Audit Confirms Your Worst Fear: Employees Are the Weakest Link in Digital Security

Advertisement
By Associated Press | Updated: 19 March 2018 17:01 IST

Michigan auditors who conducted a fake "phishing" attack on 5,000 randomly selected state employees said Friday that nearly one-third opened the email, a quarter clicked on the link and almost one-fifth entered their user ID and password.

The covert operation was done as part of an audit that uncovered weaknesses in the state government's computer network, including that not all workers are required to participate in cybersecurity awareness training. Phishing schemes - in which hackers try to deceive email recipients by posing as legitimate entities - can lead to identity theft and other problems.

The topic of the email was about an expired password, said Kelly Miller, state relations officer for Michigan's Office of the Auditor General.

Advertisement

Phishing was how Russian-linked players stole the emails of Hillary Clinton's presidential campaign chairman John Podesta.

Advertisement

Auditors made 14 findings, including five that are "material" - the most serious. They range from inadequate management of firewalls to insufficient processes to confirm if only authorised devices are connected to the network.

"Unauthorised devices may not meet the state's requirements, increasing the risk of compromise or infection of the network," the audit said.

Advertisement

The Department of Technology, Management and Budget agreed with many of the findings while partially concurring with some. It said the auditors' phishing email was reported to a "security tips" mailbox multiple times and there are other controls that may limit the effectiveness of such attacks.

The agency added that it is formalising a standard that adopts industry best practices for secure configurations, estimating it will be done in April.

Advertisement

"The data held within the state government network is safe and secure due to the many layers of protection in our security ecosystem," said spokesman Caleb Buhs, who said the state has already begun implementing many of the auditors' recommendations. "This audit provides us with a good roadmap for prioritising future technology infrastructure investments."

The audit, which covered a three-year period between 2014 and 2017, said the state did not fully establish and implement an effective process for managing updates to network devices' operating systems. Ten high- or medium-severity vulnerabilities were identified.

Overall, Auditor General Doug Ringler deemed state's efforts to design, administer and monitor a secure IT network as "moderately sufficient."

A Democratic critic of Gov. Rick Snyder's administration, Senate Minority Leader Jim Ananich of Flint, said "there is just no excuse for why Michigan's top officials have failed to protect our state from hackers."

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Realme P4 Power 5G With 10,001mAh Battery Arrives in India: See Price
  2. Redmi Note 15 Pro Series 5G Launched in India With These Features
  3. Adobe Express Premium Is Now Free for One Year for All Airtel Users
  4. Samsung Galaxy S26 Ultra Could Cost Less than Its Predecessor
  5. Realme Buds Clip Launched in India With Open-Ear Design, IP55 Rating
  6. How to Change Your Mobile Number and Address Using New Aadhaar App
  7. Why the Redmi Note Remains Xiaomi's Easiest Recommendation
  8. Realme P4 Power 5G Launch Today: Know Price in India, Specs and More
  9. Clawdbot (Now Moltbot) Explained: What is It and Why is It Going Viral?
  10. PS Plus Essential Will Add Four Free Monthly Games in February
  1. iPhone 18 Series Pricing Could Remain Unchanged Despite Rising Memory Costs, Analyst Claims
  2. PS Plus Monthly Games for February Announced: Undisputed, Subnautica: Below Zero, Ultros and Ace Combat 7
  3. Realme Buds Clip Launched in India With Open-Ear Design, IP55 Rating: Price, Features
  4. Snap Forms New Subsidiary Specs Inc. to Lead Consumer Smart Glasses Push
  5. Sony WF-1000XM6 Tipped to Launch With New 'Sandpink' Colour Option
  6. Realme P4 Power 5G Launched in India With 10,001mAh Battery, 50-Megapixel Primary Camera: Price, Specifications
  7. Redmi Note 15 Pro+ With 200-Megapixel Camera Launched in India Alongside Redmi Note 15 Pro: Price, Specifications
  8. Samsung Galaxy S26 Series Spotted in Leaked Case Renders; Samsung Tipped to Launch 25W Qi2 Magnetic Wireless Charger
  9. Samsung Galaxy A07 5G India Launch Timeline Revealed; Key Features Including 50-Megapixel Camera Confirmed 
  10. Samsung Galaxy A37 Spotted With Flat Display and New Frame Design in Leaked Renders
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.