(Story Time) Lying is not okay, rules DO apply to you, and good senior management is worth it's weight in platinum

When everyone knows any cybersecurity violation will get you immediately escorted out, fired and put on a no-rehire list, there's much better compliance.

Not exactly. People will ignore potentially serious issues, and hope that whatever fuck up that happened doesn't get discovered - or that they can blame it on someone else. Blatant and repeated disregard, including user training and documenting this on their employee record, should be enough. I would loop in HR, Finance, Legal, Risk, and InfoSec to land home the idea that bonuses (including their managers and department heads bonuses), or vertical movement / retention within the company, as well as insurance, and compliance audits are all tied to these people being migrated. Slaughtering the first lamb and firing the worst offender with cause would send the right message.

/r/sysadmin Thread Parent