Compliance Does Not Equal Security

Compliance Does Not Equal Security

I train a lot of people, and I always like to ask whether they have done this type of training before. Largely people in this day and age have done some flavour of cyber awareness training.

But no matter, the flow of the workshops are nearly always the same - I work through the content and people say things like "I didn't know that!" or "OMG" or "I want to live in a cave now".

At the end when I summarise I always get positive feedback, lots of comments about new things learned, and how scary it was. To which I say: "But you know this stuff now and that keeps you safer, so you can be far more confident online".

So what's the disconnect here? People have done awareness training, but they still don't know a lot of the things I teach. That's not right.

The problem, is that they haven't "done" awareness training. They've more accurately been "presented" with awareness training, so that a company can tick a box. People are largely presented with boring content, they work through it while disinterested and likely multi-tasking, they fumble through some quizzes at the end, and now the box has been ticked.

That's compliance. The company might have to do this to comply with a cyber security framework. What has been achieved? Not much. I know it's not much, because I train these people, and they don't know what I'm showing them! And cyber security awareness is NOT a one off thing. This is not people's jobs - they need regular training and reminders to keep them informed and suspicious.

What it comes down to is whether you care about risk, or just compliance. Given the average cost of a data breach (in the millions), surely companies should care about reducing risk? And yet, they still often don't.

If you only want to tick a box to say you've done awareness training for your staff, then you're likely still accepting a large amount of risk. Risk has a probability of occurring, so it's only a matter of time before a staff member is tricked, and your network is hacked. Now suddenly the money you saved on awareness training by using cheap and boring online content is soaked up a thousand times over with your incident response costs.

And that's when I get called in.

Original article can be found here.


Santiago Bernhardt

Fractional with experience in Architecture, Platform, DevOps, SRE and Security.

10 个月

The balance of tickboxing and actual security posture is what kills the industry. Too much bluff from senior leaders that will end in breaches and leaks. +1 to training and ongoing assurance and reminding.

Elliot Seeto

Executive Coach - Cybersecurity - Pax8 APAC Academy

10 个月

Excellent call out Mike. Great article.

要查看或添加评论,请登录

Mike Ouwerkerk的更多文章

  • How to get staff to watch awareness videos

    How to get staff to watch awareness videos

    Cyber security awareness is not a one off initiative. People will slowly forget information they are taught, that's a…

    1 条评论
  • 10 Hard Truths About Cyber Security Awareness

    10 Hard Truths About Cyber Security Awareness

    I've been in the trenches of cyber security awareness for quite a few years now. In that time I've made a lot of…

    3 条评论
  • How do we spot deep fakes? Don’t bother!

    How do we spot deep fakes? Don’t bother!

    If you haven’t heard of deep fakes, it’s the use of technology to pretend to be someone. You can recreate someone’s…

  • Conversations with a Romance Scammer

    Conversations with a Romance Scammer

    OK, I'm out - "She" wants to have a voice chat. For the last week or so I've been chatting to a romance scammer.

    17 条评论
  • "Human Error" in Cyber Security - It's not what you think!

    "Human Error" in Cyber Security - It's not what you think!

    It's a constant message in cyber security - companies are being breached, and they blame "human error" for about 90% of…

    8 条评论
  • Cyber Security Cultural Change for SMEs

    Cyber Security Cultural Change for SMEs

    The war with cyber criminal scumbags wages on, and unfortunately the battle is still being lost by the good guys…

    5 条评论
  • Toot Toot Here Comes the Deep Fake Pain Train

    Toot Toot Here Comes the Deep Fake Pain Train

    The Scam Picture this: The receptionist gets to work, and there's a voicemail from the IT Manager saying that cleaners…

    2 条评论
  • The Benefits of Cyber Crime

    The Benefits of Cyber Crime

    Yeah I'm gonna go there. Doom and gloom is all we hear, the global economy is losing trillions, companies are getting…

    18 条评论
  • It's All About the Lightbulb Moments

    It's All About the Lightbulb Moments

    Metrics in cyber security awareness can be a bit of an art form, and will need to vary between organisations. But I…

  • My nomination for "10 Best Security companies in Asia 2019 (Asia Edition)"

    My nomination for "10 Best Security companies in Asia 2019 (Asia Edition)"

    I had a bit of fun baiting some more scammers / scumbags. No doubt they'll email me for the same bogus award next year…

    6 条评论

社区洞察

其他会员也浏览了