Skip to main content
EnglishEnglish
Digital Skills and Jobs Platform
JHR-Claus-560x340

At Folkemødet on Bornholm I met Claus Due from the company Procio, where we both participated in CyberWalk. Here, he talked about the work on IT readiness action cards – a simple tool to help employees respond quickly and correctly when a cyber incident occurs.

The conversation made an impression because it pointed to something that many organisations can recognise: Although cybersecurity is often associated with technology, software and advanced systems, the first critical minutes are largely about people.

''People get tunnel vision when panic occurs. It is exactly the same mechanism as seen in physical accidents. In the situation, employees do not need to read long documents. You need something specific that says: Do I see the situation right? What am I supposed to do? And what should I not do?''- Claus Due, Procio.

Inspired by First Aid

The idea of using action cards in IT preparedness stems from a format that is already used in the world of first aid.

Through the collaboration with Action-Cards®, Claus Due was introduced to their card and book format, which is used for lifeguards and first aid situations where people under pressure need few, simple and action-oriented instructions. He quickly saw the perspective of transferring the mindset to IT and cybersecurity and developing content and scenarios for this area.

“I saw how the concept worked in first aid and thought: Why don't we have something similar in cyber security? When a cyber incident occurs, people respond mentally in the same way as in a physical emergency.”

According to Claus Due, the challenge is that many companies are good at producing documentation, risk assessments and contingency plans , but less good at translating them into concrete actions in everyday life.

“You lack the touch in the company. It will easily become evidence for the sake of the evidence.”

The biggest mistake is waiting.

When a cyber incident occurs, technology is only part of the challenge.

One of the mistakes Claus Due often sees is that employees spend too long assessing whether there is a problem at all.

“You doubt whether you are in an incident or not. That's why you let time pass. You do a little more research before you say anything. And this particular delay can be critical.”

Therefore, the work on action cards is based on a simple principle: Better to react once too much than once too little.

“You should react rather than not. The most important thing is not necessarily that you solve the problem yourself. The most important thing is that you get the right contacts right away.”

Preparedness must be visible – and trained

Many companies already have contingency plans on the intranet or in folders.

The problem is that they are often not used when the situation arises.

Therefore, Procio works to ensure that action cards and other short instructions for action must be easily accessible where the employees are located.

“They must be in the workshop, in the administration and in the lunch room. Just like a first aid kit or a defibrillator. Because it is on the same level that you have to be able to react.”

The cards are also used as a training tool, where employees continuously practice concrete scenarios.

“You don’t train tunnel vision through an awareness program on a screen. You train it by working with concrete situations.”

Phishing is an example of an event where training can make a tangible difference. Especially increasingly persuasive CEO scams, where criminals pretend to be leaders or trusted collaborators, can be difficult to figure out.

“We can see that the attacks are becoming more sophisticated. Fraudsters use information from LinkedIn and social media to make inquiries look more credible.”

According to Claus Due, experience shows that employees who train concrete scenarios become better at detecting suspicious inquiries and reporting incidents more quickly.

Four questions every employee should be able to answer

A key principle of operational IT readiness is that employees must be able to quickly answer four simple questions:

  1. What should I pay attention to?
  2. What should I do in the situation?
  3. Who should I contact?
  4. What should I not do?

It might sound simple. However, according to Claus Due, simplicity is crucial when the situation is serious and decisions need to be made quickly.

Management must own the task.

A point Claus Due returns to several times is the responsibility of management.

For many places, cybersecurity continues to be seen as a technical issue. It's a mistake, he says.

“Cybersecurity is a business essential discipline. Therefore, the management must not leave it to a technician alone."

According to him, if cybersecurity is to be properly anchored, it requires cooperation between management, quality managers and IT specialists.

“When the three roles work together, safety is anchored in the business, processes and technical setup.”

Start with the main risks

If Claus Due were to take over the cybersecurity of an average Danish company tomorrow, he would not start with large projects or complicated systems.

He would start by identifying the company's main risks and then take concrete steps.

“The worst thing is to start too big. Take half a day, identify the main risks, make a simple plan and get started.”

At the same time, he wonders why so many companies are still waiting for a legal requirement or a customer requirement before they act. “We know cybersecurity is important. So why wait? "Why don't you just start?" he asked.

From Plans to Action

Perhaps one of the most interesting things about the conversation with Claus Due is not the tool itself, but the thinking behind it.

Many organisations already have policies, procedures and contingency plans in place. The challenge is often to get them translated into action in the real world when employees are in a pressured situation.

Here, the work with action cards points to an important learning that goes far beyond the individual format: People act better when responsibilities, ways of contact and options for action are simple, visible and trained in advance.

If readers only have to take one thing from the interview, perhaps that's exactly the message:

Cybersecurity is not just about technology. It's about people, leadership and the ability to react when something goes wrong.

Action cards and scenario training are examples of how to make preparedness concrete and operational. Other organisations may choose different methods. However, the common denominator is the same: Don't wait for the next legal requirement or next cyber incident. Start with the most important thing, create a clear plan of action and anchor the work throughout the organization.

Read more on procio.dk about IT preparedness and action cards.

News details

Digital technology / specialisation
Geographic scope - Country
Austria
Belgium
Bulgaria
Cyprus
Geographical sphere
National initiative
0