Backing the human firewall for better protection

Issue 7 2021 Security Services & Risk Management

Despite the easing of lockdown regulations, working from home remains a business necessity for many people. And this continues to present companies with new forms of cybersecurity risks that take advantage of ongoing market fluxes and uncertainty. This is where the concept of the human firewall becomes critically important.

At its most basic, a firewall is a computer network security system that restricts Internet traffic in, out, or within a private network. A human firewall, on the other hand, combines security awareness and training solutions to deliver a comprehensive way for organisations to protect all levels of their structure, regardless of where people are working from. Essentially, this concept centres on continued employee awareness training to ensure that remote workers understand best practice when it comes to cybersecurity.

This training is not a once-off process but reflects evolving attack perimeters, especially given how a distributed work environment has created new vectors which malicious users can exploit. So, beyond investing in comprehensive anti-virus and endpoint protection software, creating awareness about keeping family members away from work devices and ensuring the organisational virtual private network (VPN) used is as strong as possible, companies must commit to user education across all levels of the business, to minimise their employees posing unnecessary cyber-related risks to the business. Whether it is C-suite executives, a salesperson, an administrative staff member, or the receptionist, consistent training must form an integral part of any company’s cybersecurity strategy.

A security aware culture

At a time when artificial intelligence (AI), machine learning (ML) and robotic process automation (RPA) are becoming part of the norm with employees reskilling and upskilling themselves for a digitally-led environment, so too must this skill set expand to incorporate cybersecurity. It is all about minimising human error, understanding how malware such as ransomware and phishing attacks perpetrate the company network and being vigilant of social engineering tactics when using remote devices.

After all, the best cybersecurity solutions in the world mean little if an employee still clicks on a malicious email, submits sensitive data on a spoofed website and the like. Training must also be adapted to the skill set, knowledge and responsibilities of individual employees.

The content must reflect the current threat landscape and provide guidance on likely future scenarios. It is especially important for smaller businesses to create a security aware culture when employees are working from home and not inside the relative safety of the corporate network. These companies can ill-afford a data breach which could potentially result in significant financial damage and possibly even business closure.

Even though cybersecurity policies must be updated as a matter of course, the reality is that employees must practically understand what they can and cannot do especially when working remotely. Theory is important, but the rapidly evolving threat landscape means that there should be ongoing updates to knowledge bases that include documentation, online materials, email updates and the like.

The new normal is here to stay for the foreseeable future. It is up to the companies themselves to maintain their cybersecurity awareness to safeguard their most important assets.


Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Your Wi-Fi router is about to start watching you
News & Events Surveillance Security Services & Risk Management
Advanced algorithms are able to analyse your Wi-Fi signals and create a representation of your movements, turning your home's Wi-Fi into a motion detection and personal identification system.

Read more...
Cybersecurity and insurance partnership for sub-Saharan Africa
Sophos News & Events Information Security Security Services & Risk Management
Sophos and Phishield Announce first-of-its-kind cybersecurity and insurance partnership for sub-Saharan Africa. The SMARTpod podcast, discussing the deal and the state of ransomware in South Africa and globally, is now also available.

Read more...
Corporate and academic teams can register for Kaspersky contest
Kaspersky News & Events Information Security
Kaspersky has announced the registration opening for its new Kaspersky{CTF} (Capture the Flag) competition, inviting academic and corporate teams from around the globe to compete in a battle of skill, strategy and innovation.

Read more...
FICA in the era of deepfake and AI-driven fraud
Security Services & Risk Management
A growing fraud strategy involves leveraging AI to produce highly convincing fake images, videos, and audio, commonly referred to as deepfakes, which are used to impersonate real individuals and spread misleading or false information.

Read more...
Protect your smart home devices
Kaspersky IoT & Automation Information Security Smart Home Automation
Voice assistants, kitchen robots, smart lights and many other intelligent devices have become part of our everyday life. However, with the rise of smart technology comes the need for robust protection against potential vulnerabilities.

Read more...
Survey highlights cost of cyberdamage to industrial companies
Kaspersky Information Security News & Events
The majority of industrial organisations estimate their financial losses caused by cyberattacks to be over $1 million, while almost one in four report losses exceeding $5 million, and for some, it surpasses $10 million.

Read more...
Cybersecurity a challenge in digitalising OT
Kaspersky Information Security Industrial (Industry)
According to a study by Kaspersky and VDC Research on securing operational technology environments, the primary risks are inadequate security measures, insufficient resources allocated to OT cybersecurity, challenges surrounding regulatory compliance, and the complexities of IT/OT integration.

Read more...
Risk management and compliance enforcement
Security Services & Risk Management
Having a risk management and compliance programme (RMCP) is not just a procedural formality; it is a legal requirement under Section 42 of the Financial Intelligence Centre Act (FICA).

Read more...
The dangers of poor-quality solar cables
Security Services & Risk Management Smart Home Automation
Reports indicate that one in six fires attended by South African firefighters is linked to substandard solar installations, often due to faulty wiring or incompatible components.

Read more...
Growing risks for employers
Security Services & Risk Management
With South Africa’s unemployment rate exceeding 32% and expected to rise beyond 33% this year, desperation is fuelling deception in the job market. Trust is no longer a given, it is a gamble.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.