A Breach in Your e-Policy Approach

Companies do too little workforce training on IT-security issues, leaving them open to compliance and litigation problems. Most often, the problems come from employees trying to find workarounds to productivity issues coupled with ignorance of the policies. Malicious intent is usually not at the root of security lapses.

By David Shadovitz

In today's digital workplace, e-policies that touch the worlds of e-mail, the Internet, social networks and the like are commonplace. But do employees really understand what they should and shouldn't be doing?

A recent study by Clearswift, a Reading, U.K.-headquartered information-security firm, suggests the answer may often be "no."

In the study of roughly 2,000 office workers, nearly three-quarters (74 percent) of the respondents said they feel "confident" that they understand their company's Internet and e-mail policies. But when asked about the e-policy training they've received, more than one-third (38 percent) said they hadn't received any IT-security training since joining their companies.

"If you put these figures in the context of technologies such as social media and Web 2.0, these figures are pretty alarming," says Andrew Wyatt, chief operating officer for Clearswift. "The pace in which technology moves forward means you can't conduct training every three or four years. You need to do it on a more regular basis, at least every 12 months."

Other experts say the training should be even more frequent.

"Sometimes, when we talk about training, we think it means getting employees together to talk to them," says Michael R. Overly, a partner at Foley & Lardner in Los Angeles. "But there are a lot of different ways to deliver it."

One client, he says, regularly picks out a particular item from its policies that it's especially concerned about and creatively works it into an e-mail that's sent out to the workforce.

The Clearswift findings are in line with a joint study in 2009 by the American Management Association and The e-Policy Institute that found fewer than half (47 percent) of all organizations formally train employees about e-mail risks, policy and usage.

"It's one thing to have a policy in place -- and I recommend that 100 percent of companies have one -- but you can't stop with just a policy," says Nancy Flynn, executive director of The ePolicy Institute in Columbus, Ohio, and author of The e-Policy Handbook, now in its second edition. "You also have to educate employees about the individual and organizational risks."

Flynn notes that it's important for e-policies to address all forms of technology, even those not currently being deployed in the organization.

"Even if the employer hasn't introduced that technology into the workplace, you still should have a policy in place for it, because it's likely that your employees have brought it in through the backdoor," she says.

Employers would be foolish to think that an "untrained workforce is a compliant workforce," she says.

By not providing any formal training, Flynn says, employers are relying on their employees to take the initiative. "You're expecting them to walk into the HR office, grab a copy of the employee handbook and look up an e-mail or social-media policy," she says. "But even if an employee does pick it up and read it, there's no guarantee they actually understand it."

As part of e-policy training, Flynn believes it's important for employers to follow up with a quiz, thereby ensuring employees fully understand the risks and rules.

To be sure, experts say, the failure to properly train employees on what they should and shouldn't be doing can be costly.

Since the AMA and The e-Policy Institute began asking employers in 2001 what their No. 1 concern was when employees log onto to their systems, respondents consistently have cited legal concerns.

Nearly one-in-four employers (24 percent) report that a court or regulatory body subpoenaed employee e-mail in the past year, while nearly one in 10 employers (9 percent) have battled lawsuits that were directly prompted by employee e-mail, the AMA-e-Policy Institute study found.

Companies that support their e-policies with training are going to be in a much better position to defend themselves in court, experts say. Of course, training can take many different forms, from classroom instruction to conducting a webinar to sending out e-mail reminders.

"One of my roles at The e-Policy Institute is to serve as an expert witness in lawsuits," Flynn says. "First, I'm typically asked to evaluate employer's policies to see if they're up-to-date, adhere to best practices and are clear. But then I'm asked to look at the training programs and [offer an opinion on] whether the employer is educating employees about the policies and risks."

Her experience has been that "the courts will favor those organizations that back their policies with training."

Overly says many breaches occur because employees, in trying to get their jobs done, don't fully understand the consequences of their actions.

That opinion was echoed by 63 percent of the respondents in the Clearswift survey. They blamed breaches in security on ignorance or a lack of understanding. About 6 percent attributed breaches to malicious intent.

"Employees," Overly says, "will inevitably take it upon themselves to find workarounds that will almost inevitably be insecure."

Overly tells the story of a chief information officer of a large company who was convinced particular documents didn't exist because his company had a 30-day rotational back-up policy. "But when we brought in the person in charge of the back-up tapes, much to the shock of the CIO, the back-up tapes were on a 12-month rotation, because that person thought it would provide the company with greater protection," he says.

Ongoing e-policy training is more than just a good idea today, but a necessity, experts say.

"Any company that has anything to do with credit-card information has to comply with the Payment Card Industry Data Security Standards, which has contractual obligations for training your personnel on an ongoing basis," Overly says.

What's more, he adds, three states -- Nevada, Minnesota and, most recently, Washington -- and have incorporated some of these standards into state law.

To maximize the effectiveness of e-policy practices, Overly advises employers to write them in a way that's understandable to entire workforce.

"I do information security for a living and I'm a lawyer," he says, "yet I can't understand some of [employer policies I read]. So how is the guy in the mailroom going to understand them?"