Firstly: this may be a not-programming-related-question.
However: As a programmer who is very concerned about security, this is a question which weighs heavily on my mind, and directly affects my activities as a programmer.
The weak point in my systems is nothing about the systems themselves, but rather the users. So, what I need to do is to educate my users about security.
Things I would like to tell them about include:
- what the cost of a breach could be
- the computers really can't solve the problem (it's down to people)
- phishing / spear-phishing
- some awareness of the kinds of vulnerability that are out there
- why it can be disastrous just to click a nastly link in an email
Do you have any tips on how to educate users in this stuff?
In particular (bearing in mind that I am but a lowly grunt), any helpful suggestions about how to get senior people intersted in real-world solutions (not just rhetoric)?
Is there anyone who is an IT security guy (or gal)? I would really appreciate any war stories or real-life efforts from an experienced source.