Security Think Tank: Training can no longer be a compliance exercise

Historically, security training has tended to take a compliance-based focus, a ‘tick-box’ exercise using generic, off-the-shelf courses. This needs to change, says Hayley Watson of Turnkey Consulting.

Hayley Watson

By

Published: 28 Feb 2023

‘Humans are the weakest link’ has been the refrain of the IT security community for many years and, with social engineering attacks becoming ever more prominent and sophisticated, an organisation’s people will continue to be one of its biggest security risks.

Despite this, educating this core line of defence has tended to take a compliance-based focus, a ‘tick-box’ exercise using generic, off-the-shelf courses outlining the perils of social engineering, with little included to raise awareness around why training needs to be undertaken. Perhaps unsurprisingly, one of the biggest challenges is getting the average system user to complete this cyber security coaching, which is often seen as an inconvenience and not the key enabler in defending the perimeter that it is.

A risk-based approach

However, 2022 saw training and awareness start to evolve to take a more balanced ‘human risk’ approach. This acknowledges that there is a significant risk of people clicking on phishing emails and Business Email Compromise (BEC) scams, and that more should be done to manage it in the same way as other organisational risk, with targeted remediation and mitigating controls applied.

One focal point is the area of behavioural change. While it is possible to show if someone has completed a cyber security training module, few security tools can indicate whether the individual has paid attention and is actively making smarter decisions to reduce the risk they encounter every day. Altering behaviour generally requires a different approach – one that incorporates targeted training, repeated at frequent intervals to ensure the key points are retained and acted upon. (This must be undertaken without overloading the user with constant reminders, or lengthy exercises – both of which are likely to be ignored.)

Typically, business areas such as HR, finance, and IT support get most of the attention levelled at cyber security training as they have access to confidential information or privileged access to applications and processes. But a more advanced approach is to review all parts of the business; analysing incident reports will show where risks are materialising, and training completion rates, along with scores from short tests undertaken after the course, will indicate where people struggle. The threat landscape, and its change over time, also needs to be a consideration as it will indicate where to focus in terms of improving staff knowledge and awareness.

Going further, training should be graduated based on the risks that are present within a particular job role and the impact to the business, should the person in that role be compromised. The education (and testing of that education) of an employee who has privileged access to servers, databases or applications for example must have more rigour applied to it than that of someone with no access to IT assets; to do this effectively requires some alignment of training delivery with identity provisioning, based on the risk profile of assets.

Training tools

When it comes to the content itself, the simulation of security incidents is now a mainstay of training and awareness programmes, and a key component in helping organisations to understand their risk. These typically take the form of phishing simulations, which are invaluable for measuring how individuals react when they receive something suspicious.

Gamification, which is becoming increasingly popular in many other areas of learning, is a way to make cyber security training more fun and engaging; enabling employees to play out a disaster scenario can demonstrate the importance of security measures by helping them to visualise what an attack or breach may look like from start to finish.

Other successful and creative training methods organisations have deployed include getting employees to watch relevant TV shows (such as Mr Robot) and turning security training into a mini-TV series of their own. Facilitated ‘wargame’ sessions for senior managers, in which one side acts as attackers and the other as defence, is also a good way to help people understand some of the techniques and challenges. The key is getting to know the audience and what will work to engage them.

It’s also important to acknowledge an organisation’s culture and where people are based geographically. Some parts of the business could react differently to the types of training on offer. Gamification, or introducing leader boards, might be a huge hit in one part of the enterprise for example, but ridiculed by another.

Make it personal

A key element of security training and awareness activity is communicating the responsibility that employees have to keep the company safe, as well as ensuring that they perceive there to be a real threat. Content needs to provide real life examples that are applicable to the audience and the level of risk associated with their role and the industry. Emphasising the impact an attack could have on the employee, as well as the organisation, provides an ‘emotional’ hook, and encourages people to look at what they can do to avoid falling victim in the first place.

Educating employees on cyber risk in the personal context so that they change their behaviour when handling their own information, is likely to also have a positive impact on their actions in the workplace.

An ongoing process

Most people won’t overtly deal with cyber security in their daily tasks, meaning skills and facts may not stick in their minds; training therefore needs to be an ongoing process. This is where integrated tools such as KnowBe4 are useful; the platform allows organisations to periodically send simulated phishing attacks across the enterprise, testing employees’ awareness of phishing and reactions to it. Emails can be edited to mimic any threat employees may face, they also encourage staff to go through the process of reporting the attack within their email interface, thereby providing a physical refresher of what to look out for and how to deal with it.

Carrot not stick

The key to successful security awareness training is to engage all staff in the overall journey, with a key contributor to this approach being incentives for reducing cyber attack based risk, such as bonuses or gifts for the teams with the lowest click-rate on phishing emails, or publicly praising employees who correctly identify genuine phishing attempts or suspicious behaviour. Creating ‘security champions’ within the business provides an aspirational goal, and competition between divisions or locations for the best performance in training can be beneficial.

It’s critical however to avoid a punitive approach; if someone fails a simulation test (or any other type of training module), the message needs to be supportive and educational. Making people feel foolish leads to resentment, an unwillingness to undertake further training and potentially a reluctance to report future incidents for fear of being embarrassed again.

