Insights

/ Insights / Cybersecurity: We know the risks, but what about behavior change?

Free thinking from Grayling people

Cybersecurity: We know the risks, but what about behavior change?

10th November 2017


A recent report from National Cyber Security Alliance found that most Americans are more concerned about having their identity stolen than losing their main source of income. At the same time, according to the National Institute of Standards and Technology, six in 10 admitted to not changing their passwords regularly and reusing login credentials across multiple sites (security 101!).

As a communicator, this contradiction tells me a few things. First, that breaches like Equifax and Yahoo! are making consumers sit up and take notice. Second, that cybersecurity companies pumping millions of dollars into PR and advertising are actually getting through to the average American (phew!). But the third thing it tells me is the most concerning, namely that although the public understands the risks and knows what’s at stake, that for all the fearmongering, behavioral change isn’t happening.

Consumers – and businesses - are almost continually bombarded with commercials that tell them (I’m paraphrasing) “your security is at risk – buy our product!” This clearly isn’t working. To effect change, security companies must take a more constructive approach to their messaging. Think public education; think a collaborative approach to solving the hacking crisis. Point solutions and FUD just aren’t resonating.

At the enterprise level, driving action is even more difficult. According to PWC, the overwhelming number of security incidents are caused by employees, former employees or trusted contractors that are already inside your network. Given that the previously mentioned NCSA survey found that nearly all Americans were at least “somewhat concerned” about having their identity stolen, it’s hard to make an argument that the average office worker is unaware of the impact that a breach could have on their employer. Rather, it’s that they just don’t care.

At both the public and enterprise level, security companies are failing to achieve their number-one objective: to change behaviors. Sure, most Americans know they should be doing something to make their own identities and their employers’ data secure. But whether it’s that they’re overwhelmed with the choices presented to them, or that they simply believe that it won’t happen to them, they’re not taking precautionary measures.

Here’s my advice – stop selling just for a minute and start educating. Cybersecurity has the potential to be our next national crisis and it’s on us all to stem the bleeding before it’s too late.

Elliott Suthers is a Grayling senior vice president in San Francisco.


Grayling Team

Latest Insights

14th December 2017


Chile and Peru find a voice

Max Cano of Grayling’s Chilean affiliate, Mazicorp, shares his thoughts on following his attendance at a communications industry conference in Brazil.I recently returned from Brazil, where my...

Read More

14th December 2017


Play Time

Loretta Ahmed, CEO Grayling Middle East and Africa, looks at how injecting fun into every aspect of brand communication can increase customer engagement. In 2018 smart marketers will drive purpose and...

Read More

13th December 2017


Small is the New Big

As the pace of change gets faster, organizations of all sizes are embracing the start-up mentality. In the latest of our 2018 Trends predictions, Grayling’s San Francisco MD, Alan Dunton explains...

Read More