The Cyber Security Review | Tuesday, January 31, 2023
Employers must instill a healthy skepticism online and raise awareness about phishing, spamming, and scamming.
FREMONT, CA: When it comes to cybersecurity, there is such an emphasis on technology—securing networks, devices, and IT environments—that organizations frequently forget that hackers do not continually target technological measures. They often attack people. Eighty-two percent of all cybersecurity events involve human error, which suggests that many cyberattacks and breaches can be averted if individuals are more vigilant online.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Cybersecurity training is, therefore, essential. Organizations must encourage employees to exercise healthy skepticism online and raise their understanding of basic dos and don'ts, best practices, and the most recent phishing, hacking, and scamming methods. According to studies, regular security training improves security awareness. And ultimately, this savvy can help lessen the risk of fraud, phishing, and business email compromise assaults. When creating or developing a security awareness program, it is essential to keep these points in mind.
Maintain consistency: Many firms view security training as a once-a-year, box-checking exercise. Unfortunately, this method of shaping security behavior is ineffective. The "forgetting curve" is a constant adversary; thus, security training must be considered an ongoing process. Additionally, the more time users devote to training, the more likely they value security and their role in defending the organization.
Focus on behavior rather than (just) awareness: Recognize the distinction between knowledge, intent, and behavior. Even if someone is aware, it does not necessarily follow that they care or will act accordingly. As with speed limit signs, individuals are aware of their existence, but many continue to disregard them. Similarly, personnel may possess security knowledge, but without motivation or ingrained habits, they may not demonstrate secure behavior.
Organizations might employ phishing simulation exercises to concentrate on behavior. When employees face a phishing simulation, they are prompted to click on the link, ignore it, or notify security teams. These exercises aid in developing muscle memory and encourage a particular sort of cautious behavior until it becomes a habit. Consider conducting simulated tests every 30 days so that employees are constantly informed of the repercussions of their behavior and remain cautious.
Utilize training tools and resources of high quality: What are the aesthetics of your training materials? If the same slides are used year after year or are no longer relevant, your staff will likely not take the training seriously. Content should be relevant, regularly updated, and written in a language the business understands. Consider that the platform or tools used to deliver training will impact participation rates, and ensure that the technology you pick makes it easy for users to attend and finish training.
Tailor material to your audience: Different levels of sensitivity, proficiency and security maturity will exist across the organization's personnel. This variety should be considered throughout the development of programs. For instance, personnel that has less security maturity or expertise may require individualized training and hand-holding. Additionally, training should be developed with the level of risk in mind. For instance, banking may have a different level of risk than customer service, necessitating additional training.
More in News