Cybersecurity Fatigue Gets Us All Hacked

Nick Espinosa

Cybersecurity teams have a tendency to bombard their users with security notifications to the point where everyone starts to ignore them. Add to this the continuous news of major data breaches by large corporations, and what the world ends up with is cybersecurity fatigue. The criminal hackers know this and start leveraging our complacency against us. As an example, one of the most common types of attacks that prey on fatigue is multi-factor authentication (MFA). Many users get a lot of push notifications to keep logins alive, and users tend to start blindly accepting all the push authentication notifications, thinking they’re all legitimate. 

On top of this, a common mindset cybersecurity professionals see from users is the “well, my data is already out in the darknet, and that major hotel/retail store/etc. I do business with just got hit, and if they can’t defend themselves, what chance do I (or my business) have?” It’s a completely understandable position to take regarding the current state of the world. But, if we’re thinking through the issues with that mindset, we start to realize why this is problematic. Also, personal data ages over time. We move and change addresses, for example. We also change phone numbers, email addresses, jobs, titles, positions, credit card numbers and more. The data that makes a person who they are online may not be the same that was stolen years or even days ago. 

For businesses that gain fatigue it’s a loss of revenue due to reputation damage. How many customers will still want to do business with a company that got them breached? Will prospective customers, once they hear about this, want to do business together as well? What about proprietary information regarding how the business conducts their operations? If a business understood the “secret sauce” of a competitor, is that advantage still there? 

In order to spot fatigue in your users and business, consider some of these visible signs:

  • Ignoring updates to software and hardware. We primarily update everything in order to fix known vulnerabilities that can be exploited. 
  • Poor login practices. Employees who use weak passwords or the same passwords for everything and don’t enable MFA for logins, are also red flags. 
  • Using insecure remote access methods. Connecting to the corporate infrastructure without using at least a virtual private network or VPN connection is a serious risk. 
  • Failure to adhere to cybersecurity training. Untrained users open phishing emails and click on links. They also don’t realize pirated software is often infected. 

The good news is that cybersecurity fatigue can actually be addressed and even reversed. Savvy cybersecurity teams will take the following steps to ensure their users are more engaged in the cybersecurity process:

  • Run drills and tests that involve everyone. This helps to assess weakness in the defensive posture but also can be rather interesting for everyone involved if performed in an energetic way. 
  • Gamify the training without making it a competition. There a lot of training platforms that have humorous videos and even mini video games designed to challenge users to keep fresh on cybersecurity hygiene. 
  • Remove needless security choices from your users. They don’t need access to the control panel, for example. Updating systems can be automated without a need for their intervention. Finally, password managers that are both secure and helpful in generating good and unique passwords is also a must. 
  • Make cyber-hygiene a top-down involvement in the organization. If the CEO isn’t enthusiastic and the biggest cheerleader for cybersecurity, then no one will take it seriously. 

It takes effort, but with a streamlined approach and some perseverance, we can turn the tide of fatigue into something that interests everyone. Don’t let your company become the next victim to this correctable situation. 

 

Nick Espinosa is a cybersecurity expert, working with companies to design custom cyberdefense strategies. Learn more at www.securityfanatics.com.


Published: July 11, 2023

IN THIS ISSUE


Amid Wildfires, HVAC Systems Can Help Improve Indoor Air Quality and Save Lives

Recent wildfires have caused smoke and air quality issues in Canada and several areas of the United States. Canada’s fire season is just the beginning. Similar conditions are anticipated in several areas of the United States, according to CNN


ARCHITECTURAL: Styling Sheet Metal Into Bold Canopies

Multi-component systems at two retail grocery sites required attention to detail, careful coordination and a dedication to teamwork.


Cost Segregation Studies: The Forgotten Win-Win for Contractors

A cost segregation study is any real estate owner’s best friend. If you own buildings or are thinking about constructing a building to rent or use in your business, what could be better than a non-cash deduction to offset current-year taxable income?


Court Rejects First Amendment Challenge to Public-Sector PLAs

On June 14, a federal district court in Minnesota dismissed a constitutional challenge to four public-sector project labor agreements (or “PLAs”).


Creating a More Respectful Workplace

Throughout my time in the industry, I’ve seen (and heard) everything regarding the workplace environment. I grew up as a roofer and roofing contractor. As a kid, I was always in the shop, visiting job sites and learning about construction.


Cybersecurity Fatigue Gets Us All Hacked
Debt Ceiling Deal Details & More

Negotiators inked a deal to increase the federal debt ceiling and identify areas where they can curb spending. 


Family + Field — Mom Pods Ease the Transition Back to Work

Weather-ready lactation pods equipped with comfort conveniences will remove barriers to motherhood in the field.


HVAC: Delivering on Promises For A Safe, Collaborative Environment

The Helm Group helped the RUSH University Medical Center with its new facility, maximizing on-time and cost-saving services.


INDUSTRIAL: Sharing the Lime (Stone) Light

Coordination with other trades is the key to success for this Ohio landfill project.  


Inside the CEA National Issues Conference

The Construction Employers of America event offers a robust, ongoing dialogue with policymakers in Washington, D.C. concerning issues impacting the unionized construction industry.


RESIDENTIAL: The Role of Duct Cleaning in Residential HVAC

Vogel Heating and Cooling resolves residential customer concerns about HVAC and duct cleaning in Missouri.


Welcome New SMACNA Members