Cyber training in 2023 needs to drive measurable change

2023 will see more focus on security training programmes that not only provide employees with an understanding of the risks they face but more importantly drive measurable behavioural change, says PA Consulting’s Richard Allen

By

  • Richard Allen

Published: 27 Feb 2023

As we enter 2023, the pace of technological change continues to accelerate, the effects of the Covid-19 pandemic continue to transform the ways organisations and their employees work, and there continue to be huge shortages of cyber security professionals. Cyber security training has rapidly evolved in recent years, so what might 2023 bring?

Cyber security awareness training

Today’s hybrid working world where many employees have access to critical data at home and are using business networks through personal devices or infrastructure continues to create heightened cyber risk for employers. Given that research shows that about 80 percent of cyber incidents can be avoided by practising simple cyber hygiene, 2023 will see many organisations continue to increase their spend on cyber security awareness training. This will need to cover not only basic areas such as password strength, protecting themselves from phishing and identity theft, but also focus on how workers should share and handle confidential data.

But not all cyber security awareness training is the same. This year we are specifically likely to see an increased move towards those providers whose platforms deliver intelligent cyber security awareness education, personalised advice and nudges/micro training in response to individual actions. These approaches aim to balance technology, process and people to build resilient organisational security cultures. With an increasing ability to measure behaviour, this type of platform significantly advances both the delivery of security training and the measurement of the impact of that training.

Increased demand for professional certifications 

Undoubtedly professional certifications make employees more attractive to prospective employers. As a result, some firms shy away from offering these to employees fearing that they are paying for someone to gain the qualifications needed for their next job. However, professional certifications can also play a key role in keeping security staff engaged and feeling like they have a future with the organisation.

Recent years have seen a proliferation of training providers and courses and it can be difficult to identify highly competent trainers and good quality courses. 2023, is likely to witness increased demand for industry recognised professional certifications from established training providers or for courses that have gained external assurance, such as those included on the NCSC Assured Training scheme.

A move back to the classroom

In the last few years there has been a sudden shift towards the online delivery of technical training, not least because of the Covid pandemic. While teaching cyber security online may seem like a logical extension of the digital age and perhaps the best way for people to learn, an increasing number of delegates are reverting to attending face-to-face training courses. This is particularly the case for those courses delivering a high degree of technical knowledge and skills. The reason may be as simple as delegates wanting a different experience from their day-to-day activities, but it’s more likely that face-to-face interaction with an instructor and other participants enables more effective non-verbal communication. Classroom training offers the ability to discuss, collaborate, and practice with a tutor on hand who can adapt the content and approach, resulting in a better learning outcome and experience.

Teaching technical cyber security skills to a wider audience

The global cyber security skills gap continues to be a challenge for many organisations. With the (ISC)2 2022 Cyber security Workforce Study suggesting 3.4 million more cyber security professionals are needed worldwide including 57,000 in the UK there is unlikely to be a quick resolution of this problem.

While many organisations have started to attempt to uncover and recruit diverse external talent in order to address this, the idea that just providing technical cyber security training to a narrow audience does not reflect reality. As a result, there is a growing trend for proactive industry leaders and organisations to provide a far greater number of their employees with this type of training. This also provides organisations with the opportunity to identify individuals with complementary skill sets who could move over to security roles.

Exercising

Developing cyber resilience has become a key objective of many organisations’ cyber security training efforts. Understanding how to respond to, continue to operate during, and recover from an attack is paramount. That requires developing processes, exercising them and training the individuals who can carry them out, at varying and increasing levels of complexity. This enables the organisation to keep up with the latest threats and attack trends not only by securing against them, but also by preparing for them to happen.

Historically, many organisations saw training as an expense rather than an investment. Now many recognise the importance of cyber security training to build a cyber secure organisation. That means the year ahead will see more focus on cyber security awareness training programmes that not only provide employees with an understanding of the risks they face but more importantly drive changes to their behaviours that can be measured. At the same time, the requirement to build technical capability will accelerate across organisations as they help provide the training their workforces need to get out in front of the bad guys.

