Cyber Security – How to encourage non-compliance

Why should employees or students dare to point out deficiencies in security on college campuses when the reaction from the administration may be to terminate the discoverers instead of those responsible for the original violation of policy (i.e. leaving files with id out in the open).

A student journalist at Western Oregon University was reprimanded, and the newspaper adviser was fired, after publishing an article showing the institution had not secured sensitive, private information about some applicants.

