Ask Slashdot: How To Communicate Security Alerts? 84
Capt.Michaels writes: "I need to start sending security alerts and warnings to employees at my somewhat sizable company. My problem: I'm not sure how to send these alerts without freaking everyone out and causing the help desk to get flooded with phone calls. For example, let's take the current Internet Explorer exploit that caused US-CERT to recommend switching browsers. I don't want everyone killing our limited help desk with ridiculous questions like, 'I downloaded $New_Browser, how can I get my toolbar? How do I bookmark things in this browser? Can you tell me which browser you recommend?' Simply put: some vulnerabilities are worth major changes, but many aren't. If we switched software every time a new vulnerability came out, we'd never get anything done. Sooner or later, a patch will come out, and everything will be back to normal. But how do I communicate to end users that they should be aware of an issue and take extra care until it's fixed, without causing panic?"
Run around in panic... (Score:5, Funny)
Also, what kind of security events are we talking about here?
You let your employees choose their own browsers? (Score:5, Funny)
Goddamn hippy.
Military Basic training method (Score:4, Funny)
Don a utilitarian yet heavily starched and pressed uniform, wear a funny hat and a hitler style mustache. Then get a ridding crop and an air horn. Go from cubicle to cubicle screaming and yelling obscenities and personal insults while instructing your vic.... users to apply patches or whatever. If anyone tries asking a question blow the air horn in their face then belittle them and kick up the crazyness of the insults a notch or two.
Or you could send out a friendly and professionally written email with precise directions with a picture for every step. But that honestly doesn't seem like much fun to me.