10 Hard Truths About Cyber Security Awareness

10 Hard Truths About Cyber Security Awareness

I've been in the trenches of cyber security awareness for quite a few years now. In that time I've made a lot of observations, so here's my list of 10 hard truths for what NOT to do:

  1. Don't give training that is boring. People don't like boring, they don't learn, they don't change behaviours.
  2. Don't give people the opportunity to multi-task. If they are doing two things are once, they are doing two things badly at once. If someone is doing awareness training while checking their emails, then really they're just checking their emails. Money, meet drain.
  3. Don't leave management out of training sessions. They should be in on every session, leading from the front, asking questions, and showing others they care! If they're sitting in on a session and using their laptop, frankly, they're not a leader, they're a bad example and the cause of a wasted opportunity.
  4. Don't talk about protecting the business. Instead, talk about personal impact. Newsflash - people don't care about the business much. What they do care about is their own money, and their own confidential information.
  5. Don't punish someone for getting tricked. It's not their fault. Be supportive, give them help to not get tricked again. If you reprimand them, they will probably never report being tricked again, and that WILL be a disaster.
  6. Don't train for compliance. Ticking boxes means you'll do the minimum, and get hacked more often. If you give people minimal training for compliance, you are spending money with little to no financial benefit. They're not learning, and you've still got vulnerable people.
  7. Don't call people the 'weakest link' . Ever. If you're responsible for risk and you don't equip your staff to deal with cyber criminals, then YOU are the weakest link. Also, you can't seriously expect people to change, if you've blamed them for a problem that isn't theirs. That's just demotivating!
  8. Don't do awareness training once every 3 years, and expect to be safe. You're not. What you are is a ticking time bomb. Cyber security awareness is not the core job of your staff. It takes good training, and reinforcement to build knowledge, and change behaviours. And what are you doing with the new staff in this time exactly?
  9. Don't forget about suspicion. If you want people to be aware, they first have to be suspicious. Build that little voice in their head that is constantly asking "could this be a scam"? Suspicion leads to awareness, because people will naturally question, and look for answers. That leads to behaviour changes, and that leads to a culture of awareness. So peak their suspicion, by talking about scams regularly.
  10. Don't complicate things. Keep it simple, like 16 years old simple. If you talk about smishing and vishing and qishing, you're filling their brains with stuff that just doesn't matter. They mostly need to know about things like common scam warning signs, links, file extensions, and procedures for checking information.

Original article can be found here.


John Daddow - AI For Business

Passionate about the future of AI in phone communication. Let's connect.

11 个月

Excellent insights on what to avoid in cyber security awareness! Understanding these hard truths is crucial for a robust defense against cyber threats. How do you continually reinforce these principles to ensure they become ingrained in everyday practices? #cybersecurityawareness #continuousimprovement

回复
Patrick Conheady

Will migrate applications for money

11 个月

Number 7 is my favourite.

要查看或添加评论,请登录

Mike Ouwerkerk的更多文章

  • How to get staff to watch awareness videos

    How to get staff to watch awareness videos

    Cyber security awareness is not a one off initiative. People will slowly forget information they are taught, that's a…

    1 条评论
  • Compliance Does Not Equal Security

    Compliance Does Not Equal Security

    I train a lot of people, and I always like to ask whether they have done this type of training before. Largely people…

    3 条评论
  • How do we spot deep fakes? Don’t bother!

    How do we spot deep fakes? Don’t bother!

    If you haven’t heard of deep fakes, it’s the use of technology to pretend to be someone. You can recreate someone’s…

  • Conversations with a Romance Scammer

    Conversations with a Romance Scammer

    OK, I'm out - "She" wants to have a voice chat. For the last week or so I've been chatting to a romance scammer.

    17 条评论
  • "Human Error" in Cyber Security - It's not what you think!

    "Human Error" in Cyber Security - It's not what you think!

    It's a constant message in cyber security - companies are being breached, and they blame "human error" for about 90% of…

    8 条评论
  • Cyber Security Cultural Change for SMEs

    Cyber Security Cultural Change for SMEs

    The war with cyber criminal scumbags wages on, and unfortunately the battle is still being lost by the good guys…

    5 条评论
  • Toot Toot Here Comes the Deep Fake Pain Train

    Toot Toot Here Comes the Deep Fake Pain Train

    The Scam Picture this: The receptionist gets to work, and there's a voicemail from the IT Manager saying that cleaners…

    2 条评论
  • The Benefits of Cyber Crime

    The Benefits of Cyber Crime

    Yeah I'm gonna go there. Doom and gloom is all we hear, the global economy is losing trillions, companies are getting…

    18 条评论
  • It's All About the Lightbulb Moments

    It's All About the Lightbulb Moments

    Metrics in cyber security awareness can be a bit of an art form, and will need to vary between organisations. But I…

  • My nomination for "10 Best Security companies in Asia 2019 (Asia Edition)"

    My nomination for "10 Best Security companies in Asia 2019 (Asia Edition)"

    I had a bit of fun baiting some more scammers / scumbags. No doubt they'll email me for the same bogus award next year…

    6 条评论

社区洞察

其他会员也浏览了