{"guid":"56410e34-a119-51b8-ad35-694c8d4584c9","title":"How to tell your co-workers that they suck at InfoSec and actually get away with it","subtitle":null,"slug":"2025-533-how-to-tell-your-co-workers-that-they-suck-at-infosec-and-actually-get-away-with-it","link":"https://talks.mrmcd.net/2025/talk/KZDWWW/","description":"Als Unternehmen ist das Thema Informationssicherheit von steigender Bedeutung. \nVon vielen Mitarbeitern wird der Bereich Informationssicherheit und die damit verbundenen Regelungen als Gängelung und lästig betrachtet. \nEs ist als Unternehmen jedoch wichtig, dass alle Mitarbeiter zum einen eine Awareness für das Thema haben, aber auch die Entscheidungen des Unternehmens mit tragen. \nEs wird anhand eines Fallbeispiels gezeigt, wie genau diese Ziele erreicht werden können und was eventuell beim gewählten Ansatz noch besser gemacht werden könnte.\n\nDen Mitarbeitern (300+ Personen) zu sagen, dass ihr Verhalten im Umgang mit Informationen und Technik sich verändern muss, ist nicht immer zielführend oder einfach. \nMeistens ist die erste Rückfrage: \"Was soll das denn bringen?\" oder \"Wie soll ich so denn dann arbeiten?\"\n\nGenau um das zu verhindern habe ich mich mit dem ISO, dem IT-Leiter und dem Vorstand abgestimmt und einen Workshop ersonnen, in dem wir (ein Freiwillig gemeldeter IT-Leiter und ich) genau dieses verhindern wollten. \n\nWie sah die Vorbereitung aus?\nWie lief der Workshop ab?\nWas für \"Vorkommnisse\" gabes während des Workshops?\nWie war die Reaktion der Kollegen?\nWelche Entscheidungen wurden im Anschluss getroffen?\nWas kann man für das nächste mal besser machen? \nWas muss man auf jeden Fall haben?\n\nDiese Fragen versuche ich so gut es mit möglich ist zu beantworten und vielleicht auch einen kleinen Einblick in die Probleme der Mitarbeiter, aber auch der Unternehmen bei der Verbesserung der Informationssicherheit zu geben.\n\nhttps://creativecommons.org/licenses/by-sa/4.0/","original_language":"deu","persons":["Nervofix"],"tags":["533","2025","mrmcd25","C120 - Art. 15 DSGVO","mrmcd25-deu","Darmstadt","mrmcd25","Day 1"],"view_count":394,"promoted":false,"date":"2025-09-12T19:20:00.000+02:00","release_date":"2025-09-12T00:00:00.000+02:00","updated_at":"2026-03-20T16:45:06.868+01:00","length":2648,"duration":2648,"thumb_url":"https://static.media.ccc.de/media/conferences/mrmcd/mrmcd25/533-56410e34-a119-51b8-ad35-694c8d4584c9.jpg","poster_url":"https://static.media.ccc.de/media/conferences/mrmcd/mrmcd25/533-56410e34-a119-51b8-ad35-694c8d4584c9_preview.jpg","timeline_url":"https://static.media.ccc.de/media/conferences/mrmcd/mrmcd25/533-56410e34-a119-51b8-ad35-694c8d4584c9.timeline.jpg","thumbnails_url":"https://static.media.ccc.de/media/conferences/mrmcd/mrmcd25/533-56410e34-a119-51b8-ad35-694c8d4584c9.thumbnails.vtt","frontend_link":"https://media.ccc.de/v/2025-533-how-to-tell-your-co-workers-that-they-suck-at-infosec-and-actually-get-away-with-it","url":"https://api.media.ccc.de/public/events/56410e34-a119-51b8-ad35-694c8d4584c9","conference_title":"MRMCD 2025 - Volle Transparenz","conference_url":"https://api.media.ccc.de/public/conferences/mrmcd25","related":[],"recordings":[{"size":243,"length":2648,"mime_type":"video/webm;codecs=av01","language":"deu","filename":"mrmcd25-533-deu-How_to_tell_your_co-workers_that_they_suck_at_InfoSec_and_actually_get_away_with_it_av1-hd.webm","state":"new","folder":"av1-hd","high_quality":true,"width":1920,"height":1080,"updated_at":"2025-09-12T23:38:01.941+02:00","recording_url":"https://cdn.media.ccc.de/events/mrmcd/mrmcd25/av1-hd/mrmcd25-533-deu-How_to_tell_your_co-workers_that_they_suck_at_InfoSec_and_actually_get_away_with_it_av1-hd.webm","url":"https://api.media.ccc.de/public/recordings/90806","event_url":"https://api.media.ccc.de/public/events/56410e34-a119-51b8-ad35-694c8d4584c9","conference_url":"https://api.media.ccc.de/public/conferences/mrmcd25"},{"size":93,"length":2648,"mime_type":"video/webm","language":"deu","filename":"mrmcd25-533-deu-How_to_tell_your_co-workers_that_they_suck_at_InfoSec_and_actually_get_away_with_it_webm-sd.webm","state":"new","folder":"webm-sd","high_quality":false,"width":720,"height":576,"updated_at":"2025-09-13T01:14:25.406+02:00","recording_url":"https://cdn.media.ccc.de/events/mrmcd/mrmcd25/webm-sd/mrmcd25-533-deu-How_to_tell_your_co-workers_that_they_suck_at_InfoSec_and_actually_get_away_with_it_webm-sd.webm","url":"https://api.media.ccc.de/public/recordings/90834","event_url":"https://api.media.ccc.de/public/events/56410e34-a119-51b8-ad35-694c8d4584c9","conference_url":"https://api.media.ccc.de/public/conferences/mrmcd25"},{"size":256,"length":2648,"mime_type":"video/webm","language":"deu","filename":"mrmcd25-533-deu-How_to_tell_your_co-workers_that_they_suck_at_InfoSec_and_actually_get_away_with_it_webm-hd.webm","state":"new","folder":"webm-hd","high_quality":true,"width":1920,"height":1080,"updated_at":"2025-09-13T01:00:56.853+02:00","recording_url":"https://cdn.media.ccc.de/events/mrmcd/mrmcd25/webm-hd/mrmcd25-533-deu-How_to_tell_your_co-workers_that_they_suck_at_InfoSec_and_actually_get_away_with_it_webm-hd.webm","url":"https://api.media.ccc.de/public/recordings/90830","event_url":"https://api.media.ccc.de/public/events/56410e34-a119-51b8-ad35-694c8d4584c9","conference_url":"https://api.media.ccc.de/public/conferences/mrmcd25"},{"size":91,"length":2648,"mime_type":"video/mp4","language":"deu","filename":"mrmcd25-533-deu-How_to_tell_your_co-workers_that_they_suck_at_InfoSec_and_actually_get_away_with_it_sd.mp4","state":"new","folder":"h264-sd","high_quality":false,"width":720,"height":576,"updated_at":"2025-09-12T23:25:00.196+02:00","recording_url":"https://cdn.media.ccc.de/events/mrmcd/mrmcd25/h264-sd/mrmcd25-533-deu-How_to_tell_your_co-workers_that_they_suck_at_InfoSec_and_actually_get_away_with_it_sd.mp4","url":"https://api.media.ccc.de/public/recordings/90797","event_url":"https://api.media.ccc.de/public/events/56410e34-a119-51b8-ad35-694c8d4584c9","conference_url":"https://api.media.ccc.de/public/conferences/mrmcd25"},{"size":40,"length":2648,"mime_type":"audio/mpeg","language":"deu","filename":"mrmcd25-533-deu-How_to_tell_your_co-workers_that_they_suck_at_InfoSec_and_actually_get_away_with_it_mp3.mp3","state":"new","folder":"mp3","high_quality":false,"width":0,"height":0,"updated_at":"2025-09-12T23:24:55.003+02:00","recording_url":"https://cdn.media.ccc.de/events/mrmcd/mrmcd25/mp3/mrmcd25-533-deu-How_to_tell_your_co-workers_that_they_suck_at_InfoSec_and_actually_get_away_with_it_mp3.mp3","url":"https://api.media.ccc.de/public/recordings/90796","event_url":"https://api.media.ccc.de/public/events/56410e34-a119-51b8-ad35-694c8d4584c9","conference_url":"https://api.media.ccc.de/public/conferences/mrmcd25"},{"size":27,"length":2648,"mime_type":"audio/opus","language":"deu","filename":"mrmcd25-533-deu-How_to_tell_your_co-workers_that_they_suck_at_InfoSec_and_actually_get_away_with_it_opus.opus","state":"new","folder":"opus","high_quality":false,"width":0,"height":0,"updated_at":"2025-09-12T23:24:40.806+02:00","recording_url":"https://cdn.media.ccc.de/events/mrmcd/mrmcd25/opus/mrmcd25-533-deu-How_to_tell_your_co-workers_that_they_suck_at_InfoSec_and_actually_get_away_with_it_opus.opus","url":"https://api.media.ccc.de/public/recordings/90793","event_url":"https://api.media.ccc.de/public/events/56410e34-a119-51b8-ad35-694c8d4584c9","conference_url":"https://api.media.ccc.de/public/conferences/mrmcd25"},{"size":283,"length":2648,"mime_type":"video/mp4","language":"deu","filename":"mrmcd25-533-deu-How_to_tell_your_co-workers_that_they_suck_at_InfoSec_and_actually_get_away_with_it_hd.mp4","state":"new","folder":"h264-hd","high_quality":true,"width":1920,"height":1080,"updated_at":"2025-09-12T23:04:24.627+02:00","recording_url":"https://cdn.media.ccc.de/events/mrmcd/mrmcd25/h264-hd/mrmcd25-533-deu-How_to_tell_your_co-workers_that_they_suck_at_InfoSec_and_actually_get_away_with_it_hd.mp4","url":"https://api.media.ccc.de/public/recordings/90785","event_url":"https://api.media.ccc.de/public/events/56410e34-a119-51b8-ad35-694c8d4584c9","conference_url":"https://api.media.ccc.de/public/conferences/mrmcd25"}]}