Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Time to educate the digital na(t)ives.

by The Gurus
September 10, 2015
in This Week's Gurus
Share on FacebookShare on Twitter

Time to educate the digital na(t)ives.

Each and every day we learn from the news about more or less sophisticated technical hacks that enable minor or major data breaches. In the best cases responsible disclosure models are applied to avoid these hacks to be in the wild at all. Most of the known issues are fixed within a more (e.g. Firefox) or less (e.g. Apple) reasonable timeframe and patched throughout many of the relevant installations. Several are not (and I am looking at you, Android).
But weaknesses and threats are not necessarily connected to e.g. sophisticated buffer overflow / malign code executions attacks in the first place. Many issues and problems, in both personal and corporate deployment scenarios result from individual wrongdoing. Many of us can be considered to be digital natives. So we should expect them and us to behave and act as responsible digital citizens, when it comes to security, data protection and maintaining personal privacy. The truth is: they are not and this is an ongoing challenge. A few examples:

  • It seems unbelievable but spam mails and their attachments (and users still clicking on them), drive by downloads and phishing attacks by mail, skype or messenger apps are still among the top 5 cyber security threats in 2015.
  • One of the most recognized data breaches of the recent weeks did not require a sophisticated attack vector. It was the disclosure of sensitive medical data by sending a mass mail with all recipient addresses in the to: rather than the bcc: Whether this was done by accident or because of lack of experience/expertise with the mail protocol, this could surely have been avoided. Through education, through diligence and maybe through some intelligent checking in the mail client (More than 10 to:-recipients? Let’s better reconfirm the user, if this really is what is wanted.). Have you never sent a quick mail to the wrong recipient, because the type-ahead functionality of your mail client picked another recipient than expected and you didn’t check? Had some embarrassing moments because of texting or chatting with the wrong recipient?
  • Again and again weak, reused or default passwords together with the unwillingness to activate multifactor authentication are continuing to be major threats. And if one thinks he or she is safe, checking whether your account has already been compromised might be salutary.
  • Let’s be honest: We all know those “power users”, who have loads of tools installed to “unlock the hidden powers” of their systems. Those self-appointed experts who manipulate registry entries and read every tech magazine or blog to change their systems default behaviour. Who run untrusted software and cut and paste code from geek sites to the command line or the terminal. And readily run arbitrary code with admin/root access, because otherwise this great new tweak doesn’t work.
  • On the other side there are those who still run outdated und unpatched systems like XP for various but definitely no good reasons.
  • The currently discussed issues regarding devices running older Android versions which suffer from the Stagefright vulnerability is a very real problem for many users. Apart from some patching initiatives and a few devices still maintained, there is a large fraction of Android devices left with no options to upgrade or patch the system. Continuing to use them puts all personal and additionally stored data at risk and every user is responsible for that.
  • Talking about responsibility: some systems do come with an appropriate security concept and with highly reliable mechanisms for protecting the users privacy and security. Undermining these mechanisms by jailbreaking/rooting these devices to gain more “freedom” from the vendor and of course especially the freedom to run pirated software from some shady “app store” for free has just recently again been proven to be not the cleverest idea.

The saying goes: “There is no patch for human stupidity”. But the issue is not stupidity but the lack of expertise. Both digital natives and the elder ones (a.k.a. the digital immigrants) tend to be over-challenged with the technologies available through their computers and mobile devices.
Users need to be educated and made aware of risks and threats. On the enterprise level the only possible “patch” for this issue is guidance through appropriate, complete and actionable policies and, as a result, constant and well-executed training. This is one of the essential responsibilities of a CISO. Appropriate educational programs for corporate users will likely be more successful if they cover aspects of both their daily business duties and their personal privacy and security. With both aspects constantly converging  in a world of BYOD (Bring your own device) this is of increasing importance anyway.
Education and awareness are equally important on a personal and private life level, but there won’t be a regular training program. So it is up to the individual, i.e. us. If you know better (and you do), first check your own behaviour and your systems, and improve them to an adequate level. Then tell your friends and family and demonstrate it through your daily behaviour. Try to educate, they might listen. And if you are in the right position (and many of us are), try to influence your team, your colleagues, your organization.
While we are at it: If you are a developer of operating systems, apps or websites: Proper security and privacy guidance built-into your code, true end-to-end encryption, the use of open and rock-solid standards, clever sandboxing and instant security patches whenever required will be getting more and more important and recognized. A good reputation in that respect might soon distinguish you from your competitors.
 
 
Matthias Reinwarth is Senior Analyst at KuppingerCole focusing on Identity and Access Management, governance and compliance. He has consulted in the Identity Management sector since 1993. Based on a combined education in economics and IT, Matthias developed a strong background in Identity and Access Management including Identity and Access governance and compliance. Furthermore Matthias has co-authored the first German book on directory services in 1999 and has acquired practical experiences as an IAM consultant for more than 20 years. He has been successfully working in assignments across various sectors including media, government, financial, telecommunications, logistics and industry (e.g. chemistry and pharmaceutics). Matthias areas of expertise cover all major aspects of IAM including technology and infrastructure, data and entitlement modeling as well as IAM processes and governance

ShareTweet
Previous Post

Businesses must prepare for new generation of cyber risks

Next Post

DOE hacked 150 times from 2010 to 2014, report says

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol