Section outline
-
-
We know that vacation, paid time off, and sabbaticals are important for our mental health and wellbeing—but could they also be important for cybersecurity? In this report, we'll explore why vacations can be both big challenges and useful opportunities for cybersecurity, and why mental health breaks are so critical for team members in security-related roles.
Why Vacations are Beneficial for Cybersecurity
Consider this: your colleague who maintains your organization's email system is away on holiday. They haven't been able to take time off for months, so they are making the most of their vacation and fully unplugging from their devices. In the meantime, though, you have a team member locked out of their email account. What do you do?
If this scenario makes you sweat, you might have lived through such a situation in the past—or you might be that critical team member yourself. Whatever your role, you've almost certainly had your work disrupted when a colleague is away for travel, vacation, or illness.
But rather than dreading your colleagues’ vacations or avoiding taking time off yourself, try approaching vacations from a different point of view. Consider this: vacations may actually be the optimal time to gauge how well your organization’s cybersecurity efforts are working.
When a team member is away, seize the opportunity to document that experience. Try running a tabletop exercise or scenario during their absence. How would your team react to a hypothetical incident while this team member was away? Would you be able to access critical systems, like the back-end of your website or your email administration portal, or would you struggle?
Document what you find. If you weren't able to access an important system, note that. If your team was left confused about which steps to take in your security plan, write down their questions. Use their absence as a teachable moment and, when your colleague returns, discuss gaps in your cybersecurity response.
Remember, the goal of this exercise is not to make more work for your team members handling security. Instead, think about avoiding a "single point of failure" in your operations. Since no one person in your organization should hold all the access to your systems, consider how you can safely share access with others on the team. Perhaps you need to hire additional cybersecurity staff or, if resources are limited, appoint "security champions" within the organization to shoulder some of the weight. (We talk more about building a culture of security in another module.)
Here are some questions to answer when your team member is away:
-
Do you have security policies and procedures?
-
Do you know how to access those policies and procedures?
-
If so, do you understand the policies and procedures without your colleague’s help?
-
Can you implement the procedures?
-
Do you have access to the systems you need when your colleague is away?
-
Do you rely on your colleague for all security-related decisions?
Start a collaborative document that you can share with your colleague when they return to prompt a big-picture discussion about organizational security.
Addressing Vacations in Your Policies
Travel—whether for work or personal reasons—is inevitable for nearly every team member. That's why some organizations have a travel policy that helps staff determine what to do with their devices and work-related data when they work outside the office. But many of these policies overlook the implications of travel on the rest of the organization.
For example, as in our first scenario, what happens when a team member is away on vacation and can't be reached, or traveling in a part of the world where they cannot access systems remotely? Adding a section to your incident response plan that clarifies how your organization will respond when a team member is out of the office can minimize confusion and mistakes while team members travel. You may determine it’s best to designate an “on-call” staff member to take on some responsibilities while your colleague is away.
If a staff member is out of the office for non-work travel, your travel policy can still play a role. For example, perhaps they are visiting a region where device searches are common at airports or borders. In that case, it may be wise to ask them to leave work devices at home. The same may also apply if they are traveling to areas where device theft is common.
Avoiding Insider Threats
When we talk about “insider threats,” many people envision colleagues who are seeking to harm their own organization. And while threats can come from disillusioned staff members, many insider threats are unintentional.
For example, your colleague may have inadvertently infected their work device with malware, clicked on a phishing link, or allowed malicious actors access to your system. Finding the source of these threats can be challenging, especially when you have a busy organization where team members rely on many different devices for work.
Instituting a mandatory travel policy is not only beneficial for employee wellbeing, it's also a chance to identify and neutralize insider threats.
Here's how it works: every staff member needs to take a certain number of days off each year. While that staff member is away, you can use this as an opportunity to see how their absence affects your security.
Do you see any worrisome trends slow down or pause when a staff member is out of the office, such as a decrease in traffic to your network from unknown users? Or does nothing change in the baseline level of your organization's security while that team member is away? While not foolproof, having every team member regularly take breaks can help you spot trouble that might be difficult to identify when everyone is active on your systems.
Reducing the Risk of Burnout
IT and cybersecurity personnel have difficult jobs. There is often little margin for error with vital systems, websites, and data, and even small mistakes can have big consequences. The stress and anxiety of the work is magnified when a single person—or even two or three people—are tasked with managing cybersecurity for an entire organization. Not to mention that an organization itself runs a risk when those critical personnel are away or leave the team.
It’s important to recognize the challenges inherent in these roles and provide proper resources for your team members. If you can afford to bring on additional support for cybersecurity, we encourage you to do so (even if this is a third-party security provider). If not, then consider how you can create an environment where all staff take security seriously and do their part to keep the organization safe.
One way to lessen the stress on your cybersecurity personnel is to encourage a practice known as “job rotation”. This is especially helpful for organizations that have a single cybersecurity staff member or no one dedicated to cybersecurity at all.
With job rotation, you assign critical security-related tasks to team members on a rotating basis. For example, one staff member might be in charge of overseeing the organization’s password manager for a three-month stint, while another might determine who has access to sensitive data. Once that three-month window is over, the team switches roles, taking on another security-related task for another period of time.
Practicing job rotation not only takes the burden off of your cybersecurity team, but it also empowers other members of your staff to better understand and practice cybersecurity. While it’s not a substitute for cybersecurity expertise, rotation can help improve employee morale and keep your organization safer.
Job rotation isn’t practical for every organization, and you may still need a dedicated IT or cybersecurity team member to handle critical security tasks like managing software patches or incident response. But being more aware of the burden and responsibility of cybersecurity tasks is beneficial for every organization, whether you practice job rotation or not.
Here are other steps you can take to help reduce burnout among your security-focused team members:
-
Avoid relying on one team member for all cybersecurity-related questions. Create a knowledge base instead, where you can document important security information somewhere that the entire team can access.
-
Encourage your cybersecurity staff to network with professionals in similar roles at other organizations. This can establish a sense of solidarity and help them answer questions that arise on the job.
-
Empower everyone in your organization to take responsibility for their own security through conversations, workshops, discussions, and an open culture which encourages sharing.
Vacation time, employee departures, and leaves of absence are inevitable. With proper planning and proactive discussions, these can be opportunities to strengthen your cybersecurity posture for the future.
-
-