger a difficulty. Nevertheless, this isn’t to say that it’s acceptable to make use of weak passwords or reuse passwords throughout websites. What I’m saying as an alternative is that the emphasis on sturdy and distinctive passwords will lower, because the added layer of MFA will tremendously assist forestall credential theft.
Certainly, when one thing resembling credential theft has continued as a serious problem for thus lengthy, it’s time for a rethink. We’ve seen efficient precedents for this; most notably, the Common Knowledge Safety Regulation (GDPR). The European Union (EU) realized that with out stringent regulation, firms would proceed down the trail of least resistance: accumulating information and storing it with out encryption in what was mainly a wild west strategy to information safety. It prices cash to maintain issues safe, so tight-pursed Chief Monetary Officers would prioritize short-term revenue over long-term safety. Nevertheless, GDPR modified this dynamic, as hefty regulatory fines justify the finances for correct information safety measures.
Laws to the rescue
Now think about Cybersecurity Consciousness Month subsequent yr with out the lecturing about fundamental safety practices resembling sturdy and distinctive passwords and MFA. After years of hammering these factors residence, the dialog may lastly evolve. The highlight may shift to rampant scams duping individuals out of their hard-earned money. I notice a few of that is coated in the present day, however far too typically it simply will get misplaced within the shuffle.
To all policy-makers on the market: it’s time to shift this dialog and legislate on what a number of the business has didn’t implement in order that the essential training on actual cybersecurity points can turn out to be the headline.