How does cybersecurity awareness and training reduce risk to your organization?
CIOREVIEW >> Cyber Security >> NEWS

This article is part of CIOReview's Innovation Insights series featuring expert contributions nominated by our subscribers and reviewed by our editorial team.

How does cybersecurity awareness and training reduce risk to your organization?

John Bruggeman, CISSP, is a veteran technologist, CTO, and CISO, CBTS

Some people throw up their hands in frustration or resignation when I talk about cybersecurity awareness and training (A&T). I get it. I’m not new to computer security. I’ve been around the block a few times and I understand that training employees about cybersecurity risks feels like a losing battle.

But I have learned through experience that a good cybersecurity A&T program is worth its weight in gold.

How is that possible?

How can well-trained end users be an asset and not a liability?

Fairly easy actually, but you have to have a plan and you have to have buy-in at the top of the organization.

In this article I’ll outline the five areas that are key to a successful cybersecurity awareness and training program:

1. Leadership support and commitment.

2. Risk assessment and target audience.

3. Customized training.

4. Regular communication and reinforcement.

5. Ongoing evaluation and improvement.

Some of these areas might seem obvious, but as someone who has been on the front lines, what seems simple in theory is not always simple in practice and can be hard to accomplish.

1) Starting at the top, item number one, leadership support and commitment. You might think that every business or organization leader would want a well-trained workforce. A workforce that can easily spot a phishing e-mail or phone call (vishing) or SMS message (smishing) and then not click on the link. Employees that politely ask an unknown person who they are, why they are there, do they have an appointment, or other general questions when a stranger is in the building.

  â€‹If the CEO says cybersecurity awareness and training is important, takes the training, and asks others about it, the message will be clear to everyone that cybersecurity is everyone’s job.  

But business leaders or organization leaders need a clear business case to invest resources into an awareness and training program. Training that doesn’t lead to an industry certification often doesn’t appear to add value or revenue. Make a solid business case that demonstrates the potential risks to the business if information is compromised or stolen. Document the impact and costs associated with cybersecurity incidents.

I recommend that you highlight the importance of protecting sensitive or confidential information, maintaining customer trust, and mitigating potential financial and reputational damage when your organization is attacked. Showcase how the cybersecurity program aligns with the organization's strategic objectives. Emphasize how a robust security posture contributes to operational resilience, regulatory compliance, and overall business success.

If you can clearly articulate the potential return on investment for the cybersecurity program, you have won half the battle.

2) This leads directly into number two, risk assessment and target audience. Unless you are the CISO and know what is in your risk register, you will need to find out how risky things are for your organization. First, consider your general business exposure or risk profile. Are you a health care provider, an organization that is targeted daily due to the valuable personal health information (PHI) it has, or a manufacturer that can’t afford significant downtime? Do you run an e-commerce store that generates most of your organization’s revenue? Figure that out first.

Now that you’ve identified your general business exposure, know what kind of controls you have in place to mitigate the risk and protect your sensitive or confidential information. For the questions about the controls, talk to your CISO or head of cybersecurity. Answering these two big questions will give you a general sense of your risk.

Now think about your target audience for awareness and training. Who needs to learn how to spot phishing e-mails and texts and phone calls, and better secure your environment? Do you have 1,000 employees—800 working on the shop floor, not reading e-mails, and 200 in the office—or do you have 50,000 employees, all of whom have BYO devices, WFH, and who talk to and e-mail customers all day? More than likely, you will have something in between. Do you work in a regulated environment that has specific annual training needs like the Fair Credit Reporting Act (FCRA) or Fair and Accurate Credit Transactions Act (FACTA)? Regulatory compliance will impact the kind of training you must provide.

3) As you can see from the prior question, your organization is unique, which means you will need customized training material to meet your needs. This doesn’t mean you can’t buy packaged training material for your organization. Just don’t settle for generic training because it may not cover everything you need.

Ensure your training is tailored to all levels of your organization. Offer executive-level cybersecurity awareness training to enhance what your organization leaders understand about the risks, challenges, and ways to minimize risk. Remember: you got the buy-in of your CEO, so leverage that with the whole company by demonstrating the CEO's commitment to cybersecurity. If the CEO says that cybersecurity awareness and training is important, and takes the training, and asks others about it, the message will be clear to everyone that cybersecurity is everyone’s job.

