Councils spend more on 'mindfulness' than on IT security
Research has revealed they are spending nine times more on health and safety than IT security
Research by Citrix has revealed councils are spending nine times as much money on health and safety training than IT security training, which could have detrimental consequences.
An average of 27,818 is spent by the average local authority on health and safety, yet the budget only stands at 3,378 for IT security training.
While the total council spend on 'mindfulness' training was 140,888.81 in 2016, it stood at just 56,441.13 for IT security and 48,269.97 on data protection.
The amount spent on educating staff around health and safety issues has almost doubled in the last 12 months and includes topics such as meditation, working at heights and managing difficult situations, yet protecting IT systems against cyber criminals has fallen behind.
However, the information did point out that councils are making smart devices such as smartphones and tablets a key part of their IT strategy, with an average of 714 smart devices in use per local authority.
"A broad scope of training is vital in today's work environment," Jon Cook, director of sales at Citrix UK & Ireland, said. "We commend local authorities for arming their employees with these additional skills, as well as seeking to improve their work/life balance through issuing smart devices and committing to a well-rounded programme of training courses."
A total 86% of local authorities failed to spend anything at all on IT security training, data provided by Citrix's Freedom of Information (FoI) request revealed, and 40% of the smart devices in use by personnel aren't protected by enterprise mobility management software.
Get the ITPro. daily newsletter
Receive our latest news, industry updates, featured resources and more. Sign up today to receive our FREE report on AI cyber crime & security - newly updated for 2024.
"Sadly investing in IT security usually falls quite low in the spending list for most local authorities," Mark James, security specialist at ESET, said.
"The consequences for failures in IT sec are significantly lower than other areas with no clear guidelines on what constitutes a failure. If you back that up with unsuccessful or fairly insignificant fines then in most cases it's easier to do something about it after it happens than before."
The report revealed that 24% of local authorities do make use of free e-learning' or on the job' data protection and IT security training to help educate staff, but Citrix said more effort must be made to protect the organisation.
"With the responsibility for managing citizen data, coupled with the risk of penalties of up-to 500,000 for data-breaches, it is crucial that employees know how to keep information secure from external threats," Cook said.
"With the stakes so high, councils must ensure that staff understand the importance of data protection in the growing threat landscape."
Clare is the founder of Blue Cactus Digital, a digital marketing company that helps ethical and sustainability-focused businesses grow their customer base.
Prior to becoming a marketer, Clare was a journalist, working at a range of mobile device-focused outlets including Know Your Mobile before moving into freelance life.
As a freelance writer, she drew on her expertise in mobility to write features and guides for ITPro, as well as regularly writing news stories on a wide range of topics.