Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

US military can teach CEOs about cybersecurity and building a high-reliability organisation

by The Gurus
August 20, 2015
in Editor's News
Share on FacebookShare on Twitter

•    Most successful cyber-attacks are down to human error not inadequate technology – cyber-security is a leadership issue
•    Shortsightedness in the C-suite is a serious problem: CEOs need to take charge and create high-reliability organisations
•    To do so, they should embrace the core principles practised by the US military that consistently minimise risk and successfully repel more than 30 million cyber-attacks a year 

As organisations worldwide continue to fall victim to cyber-attacks made possible by the mistakes of their own network administrators and users, a new report shows how CEOs can take a cue from the US military and create high-reliability organisations (HROs) that consistently guard against cybercrime.
An article published in the Harvard Business Review, Cybersecurity’s Human Factor: Lessons from the Pentagon, by James A. Winnefeld Jr., Christopher Kirchhoff, and David Upton, identifies the six principles at the heart of the US military’s success in stopping attacks on its systems and quickly containing the few intrusions that occur. Crucially, the authors also indicate how the principles can be put into practice in other types of organisations.
‘A recent survey by Oxford University and the UK’s Centre for the Protection of the National Infrastructure found that concern for cybersecurity was significantly lower among managers inside the C-suite than among managers outside it. Such shortsightedness at the top is a serious problem,’ said David Upton, American Standard Companies Professor of Operations Management at Saïd Business School, University of Oxford. ‘The reality is that if CEOs don’t take cybersecurity threats seriously, their organisations won’t either …  They must marshal their entire leadership team—technical and line management, and human resources—to make people, principles, and IT systems work together.’  
The core principles that have enabled the US military successfully to fend off more than 30 million known malicious attacks work together to create a culture that leads people, without exception, to eliminate ‘sins of commission’ (deliberate departures from protocol) and own up immediately to mistakes. They understand all aspects of the system, and know and follow all operational procedures to the letter, which means that they listen and respond to their own internal alarm bells, helping them to forestall potential problems. 
The authors acknowledge that inculcating these principles into an organisation with a formal command structure such as the military may be easier than in a looser, more democratic organisation. However, they have identified measures that leaders in any organisation can take to embed these principles in employees’ everyday routines. 
1.    Take charge. CEOs should ask themselves and their leadership teams tough questions about whether they’re doing everything possible to build and sustain an HRO culture. Meanwhile, boards of directors, in their oversight role, should ask whether management is adequately taking into account the human dimension of cyberdefense.
2.    Make everyone accountable.  All managers—from the CEO down—should be responsible for ensuring their reports follow cybersafety practices. Managers should understand that they, along with the employees in question, will be held accountable. All members of the organisation ought to recognise they are responsible for things they can control.
3.    Institute uniform standards and centrally managed training and certification. Merely e-mailing employees about new risks is not enough. Nor is an annual course on digital policies, with a short quiz after each module. Cybersecurity training should be as robust as programmes to enforce ethics and safety practices, and companies should track attendance. After all, it takes only one untrained person to cause a breach.
4.    Couple formality with forceful backup. Be clear about who is in charge of what, and what users are and are not allowed to do. Regularly reminding employees that their adherence to security rules is monitored will reinforce a culture of high reliability.
5.    Check up on your defenses. CEOs should invest more in capabilities for testing operational IT practices and expand the role of the internal audit function to include cybersecurity technology, practices, and culture. Scheduled audits should be complemented by random spot-checks to counter the shortcuts and compromises that creep into the workplace.
6.    Eliminate fear of honesty and increase the consequences of dishonesty. Leaders must treat unintentional, occasional errors as opportunities to correct the processes that allowed them to occur. However, they should give no second chances to people who intentionally violate standards and procedures.

The Harvard Business Review article can be found here: 
https://hbr.org/2015/09/cybersecuritys-human-factor-lessons-from-the-pentagon

ShareTweet
Previous Post

UK Teenage FBI hacker charged under Computer Misuse Act

Next Post

Data of over 14,000 Government officials compromised in Ashley Madison breach

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol