
How companies are training employees to serve as the first line of defense against cyberattacks.
BY CHRIS LEWIS
EMPLOYEE TURNOVER REMAINS a persistent challenge for warehouses, logistics and transportation operations—and cybersecurity roles are hit especially hard.
That’s unlikely to change soon. The supply chain industry is competing for cybersecurity talent against deep‑pocketed sectors like finance, government and healthcare. The result: unsafe cybersecurity practices are showing up at some distribution centers and warehouses. Training and upskilling help, but they aren’t enough on their own. What’s also needed is a strong company culture that treats online safety as a shared priority.
When organizations embed cybersecurity into their values, the payoff shows up in several ways. Employees start to see cybersecurity as a shared responsibility, and every team member becomes a valuable part of the organization’s defense.
As organizations prepare to work toward such cohesiveness, it’s important for them to remember that a “one‑size‑fits‑all” approach won’t work, particularly regarding cybersecurity. There are simply too many different types of roles in the industry. For example, a warehouse worker may need practical training focused on handheld devices, while an accounting employee might require more extensive training on phishing and payment fraud schemes.
Getting employees ready for that training requires investment, and few investments matter more. As Mike Crumpler, vice president of information security at FEATUREMHI member Kenco, puts it, employees are an organization’s “first and best line of defense in cybersecurity.”
CYBERSECURITY + VALUES = LONG‑TERM DEFENSE
According to Crumpler, regardless of how many cybersecurity tools an organization invests in, they’ll only have so much influence. If employees aren’t equipped to identify—and then respond to—potential cybersecurity threats, it doesn’t matter how many tools an organization has.
Crumpler recommends embedding security awareness into company culture from an employee’s very first day. Just as important, employees need to understand how much of an impact they can have in protecting the organization’s data and systems. Combine that training with a clear sense of their own influence, and cybersecurity becomes, as Crumpler puts it, “part of everyday decision‑making.”
“Given the ongoing competition for cybersecurity talent, leaders should also focus on developing internal talent pipelines by upskilling employees from other areas of the business and creating opportunities to grow into cybersecurity roles,” Crumpler said. “When combined with strong career pathways and a culture that supports employee development, this approach can help organizations attract and retain skilled talent.”
As vice president of MHI member Systems in Motion, Kevin Thompson personally believes that every organization should implement cybersecurity into their “core processes.” At his organization, he has noticed that each employee’s experience with cybersecurity depends on their position.
At Systems in Motion, for example, one person is responsible for notifying colleagues about cybersecurity issues. The accounting team, which deals with cybersecurity threats more than any other department, tends to be the most alert to potential risks. And the chief financial officer shares information on the new cyberattack methods with the rest of the organization.
“Our company values are a fixed list of common attributes we use to match our culture,” Thompson explained. “These don’t specifically call out cybersecurity, but we do have a strong sense of urgency regarding cybersecurity.”
That sense of urgency is vital for every organization, said Larry O’Brien, vice president of research at ARC Advisory Group. O’Brien believes this urgency should drive organizations to embed cybersecurity into company culture across the entire workforce—though how that plays out will vary by role and department. In a factory setting, for example, O’Brien suggests introducing the topic in “small chunks.”
“It’s social engineering. Every ransomware attack starts with some form of social engineering,” O’Brien noted. “Phishing emails are essentially a form of social engineering, while tricking people into clicking on a link they shouldn’t click on or responding to an email they shouldn’t.”
He continued, “That’s the most important thing—making people aware of these social engineering attacks.”
By doing so, organizations can achieve a threefold goal: improve their operations’ overall profitability, reliability and safety.
By embedding cybersecurity into an organization’s culture, the likelihood of a cyber incident will decline substantially. As a result, the entire organization, not just the warehouse, will avoid potential damage to shareholder value, viability, uptime and reputation.
“Every employee should be concerned about this,” O’Brien said. “And, with this concern in mind, everyone should have some type of knowledge to prepare for cyberattacks.”
Beyond training and culture, O’Brien also sees digitization as an important tool for strengthening cybersecurity readiness. Some organizations have begun to implement digitally enabled work practices, while others have digitized their standard operating procedures. Regardless of which method organizations consider, digitization will help reduce the loss of operational knowledge that’s often associated with cyber security.
“It’s one way to avoid the loss of such knowledge, along with investing in training and skills development,” O’Brien stated. “It’s all worth the investment. The companies that do are always better off in the long run.”
Thompson agrees with O’Brien, adding that the impact of strong cybersecurity must not be overlooked. The entire industry, in particular, has to be “very vigilant.”
“From tracking trailers, to looking for stolen shipments, cybersecurity is a major concern for every company,” Thompson emphasized. “It must be monitored constantly.”
Crumpler believes that, if cybersecurity is properly implemented into an organization’s company values, it won’t ever be a “secondary thought.” Instead, it will be viewed as a front‑and‑center principle, as employees will be “trained, coached and encouraged to follow cybersecurity best practices” from the moment they’re hired.
“The companies that have well‑developed cybersecurity cultures are the ones that tend to have more reliable operations, more uptime and fewer security incidents long‑term, period,” O’Brien added.
Click here to read the full article.
MHI Solutions Improving Supply Chain Performance