Skip to content
Menu
Box Thoughts
  • Home
  • About Me
  • LinkedIn
Box Thoughts
March 26, 2014

How to destroy your corporate security through bad policy design.

What are the biggest security risks at most corporations?

  • Internal servers that hold confidential data.
  • Passwords in the form of “password” or “123456”.
  • Data hosted on 3rd party servers (the cloud).
  • System connections that allow access to other systems.
  • Email.

What are some of the most common solutions to these problems?

  • Force users to change passwords every 90 days.
  • Auto-archive email older than 90 days (or some other time period).
  • Prohibit thumb drives or connections to external drives.
  • Block websites through a web filter to prevent users from getting to Dropbox, Google Drive, etc.

So what happens in response to each of these?

  • Users simplify their password so that they can remember it each time they change it.
  • Users forward their important emails to external addresses so that they don’t lose access to it.
  • Users start using their own computers for work to make their lives easier – no limits on what they are allowed to do.

By implementing these 4 common security enhancements you have just made your internal security weaker while not actually addressing any of the core security issues.  Most security policies address issues from the technical side and ignore the messy human components.  But humans are the messiest, riskiest part of the security equation.  

Don’t fool yourself into believing that firm policies equal good security because often it is the opposite of true.

Share this:

  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on X (Opens in new window) X
  • Share on WhatsApp (Opens in new window) WhatsApp
  • More
  • Share on Reddit (Opens in new window) Reddit
  • Share on Facebook (Opens in new window) Facebook
  • Email a link to a friend (Opens in new window) Email

Related

Leave a ReplyCancel reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Recent Posts

  • Workplace operations is about balancing static vs. dynamic delivery trade-offs.
  • Commercial real estate and Proptech are the antithesis of winner-takes-all industries
  • A tool for making shift management and occupancy easier
  • Seasonality matters in your CRE data
  • CBRE’s 2025 Americas Occupier Sentiment Survey report is a full encapsulation of the current corporate real estate conversation.

analysis bias change change program collaboration Communication CRE culture data decision making demand design experience failure fear finance flex flexibility future growth hybrid idea innovation leadership managing mandate metrics modeling people personal planning portfolio productivity program management quality relationships risk strategy success team technology trust WFH work Workplace

©2026 Box Thoughts | Powered by WordPress and Superb Themes!