Security Think Tank: New trends and drivers in cyber security training

Self-paced, interactive, bite-sized learning is becoming the optimum path for cyber security training in the workplace, says John Tolbert of KuppingerCole

John Tolbert

By

Published: 16 Feb 2023

Cyber security training is a vital security strategy for many enterprises across the world. Such training has been established at large companies and government organisations for many years now. Small to medium size businesses have increasingly seen the value in contracting in training to help users avoid common security issues. Cyber security training is also required for regulatory and standards regimes such as ISO 27001.

Phishing and other threats

Phishing remains one of the biggest threats that everyone faces. Fraudsters and cyber criminals have different and variable tactics for phishing campaigns. These bad actors have and will continue to adapt to increasingly prepared workforces. Gaining access to user accounts is almost always a motive. Spear-phishing is the more highly targeted variant, wherein executives and administrators are the intended victims. Email used to the be primary vector for phishing. It still is a highly used channel, but cybercriminals now also use SMS text messages, other messaging apps, social media messaging, and phone calls (sometimes called vishing, for voice phishing). Enterprise cyber security training programs have traditionally focused on the email vector, but they also need to take into account the variety of attack channels to show users what kinds of phishing content may appear in all these different communications platforms.

But phishing is not the only subject for cyber security training. Other subjects that users need periodic reminders about include deterring tailgating into facilities (bypassing physical access controls), password management, how to handle removable media, using only sanctioned cloud services, not sending company data and personal information over unapproved channels such as personal email, not revealing company information on social media, avoiding using public wireless networks, using VPNs, and so forth. 

Most training of this nature is designed to raise user awareness to prevent user errors that lead to cyber security incidents. But employees need to know what to do when something bad happens. What should they do when they receive a phishing email? What should they do when they believe that confidential information has been compromised? What should they do when ransomware detonates on their machines?

Most companies have policies for many such situations, but assessing user responses and providing guidance in the case of cyber security incidents can go a long way to reducing the damage that can be done.

Evolution of training formats and trends

When organisations began conducting cyber security training in the 2000s, it was generally an annual exercise. Those training classes for the general user population may have been offered at employee onboarding only or annually for all employees for an hour or two.

Today we see companies and cyber security training service providers offering much more frequent sessions, sometimes even on a monthly basis. However, the more frequent training programs are shorter in duration. In fact, some sessions may only be three to five minute refresher videos and quizzes.

Shorter and more frequent training sessions offer multiple advantages, such as less time out of the workday at once, increased user participation, and greater user satisfaction. Perhaps most importantly, the training material can be updated faster to reflect the constantly changing threat landscape.

Videos are the preferred format, but user interaction is key. Training sessions start with reminders and updates about the threat landscape. Real-world examples have the most impact. Leverage cyber security news stories that have been publicised. Testing users’ knowledge at the end of each session can be enlightening for organisations to gauge the susceptibility of the workforce to prevailing attacker techniques and better quantify those risks. This can serve as a feedback loop for additional training, augmentation of training and other security controls. Testing can also be fun for the users if done right, with rewards and positive reinforcement for participation and correct answers.

Current training regimes also feature self-paced learning. Users receive invitations to take training when it fits their own schedules. This avoids conflicts with other work. Of course, deadlines and reminders to need to be put in place to ensure that training takes place. On the other hand, there is value to having short training sessions that interrupt non-critical work. This is to address situations when users are indeed busy and are more likely to make mistakes in judgment that adversely affect organizational security posture.

There are a number of cyber security training services to choose from that offer these kinds of training in multiple formats and styles. With account takeover and ransomware attacks proliferating, now is the time to emphasise cyber security best practices amongst your user populations.

Recommendations

  • Increase the frequency of cyber security training sessions for your employees, while decreasing the duration of each session.
  • Ensure that new training content is based on up-to-date threat information.
  • Look for cyber security training services that provide customizable content that meet the needs of your organisation.
  • Promote an open culture that encourages users to report suspicious behaviour and rewards cyber security vigilance.

Read more on Security policy and user awareness

Read More
Tama Geddes

Latest

RubyPlay partners with Caesars Entertainment in Ontario to advance North American expansion

RubyPlay, a studio-based content ecosystem, is further strengthening its presence in Ontario as part of its broader North American growth strategy with a new partnership with Caesars Entertainment. The partnership will see a curated selection of RubyPlay’s fan-favourite titles, including JMania® Lucky Pyggs, Mad Hit® Mr Coin and Diamond Explosion® 7s SE, made available on

Wizkid wins “Best African Music Act” at the 2026 MOBO Awards, beats Davido, Tyla, Rema

MusicRead Later (0)Please login to bookmark Close Nigerian superstar Wizkid...

Newsletter

Don't miss

RubyPlay partners with Caesars Entertainment in Ontario to advance North American expansion

RubyPlay, a studio-based content ecosystem, is further strengthening its presence in Ontario as part of its broader North American growth strategy with a new partnership with Caesars Entertainment. The partnership will see a curated selection of RubyPlay’s fan-favourite titles, including JMania® Lucky Pyggs, Mad Hit® Mr Coin and Diamond Explosion® 7s SE, made available on

Wizkid wins “Best African Music Act” at the 2026 MOBO Awards, beats Davido, Tyla, Rema

MusicRead Later (0)Please login to bookmark Close Nigerian superstar Wizkid...

South Block Continues Rapid Expansion Adding 24th Block in Burke, Virginia, March 28

MusicFirst 100 grand opening guests score free Mini...

Family Business? Tee Grizzley Reacts After His Mom Accuses Him Of Leaving Her To Struggle (PHOTOS)

Y’all… it looks like some family tension might be brewing behind the scenes involving Tee Grizzley and his mom. What seemed like a regular social media post quickly turned into something deeper. And now, folks are side-eyeing the situation and wondering what’s really going on. RELATED: Tee Grizzley Shares A Message For Artists After His

SoE necessary but not sufficient, business leaders say

PE­TER CHRISTO­PHER Se­nior Mul­ti­me­dia Re­porter pe­ter.christo­pher@guardian.co.tt Heavy hand­ed but nec­es­sary giv­en the state of crime in T&T. This was a com­mon as­sess­ment from var­i­ous busi­ness groups when asked for their per­spec­tive on the lat­est de­c­la­ra­tion of a state of emer­gency in the coun­try. The T&T Cham­ber of In­dus­try and Com­merce, in a re­leased is­sued yes­ter­day

The Big Business of Carolyn Bessette-Kennedy

Can a nine-episode limited series really impact an entire season of shopping trends? Today brands are experiencing—and chasing—the “Carolyn Bessette-Kennedy effect” as a result of Ryan Murphy’s Love Story. And in many cases, it’s more pervasive than they could have prepared for. The FX series, based on the relationship between John F. Kennedy Jr. and