Clearly define the objectives of the training program with the specific outcomes everyone should achieve. Keep it simple initially, like improving the awareness of phishing, smishing, and vishing attacks. Or promote secure password practices and raising awareness of social engineering techniques. Once you have a strong foundation, build on that with additional cybersecurity concepts and topics.

Training comes in various shapes and sizes and people learn in different ways and that is why you want to plan on having different kinds of training as part of your A&T program. Here are some of the options available.

Computer-based training (CBT): CBT involves interactive, self-paced training modules that participants can complete on their computers. Good CBT training includes multimedia elements, quizzes, and assessments to reinforce learning. CBT allows participants to learn at their own pace and can be easily updated to reflect evolving cybersecurity threats. This kind of training is a commodity and is priced competitively.

Online or classroom lectures: Lectures involve an instructor delivering information to your users. Lectures can be useful for presenting foundational cybersecurity concepts, explaining complex topics, and sharing case studies or real-life examples. Engaging speakers and interactive elements like Q&A sessions can enhance the effectiveness of lectures. This kind of training is the most expensive and requires scheduling and coordination of your staff.

Workshops: Workshops are hands-on, collaborative sessions that provide participants with opportunities to practice cybersecurity skills, engage in group discussions, and solve practical challenges. Usually these are conducted after CBT or a lecture so that material learned can be incorporated on a deeper level. These can be expensive, depending on who conducts the workshop.

Hands-on simulations: Simulations provide participants with realistic scenarios to apply cybersecurity knowledge and skills. Simulations can involve interactive exercises like phishing simulations, network penetration testing, or security incident response simulations. As immersive experiences, they can enhance critical thinking, decision-making, and incident response capabilities. These kinds of simulations can be built into the CBT to make the material “stick” more with your employees and can be affordable when incorporated into a CBT program.

Gamification: I am a fan of gamification, mainly because I have seen it work successfully to engage students who then gain a better understanding of the material than through standard CBT. Gamification incorporates game elements into the training process to motivate students with opportunities to earn points or badges. These virtual or literal prizes can reinforce learning and track progress. Gamification can cost a little ($50 Amazon gift card every other month), or nothing at all (a virtual badge). Either way it helps make the training stick.

4) Regular communication and reinforcement will be important as you roll out your A&T program. Your employees have other things they have to do—like their jobs—and many do not consider good cybersecurity hygiene part of their job. This means you need to regularly communicate the value of learning how to spot phishing e-mails or smishing or vishing attempts.

I recommend monthly one-page security notices to keep cybersecurity in front of your employees. A regular (but not annoying) monthly communication regarding the risks and threats to them and the company is a good cadence. Remind them that the phishing e-mails they see at work will also likely be sent to them at home, “so be alert, learn how to spot the phishing e-mails and report them to security.”

If the monthly e-mail can come from the CEO or CFO, that is even better. Consistent top-level, executive engagement will really drive engagement and focus attention on this valuable asset in the battle against the various threat actors targeting your users.

5) Ongoing evaluation and improvement is the final piece to the puzzle. The CEO and CFO are not going to fund an A&T program unless there is proof that employees are aware and risk is reduced. Regularly assess the effectiveness of your A&T program with phishing simulations, social engineering tests, or other simulated attacks against your employees.

By gathering feedback from the target audience—your employees—you can identify knowledge gaps and catch and address emerging threats. Modify and enhance your A&T program based on employee feedback and let employees know you are listening to them. Check whether your gamification elements are working. You can turn your workforce into a band of first line guardians. Rather than being viewed as the weakest link, they can be your strongest line of defense.

John Bruggeman, CISSP, is a veteran technologist, CTO, and CISO with nearly 30 years of experience building and running enterprise IT and shepherding information security programs toward maturity. He helps companies, boards, and C-level committees improve and develop their cybersecurity programs, create risk registers, and implement compliance controls using industry-standard frameworks like CIS, NIST, and ISO. He is a consulting chief information security officer (CISO) for CBTS and OnX.

MORE FROM INNOVATION INSIGHTS

One Plate, One Platform: The Future of Smart Parking Management
Mobile Smart City Corp
Luis Garma, Founder and Chairman
AI as a Catalyst for Better Project Leadership
Think Big Technology
Omar Hafez, Founder
Connecting Data, Context, and Trust in the Age of Semantic AI
Zenia Graph
Aurelije Zovko, Co-founder and CTO, Zenia Graph, and Nina Mladenovski, Co-founder and COO

EXPLORE OUR KNOWLEDGE NETWORK



The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.