Security Think Tank: Training can no longer be a compliance exercise

Historically, security training has tended to take a compliance-based focus, a ‘tick-box’ exercise using generic, off-the-shelf courses. This needs to change, says Hayley Watson of Turnkey Consulting.

Hayley Watson

By

Published: 28 Feb 2023

‘Humans are the weakest link’ has been the refrain of the IT security community for many years and, with social engineering attacks becoming ever more prominent and sophisticated, an organisation’s people will continue to be one of its biggest security risks.

Despite this, educating this core line of defence has tended to take a compliance-based focus, a ‘tick-box’ exercise using generic, off-the-shelf courses outlining the perils of social engineering, with little included to raise awareness around why training needs to be undertaken. Perhaps unsurprisingly, one of the biggest challenges is getting the average system user to complete this cyber security coaching, which is often seen as an inconvenience and not the key enabler in defending the perimeter that it is.

A risk-based approach

However, 2022 saw training and awareness start to evolve to take a more balanced ‘human risk’ approach. This acknowledges that there is a significant risk of people clicking on phishing emails and Business Email Compromise (BEC) scams, and that more should be done to manage it in the same way as other organisational risk, with targeted remediation and mitigating controls applied.

One focal point is the area of behavioural change. While it is possible to show if someone has completed a cyber security training module, few security tools can indicate whether the individual has paid attention and is actively making smarter decisions to reduce the risk they encounter every day. Altering behaviour generally requires a different approach – one that incorporates targeted training, repeated at frequent intervals to ensure the key points are retained and acted upon. (This must be undertaken without overloading the user with constant reminders, or lengthy exercises – both of which are likely to be ignored.)

Typically, business areas such as HR, finance, and IT support get most of the attention levelled at cyber security training as they have access to confidential information or privileged access to applications and processes. But a more advanced approach is to review all parts of the business; analysing incident reports will show where risks are materialising, and training completion rates, along with scores from short tests undertaken after the course, will indicate where people struggle. The threat landscape, and its change over time, also needs to be a consideration as it will indicate where to focus in terms of improving staff knowledge and awareness.

Going further, training should be graduated based on the risks that are present within a particular job role and the impact to the business, should the person in that role be compromised. The education (and testing of that education) of an employee who has privileged access to servers, databases or applications for example must have more rigour applied to it than that of someone with no access to IT assets; to do this effectively requires some alignment of training delivery with identity provisioning, based on the risk profile of assets.

Training tools

When it comes to the content itself, the simulation of security incidents is now a mainstay of training and awareness programmes, and a key component in helping organisations to understand their risk. These typically take the form of phishing simulations, which are invaluable for measuring how individuals react when they receive something suspicious.

Gamification, which is becoming increasingly popular in many other areas of learning, is a way to make cyber security training more fun and engaging; enabling employees to play out a disaster scenario can demonstrate the importance of security measures by helping them to visualise what an attack or breach may look like from start to finish.

Other successful and creative training methods organisations have deployed include getting employees to watch relevant TV shows (such as Mr Robot) and turning security training into a mini-TV series of their own. Facilitated ‘wargame’ sessions for senior managers, in which one side acts as attackers and the other as defence, is also a good way to help people understand some of the techniques and challenges. The key is getting to know the audience and what will work to engage them.

It’s also important to acknowledge an organisation’s culture and where people are based geographically. Some parts of the business could react differently to the types of training on offer. Gamification, or introducing leader boards, might be a huge hit in one part of the enterprise for example, but ridiculed by another.

Make it personal

A key element of security training and awareness activity is communicating the responsibility that employees have to keep the company safe, as well as ensuring that they perceive there to be a real threat. Content needs to provide real life examples that are applicable to the audience and the level of risk associated with their role and the industry. Emphasising the impact an attack could have on the employee, as well as the organisation, provides an ‘emotional’ hook, and encourages people to look at what they can do to avoid falling victim in the first place.

Educating employees on cyber risk in the personal context so that they change their behaviour when handling their own information, is likely to also have a positive impact on their actions in the workplace.