A secure culture

As organisations large and small continue to be hit by cyber attacks, there is no doubt about the need for protection. Technology has many of the answers, but it must be reinforced with knowledgeable and engaged employees, who each understand their role in keeping out bad actors. This requires a commitment to cyber security education, as well as a desire to see training evolve to better meet the needs of today’s enterprise, while helping to make security awareness part of the organisation’s culture.

Read more on Security policy and user awareness

Read More
Rebecka Geddes

Latest

Mentalist Oz Pearlman Will Get Inside Trump’s Mind at the White House Correspondents’ Dinner

Typically, the White House Correspondents’ Dinner features a comedian for its star act. In years past, the journalists, executives, agents, and miscellaneous members of the DC establishment have gathered at the Washington Hilton to hear speeches from the head of the correspondents’ association and the president. Then a comedian gets up to properly skewer the

David Pollack Reflects on Being Laid Off From ESPN College GameDay

Moving from the Saturday morning spotlight to a home studio was a major shift for one of the most decorated defensive players in college football history. David Pollack, the former Georgia Bulldog and longtime ESPN mainstay, recently shared his perspective on the day his 13-year tenure at the network came to an abrupt end. Appearing

Star High School Football Player Shot and Killed in Texas

Star High School Football Player Shot and Killed in Texas A Lancaster High School football player was shot and killed during an off-campus shooting this week. Myers Anthony, a 16-year-old football star at Lancaster High School in Lancaster. The shooting is still being investigated as a homicide and appears to be an isolated incident. Anthony

New Orleans Saints News, April 16: Could Arvell Reese fall to the Saints?

Skip to main content Here are today’s Saints news links Apr 16, 2026, 12:30 PM UTC Welcome to today’s roundup of New Orleans Saints and NFL news! Some Saints players are showing up off the football field. A worrying trend. Without a doubt for the Saints. New Orleans Saints News Apr 15 New Orleans Saints

Newsletter

Don't miss

Mentalist Oz Pearlman Will Get Inside Trump’s Mind at the White House Correspondents’ Dinner

Typically, the White House Correspondents’ Dinner features a comedian for its star act. In years past, the journalists, executives, agents, and miscellaneous members of the DC establishment have gathered at the Washington Hilton to hear speeches from the head of the correspondents’ association and the president. Then a comedian gets up to properly skewer the

David Pollack Reflects on Being Laid Off From ESPN College GameDay

Moving from the Saturday morning spotlight to a home studio was a major shift for one of the most decorated defensive players in college football history. David Pollack, the former Georgia Bulldog and longtime ESPN mainstay, recently shared his perspective on the day his 13-year tenure at the network came to an abrupt end. Appearing

Star High School Football Player Shot and Killed in Texas

Star High School Football Player Shot and Killed in Texas A Lancaster High School football player was shot and killed during an off-campus shooting this week. Myers Anthony, a 16-year-old football star at Lancaster High School in Lancaster. The shooting is still being investigated as a homicide and appears to be an isolated incident. Anthony

New Orleans Saints News, April 16: Could Arvell Reese fall to the Saints?

Skip to main content Here are today’s Saints news links Apr 16, 2026, 12:30 PM UTC Welcome to today’s roundup of New Orleans Saints and NFL news! Some Saints players are showing up off the football field. A worrying trend. Without a doubt for the Saints. New Orleans Saints News Apr 15 New Orleans Saints

How NFL Prospects Can Build a Winning Football Resume

How NFL Prospects Can Build a Winning Football Resume For serious football players, a clean, well-structured football resume example can help turn game film into something a coach, scout, recruiter, or personnel staffer can scan fast and actually use. The competition is brutal at every level, with only 1.4% of NCAA football players drafted into the NFL

Family Business? Tee Grizzley Reacts After His Mom Accuses Him Of Leaving Her To Struggle (PHOTOS)

Y’all… it looks like some family tension might be brewing behind the scenes involving Tee Grizzley and his mom. What seemed like a regular social media post quickly turned into something deeper. And now, folks are side-eyeing the situation and wondering what’s really going on. RELATED: Tee Grizzley Shares A Message For Artists After His

SoE necessary but not sufficient, business leaders say

PE­TER CHRISTO­PHER Se­nior Mul­ti­me­dia Re­porter pe­ter.christo­pher@guardian.co.tt Heavy hand­ed but nec­es­sary giv­en the state of crime in T&T. This was a com­mon as­sess­ment from var­i­ous busi­ness groups when asked for their per­spec­tive on the lat­est de­c­la­ra­tion of a state of emer­gency in the coun­try. The T&T Cham­ber of In­dus­try and Com­merce, in a re­leased is­sued yes­ter­day

The Big Business of Carolyn Bessette-Kennedy

Can a nine-episode limited series really impact an entire season of shopping trends? Today brands are experiencing—and chasing—the “Carolyn Bessette-Kennedy effect” as a result of Ryan Murphy’s Love Story. And in many cases, it’s more pervasive than they could have prepared for. The FX series, based on the relationship between John F. Kennedy Jr. and