Richard Allen is a cyber security expert at PA Consulting

Read more on Security policy and user awareness

Read More
Maribel Catt

Latest

Embracer Will Spin-Off ‘Fellowship Entertainment’ Into Its Own Company

"this approach represents the most effective long-term solution" by Ollie Reynolds 40 mins ago Image: Amazon Game Studios Embracer has announced its intention to spin-off Fellowship Entertainment into its own company in 2027. In the press release, founder Lars Wingefors states that the approach "represents the most effective long-term solution" for Embracer, with the intention

2027 NFL Draft Prospect Interview: Mikey D’Amato, LB, Cal Poly

2027 NFL Draft Prospect Interview: Mikey D’Amato, LB, Cal Poly Name: Mikey D’Amato Position: LB College: Cal Poly Height: 6′ 0″ Weight: 235 lbs X: @mikeydamato2 Instagram: @mikey_damato_ What made you decide you wanted to be a football player? It’s kind of in my blood, my pops he actually played in the NFL so honestly

These Types Of Vehicles Typically Depreciate Faster Than Others

Every gearhead has been in this situation. You're surfing through eBay Motors or Facebook Marketplace looking for cars, either just for fun or because you want a new project, and you see it: a European luxury car like a Mercedes S-Class, a BMW 7 Series, or something wild like a Maserati. The price is really

Roundtables: Inside the Musk v. Altman Trial

Watch subscriber-only discussion going behind the scenes of the trial and the implications for the AI race. Available only for MIT Alumni and subscribers. Listen to the session or watch below Elon Musk lost his suit against OpenAI, in which he alleged CEO Sam Altman and President Greg Brockman had deceived him over the company’s

Newsletter

Don't miss

Embracer Will Spin-Off ‘Fellowship Entertainment’ Into Its Own Company

"this approach represents the most effective long-term solution" by Ollie Reynolds 40 mins ago Image: Amazon Game Studios Embracer has announced its intention to spin-off Fellowship Entertainment into its own company in 2027. In the press release, founder Lars Wingefors states that the approach "represents the most effective long-term solution" for Embracer, with the intention

2027 NFL Draft Prospect Interview: Mikey D’Amato, LB, Cal Poly

2027 NFL Draft Prospect Interview: Mikey D’Amato, LB, Cal Poly Name: Mikey D’Amato Position: LB College: Cal Poly Height: 6′ 0″ Weight: 235 lbs X: @mikeydamato2 Instagram: @mikey_damato_ What made you decide you wanted to be a football player? It’s kind of in my blood, my pops he actually played in the NFL so honestly

These Types Of Vehicles Typically Depreciate Faster Than Others

Every gearhead has been in this situation. You're surfing through eBay Motors or Facebook Marketplace looking for cars, either just for fun or because you want a new project, and you see it: a European luxury car like a Mercedes S-Class, a BMW 7 Series, or something wild like a Maserati. The price is really

Roundtables: Inside the Musk v. Altman Trial

Watch subscriber-only discussion going behind the scenes of the trial and the implications for the AI race. Available only for MIT Alumni and subscribers. Listen to the session or watch below Elon Musk lost his suit against OpenAI, in which he alleged CEO Sam Altman and President Greg Brockman had deceived him over the company’s

Interview: How Volvo built software for a two-and-a-half-tonne moving object

Anders Bell points to his grey hair and laughs. “Three years ago, it was still blond and curly,” says Volvo’s chief engineering and technology officer. The remark is more than self-deprecating. It captures what Volvo has been through: five years of building a software-defined vehicle (SDV) from scratch, as a traditional carmaker, with no blueprint

Tesla’s Business Has Become Much More Diversified in Just the Past Five Years. Does That Make Its Stock a Better Buy Today?

Key Points Tesla's energy generation and storage segment generated 27% revenue growth last year. The company's non-automotive segments were able to help offset a double-digit decline in auto revenue in 2025. These 10 stocks could mint the next wave of millionaires › Tesla (NASDAQ: TSLA) is known for its electric vehicles (EVs), and while they

WD sees sustainability as key business driver in an ‘AI economy’

Hard drive company WD promoted long-term operations and sustainability executive Jackie Jung to become its first chief sustainability officer in February, as it steps up sales to companies building AI data centers. Her vision: Turn sustainability into a “brand” for WD, a strategy that reduces risk for the $6 billion company (formerly known as Western

5 Business Ideas Worth Starting in 2026

If there is one thing Nigerians understand well, it is how to spot opportunity inside hardship. In 2026, that mindset will matter more than ever. The economy is tough, competition is rising, and many people are looking for smarter ways to earn, build, and survive. But even in a difficult environment, some businesses still stand