An ongoing process

Most people won’t overtly deal with cyber security in their daily tasks, meaning skills and facts may not stick in their minds; training therefore needs to be an ongoing process. This is where integrated tools such as KnowBe4 are useful; the platform allows organisations to periodically send simulated phishing attacks across the enterprise, testing employees’ awareness of phishing and reactions to it. Emails can be edited to mimic any threat employees may face, they also encourage staff to go through the process of reporting the attack within their email interface, thereby providing a physical refresher of what to look out for and how to deal with it.

Carrot not stick

The key to successful security awareness training is to engage all staff in the overall journey, with a key contributor to this approach being incentives for reducing cyber attack based risk, such as bonuses or gifts for the teams with the lowest click-rate on phishing emails, or publicly praising employees who correctly identify genuine phishing attempts or suspicious behaviour. Creating ‘security champions’ within the business provides an aspirational goal, and competition between divisions or locations for the best performance in training can be beneficial.

It’s critical however to avoid a punitive approach; if someone fails a simulation test (or any other type of training module), the message needs to be supportive and educational. Making people feel foolish leads to resentment, an unwillingness to undertake further training and potentially a reluctance to report future incidents for fear of being embarrassed again.

A secure culture

As organisations large and small continue to be hit by cyber attacks, there is no doubt about the need for protection. Technology has many of the answers, but it must be reinforced with knowledgeable and engaged employees, who each understand their role in keeping out bad actors. This requires a commitment to cyber security education, as well as a desire to see training evolve to better meet the needs of today’s enterprise, while helping to make security awareness part of the organisation’s culture.

Read more on Security policy and user awareness

Read More
Rebecka Geddes

Latest

RubyPlay partners with Caesars Entertainment in Ontario to advance North American expansion

RubyPlay, a studio-based content ecosystem, is further strengthening its presence in Ontario as part of its broader North American growth strategy with a new partnership with Caesars Entertainment. The partnership will see a curated selection of RubyPlay’s fan-favourite titles, including JMania® Lucky Pyggs, Mad Hit® Mr Coin and Diamond Explosion® 7s SE, made available on

Wizkid wins “Best African Music Act” at the 2026 MOBO Awards, beats Davido, Tyla, Rema

MusicRead Later (0)Please login to bookmark Close Nigerian superstar Wizkid...

Newsletter

Don't miss

RubyPlay partners with Caesars Entertainment in Ontario to advance North American expansion

RubyPlay, a studio-based content ecosystem, is further strengthening its presence in Ontario as part of its broader North American growth strategy with a new partnership with Caesars Entertainment. The partnership will see a curated selection of RubyPlay’s fan-favourite titles, including JMania® Lucky Pyggs, Mad Hit® Mr Coin and Diamond Explosion® 7s SE, made available on

Wizkid wins “Best African Music Act” at the 2026 MOBO Awards, beats Davido, Tyla, Rema

MusicRead Later (0)Please login to bookmark Close Nigerian superstar Wizkid...

South Block Continues Rapid Expansion Adding 24th Block in Burke, Virginia, March 28

MusicFirst 100 grand opening guests score free Mini...

Family Business? Tee Grizzley Reacts After His Mom Accuses Him Of Leaving Her To Struggle (PHOTOS)

Y’all… it looks like some family tension might be brewing behind the scenes involving Tee Grizzley and his mom. What seemed like a regular social media post quickly turned into something deeper. And now, folks are side-eyeing the situation and wondering what’s really going on. RELATED: Tee Grizzley Shares A Message For Artists After His

SoE necessary but not sufficient, business leaders say

PE­TER CHRISTO­PHER Se­nior Mul­ti­me­dia Re­porter pe­ter.christo­pher@guardian.co.tt Heavy hand­ed but nec­es­sary giv­en the state of crime in T&T. This was a com­mon as­sess­ment from var­i­ous busi­ness groups when asked for their per­spec­tive on the lat­est de­c­la­ra­tion of a state of emer­gency in the coun­try. The T&T Cham­ber of In­dus­try and Com­merce, in a re­leased is­sued yes­ter­day

The Big Business of Carolyn Bessette-Kennedy

Can a nine-episode limited series really impact an entire season of shopping trends? Today brands are experiencing—and chasing—the “Carolyn Bessette-Kennedy effect” as a result of Ryan Murphy’s Love Story. And in many cases, it’s more pervasive than they could have prepared for. The FX series, based on the relationship between John F. Kennedy Jr. and