The Cyber Security Review | Wednesday, February 24, 2021
By incorporating security into the overall vision and mission, enterprises can foster a cybersecurity culture and transform security awareness training.
FREMONT, CA: In today’s digital world, an increasing amount of day-to-day activities have migrated online. People work, communicate, conduct commerce, communicate online, and the reliance on cybersecurity has increased accordingly. Cyber-criminals can effortlessly wreak havoc on businesses. The increased use of the internet and mobile usage offers them even more opportunities to exploit the vulnerabilities. A successful cyber-attack can bring a company to its knees, causing damage that cannot be recovered. Fortunately, an organization can initiate things to mitigate the effects of cyber-crime, beginning with the vital first step of raising cybersecurity awareness. Here is the best practices for a 2021 security awareness program.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
• Taking Baseline Measurements of Cybersecurity Knowledge
Before a firm can evolve its awareness training, it must first determine the strength of the existing security awareness program. Resources like the SANS Security Awareness Maturity Model —designed through over 200 awareness officers' coordinated efforts — help firms identify how mature the program is and where the firm can take it. By taking baseline measurements related to current cybersecurity knowledge levels, firms can track their progress.
• Taking An All-In Attitude
Making it a company-wide program comprises buy-in from the top down and secures enough funding for initial needs and ongoing efforts. Incorporating security into the organization’s overall vision and mission is important. Let employees know what is in it for them; they will be more invested if they understand awareness initiatives extend beyond corporate security to guard against threats to their identity and livelihood.
• Setting Goals
Working with stakeholders to identify the top issues and risk factors in specific areas of the enterprise and develop a calendar of efforts to address them over time. Set reasonable, incremental objectives and be prepared to make changes if initial approaches fail to produce positive outcomes.
• Prioritizing Collaboration
Error is inevitable, regardless of how strong the security program is. So taking a “more carrot, less stick” method will encourage employees to share data and feel like collaborators. Security instances should be treated as learning opportunities rather than a reason for punishment. If users worry they’ll be blamed, they’ll be far less likely to report them.
More in News