Business Daily Media

Men's Weekly

.

4 Tips for Getting Started with Cyber Awareness and Security Training

  • Written by Tyler Moffitt, Senior Security Analyst, Webroot + Carbonite

The pandemic transformed workplaces overnight: remote working conditions accelerated years into the future as entire companies learned new ways of collaborating, communicating and doing business. Unfortunately, not all impacts have been positive. There’s been an intense uplift in cyber-attacks, with Australia’s scamwatch reporting an increase of over 50,000 last year when compared with 2019. The value of the total attacks in 2020 was over $32 million more than 2019 observed, with businesses being the chief victim targeted by scams.

Blame it on increased phishing, already overstretched IT budgets or an increased use of home networks and technology by WFH employees. However, most of these classic issues we tend to ‘blame’ stem from a lack of awareness and cyber education. When these elements are properly engrained in an organization’s processes and culture, the number of risks to the business decreases.

Given that IT staff, especially those at SMBs and MSPs, are tasked with a lot of responsibilities, yet often lack proper resources and time, it can be difficult to get a cybersecurity training and awareness program up and running and maintained. Outlined below are four recommendations IT teams should take when starting a security awareness training or education initiative.

  1. Obtain Buy-in from Stakeholders

It’s a given that business stakeholders acknowledge the importance of security tools – after all, news headlines are only getting scarier and more novel as they reflect the latest breaches and hacks. But being removed from the day-to-day IT and cybersecurity management, these stakeholders often appreciate a critical eye looking at whether the business has the right tools or is using them in the right way. What they need is to clearly understand the threats that are present and popular, the risks that ill-informed personnel may be exposed to and the risks that those personnel can introduce to the business.

Obtaining stakeholder buy-in at the start of a security awareness training initiative is also important as business leaders should play an active, consistent role in promoting the importance of security awareness and compliance across the business and to all employees.

  1. Begin with a Baseline Phishing Campaign

Test employees with a phishing campaign, without warning or context, to establish a baseline understanding of how they understand and identify phishing threats. The baseline phishing test will help businesses see clearly which employees need extra education or guidance and also enables businesses to track progress with each additional phishing test. Our data indicates that the average click-through rate for a phishing simulation campaign is 11 percent – meaning that percentage of employees clicked on what would have been a real phishing link in the test scenario. That drops to eight percent in the second campaign, but by the eleventh in a calendar year it’s down to five percent.

  1. Require Compliance and Security Training

Establish a framework of training campaigns that highlights common and timely cybersecurity topics including phishing, malware, social engineering, strong password policies and more. Negotiate with stakeholders which employees or departments will need customized courses to best tailor the program where possible, or to identify training that needs to be required by all employees because of the business’ industry. For example, employees of a healthcare provider must understand HIPPA compliance protocol, for instance, and be able to identify an email spoofing a large insurance provider.

Real-world training should also mirror real-world events, such as news related to COVID-19, because cyber criminals adapt phishing tactics quickly to take advantage of news headlines and public interest.

  1. Test Regularly

While a baseline test is a good start to get a feel for the cyber preparedness of the office, measuring if the learning has resonated with users is key to fostering cyber resilience and truly seeing ROI. For workforces, repetition and reiterating key messages of the security training will be crucial. Holding regular simulations, with ‘chunked’ learning modules of 4-5 minutes will reinforce education without accompanying fatigue.

For businesses that are unable to run monthly tests, adjust to a quarterly cadence or the needs of your training program. Whatever the testing cycle, ensure you re-test only those who failed each test so that training doesn’t become a nuisance to those who passed.

As WFH setups seem to be ending in the near future, having a cyber aware and cyber resilient workforce is a must to prevent the threats of tomorrow, today. Educating workforces is a long-term commitment and expecting overnight change from remote workforces is unreasonable. But in building an effective security awareness program that involves all employees, IT and important stakeholders, workplaces can create cyber resilience through an informed and equipped audience to help drastically reduce cyber risks to the business.


Tyler Moffitt, Sr. Security Analyst, Webroot

From Check-in to Touchdown: How AI and smarter systems are transforming the travel industry

Richard Valente, VP of Customer Experience Strategy at TP in Australia, explores how IT-BPM outsourcing is revolutionising the travel sector throu...

Online Christmas shoppers fund climate and biodiversity projects via HealthPost's Click Sphere for Good initiative

Online shoppers with HealthPost’s Flora & Fauna have made 11,000 contributions towards climate and biodiversity projects when ordering parcel ...

US landmark settlement protects SMEs, highlighting flaws in the RBA's proposed blanket card surcharging ban for Australia

Aussie SMEs warn RBA not to ignore global trends, with the current sledgehammer approach threatening business viability and increasing inflation ...

