This chapter focuses on personnel management. Having the right team focused on the
right tasks at the right time yields optimum performance. We describe some best practice
techniques that executives can include in their processes for recruiting, retaining,
rewarding, and managing talent in the Cyber Age. We also give recommendations on
how to apply that talent as you organize for success.Of special interest is the “Touhill Cybersecurity Training Plan Outline” that provides
considerable detail that executives should follow as a basis for training employees
to properly understand cyber risks and equip them with the knowledge to respond
appropriately. The intent of this training plan is to have a workforce that is not only
“cyber smart” but “cyber hardened” as well.
Remember that executives need training and regular updates in order to keep them
up to date and to emphasize for employees the importance of cybersecurity training for
everybody.
Additionally, in this chapter, we address special considerations for protecting critical
infrastructure.
There are several best practices that every critical infrastructure organization should
incorporate into its cybersecurity program. These include the following:
• Make cybersecurity a stated organizational priority and act upon it.
• “Bake in” cybersecurity to everything you do.
• Don’t buy anything without evaluating its cybersecurity risks.
• Implement strong internal controls and tightly monitor.
• Identify and have a plan to address all single points of failure.
• Train your personnel.
• Practice!
• Audit.