Sei sulla pagina 1di 2

WORK | training

Be aware, play your part


Security Awareness Campaign | As the ingenuity of cyber criminals and industrial spies increases,
the EPO is putting in place the training that will help to ensure all staff are equipped with the skills they
need to protect and secure confidential data.

Workplace security has changed beyond


recognition in the past 25 years, not least FEEDBACK FROM PARTICIPANTS
in the way that we handle confidential in-
“I liked the clear way the information and courses were communicated. Naturally, it is
formation and other sensitive data. The
important to return to this subject over and over again, because we are dealing with
EPO is at the heart of this transformation, sensitive and valuable information. And staff should not take the subject lightly.”
with strong bonds of trust with clients
who depend on us to protect patent infor- “BRAVO to everyone who developed this course. The modules give a good overview,
emphasising the importance of staff’s own responsibility in security matters. Great
mation as well as validate it. idea to allow the printing of a certificate.”
The risk of cyber attacks and cyber espio-
nage is rising. According to the European “It was fun doing the exercises. It is important to stress people’s own responsibility.
I would also suggest thinking about possible follow-up sessions and/or tests. To change
Union website, one in five European com-
people’s behaviour, repetition is key.”
panies has suffered at least one attempt
to steal its trade secrets in the last ten
years. And that number is growing, with
25% of companies reporting theft of infor- stuff of headlines – and blockbuster mov- phishing is done by sending emails,
mation in 2013, up from 18% in 2012. ies. In reality, one of the greatest threats is voice-phishing involves calling the victims
human behaviour. If an industrial criminal and relies on their willingness to help the
THE HUMAN FACTOR is able to gain someone’s trust, he or she person at the other end of the line. If the
Technology plays a key role in protecting can obtain virtually any information about caller has a plausible story, the victim may
confidential information. After all, hackers a company, without technical hacking well not suspect that an attack is under-
breaking into computer networks are the tools. In short, it’s much easier to trick way. Attackers psychologically manipulate
someone into handing over a password people and convince them to perform ac-
than to expend the effort needed to crack tions aimed at gaining access to confiden-
the system. tial information.
One of the techniques most widely used The EPO is well-equipped to resist such at-
by criminals is “social engineering”, includ- tacks. Confidentiality and trust are two of
ing  voice-phishing. Whereas “normal” the most powerful watchwords in our or-
ganisation’s culture. What’s more, the
EPO’s information systems have been de-
signed and built from the ground
up to protect patent and
other confidential infor-
mation entrusted to us.
To mitigate the risks we face, the EPO or-
ganised a lecture on “Social engineering
and physical security” on 2 July. The audi-
ence was invited to learn which tech-
niques and tactics are used by criminals to
infiltrate organisations like the EPO.

40 gazette July 2014


training | WORK

TIMELINE ACTIVITIES SECURITY AWARENESS CAMPAIGN 2014

24.09 15.09 17.11 26.11

Launch course II: Start weekly series of Launch course III: Lunchtime lecture III about
Physical Security IM security tips on the intranet Theft Theft (and Social Engineering)
TH Auditorium with
Lunchtime lecture II
live transmission to all sites
about Physical Security
TH Auditorium with
live transmission to all sites

SECURITY AWARENESS CAMPAIGN CALL THE SECURITY HOTLINE 2222 KEEPING MOBILE, STAYING SAFE
The EPO is running a course to ensure that David Gasper adds, “Contact the 2222 The sessions also showed how staff can
everyone is equipped with the latest emergency line if you’re concerned that keep information confidential when carry-
knowledge on how to access, share and security may have been compromised.” He ing smart devices, whether phones or tab-
protect information on mobile devices also encourages employees to spread the lets. Even though the EPO provides the de-
correctly. word. “Remind colleagues to be vigilant, vice, it’s important to minimise the risk of a
This first e-learning course was launched in and keep encouraging good habits, espe- security breach. And this risk increases when
June by VP4, Željko Topić. Two more mod- cially as time passes after people have tak- people are working away from the Office,
ules will follow by the end of 2014. All three en the course.” possibly in public Wi-Fi zones for example.
are mandatory for all staff. Although each The online courses are also supported by To sum up, the technology that protects
course only takes 15 minutes, they cover the a series of lunchtime security lectures, the EPO from criminal activity is only as
full range of security techniques, from articles in the gazette and news on the good as the people who work here. By
physical security to theft prevention, part- intranet. The first lecture of the 2014 series learning good habits and new skills, indi-
time home working and travel security. on cyber-crime and hacking was given on viduals and teams can remain vigilant, and
They are based on interactive learning and 2 July and a recording is available in the safe from even the most ingenious scams.
include a test to check that all the import- Media Centre. Of course, there’s more to this than just
ant points have been learned. By printing The response from the EPO staff who at- building confidence internally. Best securi-
out a certificate you can prove that you tended was extremely positive. While many ty practices also build trust with our cli-
have successfully completed the learning were surprised at the ingenuity of the latest ents and partners and help cement the
unit. Completion of all three courses will be security scams shown live on stage, they EPO’s reputation as one of the most pro-
checked at the end of the reporting year. were reassured by the training and the skills fessional and trustworthy patent offices
Željko Topić says, “This basic online train- available from the EPO’s IM department. in the world.
ing course primarily aims at reminding For many, it was also an eye-opening expe-
each of us of our responsibility when rience – not least the “performance” of a Sabine Lunau, Internal Communication
dealing with sensitive information. Staff team of experts who hacked laptops live Peter Springett, freelance author
will gain awareness, confidentiality and and in front of the audience.
security habits surrounding the use and
disclosure of data.”
Manuel Meijas Torres, Head of Security at GET STARTED ON THE
The Hague, and David Gasper, his counter- SECURITY E-LEARNING COURSES
part in Munich, stress the good news,
The Security Awareness Campaign will run for at least six months
which is that the most effective measures and all staff will have to complete the three e-learning modules and
are also the simplest. Manuel Meijas says, prove successful participation. A certificate can be printed after
“Don’t leave your office without locking completion of each course. To get started with Course 1 (“Part-time
home working and travelling”) and find out more about how to
your computer and checking for docu-
handle sensitive data, go to https://talent.internal.epo.org/auth/
ments left lying on the desk. Next to en- saml/login.php.
forcing your own ‘clear desk’ policy, re- For additional information, see the intranet:
Work > General Services > Security at EPO.
questing a key for your office from the
Contact: securityawareness@epo.org
ServiceLine can also help minimise risks.”

gazette July 2014 41

Potrebbero piacerti anche