Tuesday, February 20, 2018

Overcoming ‘cyber-fatigue’ requires users to step up for security

As a new presidential administration takes

over, it will need to pay significant attention to cybersecurity. Indeed, we’ve already been told to expect “a comprehensive plan” for cybersecurity in the first few months of the new administration. But as a professional who has long been part of the global internet security community, I am pessimistic that the typical government and individual plans or responses to our ongoing cybersecurity concerns actually will lead to meaningful improvements.
For decades, this cycle has repeated itself. First, a high-profile incident occurs – like the two massive Yahoo hacks revealed in 2016 or the even more damaging breach of federal employee data disclosed in 2015. Among other things, the resulting advice is the same: Users should change their passwords and make their login process more complicated (and more secure) by enabling two-factor authentication.