The idea is that users are trained and regularly reminded to always lock their computers when they step away for cybersecurity. So, if they forget, their computer is relatively harmlessly messed with (like with changing the desktop background).
The consequences are then trivial, in contrast to potentially severe if a person left their computer unlocked with unvetted people coming in and out of the office during an event, or if they left their laptop unattended in a public area.
Some people still leave their computers unlocked somewhat frequently, but overall I think it works.
I even noticed this locking behavior a few weeks ago and chuckled at myself. That Windows+L motion as I get up is just so ingrained.
If I'm not actively in front of my PC it is always locked.
Of course there was etiquitte. You only ever emailed smaller groups (your team, your floor, rtc) - never all staff. You always explained to a newbie so they didn't feel too embarassed or singled out - and they always got a heads up during training.
Our small team of 15 got pretty crazy though. Rebinding keys, replacing all the icons with My Little Pony or Hello Kitty custom sets, etc. It became a good competition and a great way to blow off steam in a high output role, and as a byproduct built in good physical security.
0. https://securityintelligence.com/dont-get-pantsed-embrace-a-...
I think it's probably a good technique, though it needs to be done with a bit of care to not seem too hostile or humiliating. Changing the desktop background seems like a good idea, since it's harmless, obvious to the user, easily fixed, and doesn't impede actual work.
You learn a lesson, and the team gets a treat.
It was a great way to train someone to follow SOC2 requirements.
Ianal but I don't think it's a valid defense to walk in to a bank, find an unlocked safe and take all the money to make a 'point'.
Further, you're just normalising messing with other people's accounts which doesn't seem to be a good thing from a security pov.
I can see an argument that I shouldn't be a "vigilante" about making sure people follow security practices they agreed to when taking the job, but we are all responsible for the security of the business. A repeat offender coworker who doesn't care about the security consequences of leaving their PC unlocked is a security risk which needs addressed. This isn't just a case of messing with a friend.
Further, the PC is company property and subject to acceptable use policies. It's not "my computer" so I have no reasonable expectation that it is a sacred object other people won't mess with. Assuming others won't mess with your things is a terrible reason not to lock your door at night. Getting angry at a burglar for entering because you failed basic security misses the point of your failure.
My repeat offender coworker got over his indignation that I touched his computer and then started doing what he was required to do the entire time and locked his computer every time he got up. I stopped touching his computer. He didn't get written up or fired for repeat security failures, and all was well.
Now, by "web presence", it's true they had a website. And it was made with HTML. Lots and lots of HTML, in fact, as in thousands upon thousands of hand-edited, non-version-controlled files on disk that they'd manually curated over the years.
We didn't exactly have a cybersecurity team or defined best practices. But we were treated well and worked together well. (Still friends with that dev a decade later!).
It was also a really small town. We all hung out after work, went to the lake, climbing, whatever. Lived a few houses apart from each other (or sometimes in the same house, lol). We trusted each other. Had to. It's the kind of environment where relationships took precedence over rules.
Looking back, it was definitely an uncommonly intimate situation, but it was awesome!
Damn! I'm glad I don't work with people riding on the edge of being violent like that.