Should employees be punished for sloppy cyber security?