Thryv Australia named Employer of Choice for third consecutive year at Australian Business Awards

Thryv® (NASDAQ: THRY), Australia’s provider of the leading small business marketing and sales software platform, has been awarded the Employer of ...

RogersDigital.com Announces the Launch of TheBulletin.au, a Destination for Business, Policy and Financial Insight

RogersDigital.com has announced the launch of TheBulletin.au, a new national digital publication designed to deliver sharp, data-driven reporting ...

Controlling business spend is helping finance leaders to forecast with confidence

Forecasting has always been central to financial planning; however, traditional methods based on historical trends are no longer enough. Economic ...

hacklink hack forum hacklink film izle hacklink หวยออนไลน์betsmovejojobethttps://vozolturkiyedistributoru.com/Pusulabet Girişสล็อตเว็บตรงgamdom girişpadişahbetMostbetpradabetkavbetcarros usadospin upMostbetdizipalholiganbet girişnn888trendbetultrabetjojobetDeneme Bonusu Veren Sitelerpusulabet girişbetnanotürk ifşaBets10jojobetjojobetjojobetholiganbet色情casibomnakitbahisholiganbetjojobetjojobetjojobet güncel girişholiganbet girişyakabet1xbet girişjojobetgrandpashabet girişzbahis güncel girişbetofficeenjoybetpradabetmeritkingholiganbetgiftcardmall/mygiftcasibomholiganbetbets10maksibetmamibetmeritkingcasibom girişmadridbetsekabetslot spacemancasibomcasino sitelericasibomJojobetkingroyalmeritkingPorno İzlecasibom girişkolaybettrgoalsbetoviscasibomcasibom girişmasterbettingmasterbettingyakabetartemisbetbetpuanmeritkingartemisbet girişdinamobetprizmabetvdcasinoSekabet girişmarsbahisbetkolikultrabetprimebahismeritkingprimebahistrgoalsgalabetyakabetyakabetyakabetjojobetbetnanobetpuanSahabetmr pachoaertyerCasibomcolor pickerkonya escortvbetultrabet girişholiganbet girişholiganbet girişmavibetmavibetmavibetholiganbetcratosslot girişคลิปหลุดไทยCasibomCasibomholiganbetdeneme bonusu veren siteleronwinonwindiyarbakır escortimajbetantalya escortjojobet girişbahsegeltimebetjojobetjojobetholiganbetbahiscasinojojobetbets10matbetcasibomRoyal Reelsroyal reelskolaybetKayseri Escortjojobet girişjojobetbetasus girişNişantaşı EscortbetvolebetvolebettiltStreameastcasibomKalebetpadişahbetfixbetaviator gameÜsküdar Evden Eve Nakliyatsetrabettimebettimebettimebetbahisoistanbul escort telegramcasibombetparkpantheraproject.netcasibombetsmoveholiganbet girişcasibombetnanocasibomstreameast한국야동meritkingสล็อตholiganbet girişholiganbetpornopadişahbetBetigmabetparkBetigmaBetlora girişgiftcardmall/mygiftgaziantep escorteb7png pokiesbest online casino australiabest online pokies australiareal money pokies online australiabcgame96 casinocrown155 hk casinohb88kh casinopadişahbetjojobetmarsbahisgalabetjojobet girişjojobetcasibombets10bets10betasusjojobetolimposcasinobetbabaholiganbetholiganbetolabahis girişholiganbetdeneme bonusu veren siteler rehneriblooketasyabahis girişpinbahis girişdumanbet girişxslotStreameastmostbetdaftar situs judi slot gacor hb88 indonesiaJojobet 1113mostbetmostbetmostbetgalabetkingroyalbahis siteleri 2025matadorbetcasinowon girişjojobetjojobetgiftcardmall/mygift check balance visamarsbahisjojobetซื้อหวยออนไลน์grandpashabetcasibomcasibomasdsadasdasdasdasfdasfasfsadfasdfsdfasdasdasdasdmadridbet girişjojobetroyalbetbetasus girişpin up uzbekistanSlot Heart Casinomamibet logincasinomedklarna.sebetworld96 online casino cambodiaholiganbetwww.giftcardmall.com/mygiftwww.giftcardmall.com/mygiftCasibom Giriştm menards loginbetasusmaksibetsekabet girişe wallet casino australiajojobetplay aristocrat pokies onlinesweet bonanzajojobetmaltcasino girişcanlı maç izleklasbahisSahabetcasibomcasibomcratosroyalbetci girişjojobet girişcasibomcasibomdeneme bonusu veren sitelerPinup AZjokerbetjojobetrokubetmostbetcasibomsitus slot gacormatbetJojobetmigliori casino non aamscasibomasyabahis girişperabet girişjojobetCasibomdizipalrealbahisrealbahisperabetperabetbetwoon