The Cyber Security Review | Saturday, February 04, 2023
A security awareness program should be judged based on how well it reduces intrusions, breaches, damage, and, ultimately, cyber risk.
Fremont, CA: There are alarming and, frankly, frightening statistics illustrating today's cybersecurity challenges. In essentially every industry, thousands of corporate data breaches are reported - and those are just the ones that get reported. Furthermore, more than a third of the companies estimated to have been impacted by breaches didn't get detected at all, despite the fact that hundreds of thousands may have been affected.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
The threat landscape is becoming increasingly sophisticated, evolving, and ever-expanding, which contributes to this growing challenge. During this challenging time, people themselves play a crucial role. The problem of phishing, social engineering, and other attacks aimed at stealing passwords and credentials persists despite organizations throwing innovative cybersecurity technology and expertise at the problem.
Employee Participation Remains Low
Many security awareness solutions seem designed almost to discourage employees from participating, and it's hard to achieve 100% employee participation. Training can be hindered by complexity, length, or even access issues, which can prevent employees from engaging and learning.
Employees Lose Interest and Forget What They Learn
It is difficult to retain information from many training programs because they are repetitive, uninteresting, or too stuffed with content. As a matter of fact, science has shown that most learners forget what they learn within a day.
Security Programs Are an Administrative Burden
Administrators spend a lot of time on security awareness programs. Training platforms are managed by IT and security staff who select and assign courses, create and curate content, follow up with users and handle related chores like credentialing and user management. Developing, assigning, and delivering ongoing awareness programs can be simplified with fully managed programs. A managed program that is engaging and high-quality is maintained through this approach, ensuring that content is updated and complete.
Security Programs Focus on Compliance, Not Results
In many security awareness programs, regulators often trump what's necessary to actually prevent breaches versus what's necessary to satisfy regulators. Despite annual compliance training, what really matters is preventing breaches and protecting organizations, their customers, shareholders, partners, and the broader public.
It's important to comply with regulations, but focusing on this metric is the wrong approach. A security awareness program should be judged on how well it reduces intrusions, breaches, damage, and, ultimately, cyber risk.
More in News