October 19, 2020

Using additional holidays to enthuse individuals regarding their Data Security role

One of the problems inherent in Data Security is that it is likely not to be the main focus of an individual's work (certainly for some it will be, but for most people in an organisation, they will have other primary goals). Yet, at the same time, Data Security Awareness must be maintained and increased at all times.

To promote enthusiasm in individuals to achieve a heightened level of Data Security Awareness, is therefore key. If this is set up as a competition, this is instantly less likely to succeed if the very people who are less enthused about pushing themselves, are likely to resign themselves to not winning such a competition and consequently will not try harder.

So to get the attention of the ones that are not that keen in the first place, why not focus them on extra time off - which, by a similar definition, may appeal to them better.

Do this by informing staff that there will be a series of tests being carried out by some friendly hackers (penetration tests) on an ongoing basis henceforth. Make sure that the purpose of the tests is also clearly explained (ie to discover how specific emails and enquiries are handled and whether this is carried out correctly by each individual).

Then those that pass those tests, get to have an extra half day, or even just 2 hours off. These can be applied, say, to Friday afternoons so that they can get away early for a weekend break. It may not be necessary to make them totally their choice as to when else they can be used - thus keeping some control over the use of these holidays. So if Wednesday mornings are always less busy, make it that people can earn the right of not coming in until 11am on a Wednesday. They can sleep in, or go shopping or do the housework or whatever, but the affect will be optimal for the individual and not overly detrimental to the organisation.

By applying this reward to all persons that pass the penetration testing, this removes the competitive nature and makes this a personal gain choice.

By applying this when it suits the organisation (eg Wednesday morning, in this example, or Friday afternoon) - but leaving the choice of which Wednesday morning or Friday afternoon to the individual, they are empowered by this benefit - rather than being controlled by it.

This will not work for everyone of course, but is is part of your armoury of approaches to address how to enthuse people to take Data Security seriously.

