Employee Education and Training is a Key Component of a Culture of Security

Stu Sjouwerman | Dec 11, 2018
esrmpanel-580x358

Organizations need to focus on education and training rather than blaming employees for security gaffes, according to the speakers in a panel debate at Computing′s Enterprise Security and Risk Management Live event. John Leonard, who covered the event, says that all the speakers agreed that organizations need to increase cybersecurity provisions and awareness training to build a culture of security.

“Right from the time that you employ someone, you need to make clear ‘this is what we think your responsibility is towards the overall security of our company,’” said Dr. Louise Bennett, management committee member of the Information Assurance Advisory Council (IAAC). “You need people to understand what they are responsible for, what the IT department is responsible for, what the management team is responsible for, and what you're expecting your provider to be responsible for. You need absolute clarity on that.”

Andjela Djukavonic agrees that employees can benefit from knowing everyone’s responsibilities, because this lets them know who to turn to when they have a security concern. For instance, if someone is unsure of an email’s authenticity, it’s essential that they know who to ask about it. If it’s a phishing email, it could compromise the organization’s security. If the email is legitimate, ignoring it could disrupt business operations. “It's knowing who to talk to about it and where to send the email on to so it can be checked,” Djukavonic says.

Employees who have a good understanding of their coworkers’ roles are far less likely to be tricked by certain social engineering attacks. New-school security awareness training can educate employees on these different responsibilities and foster inter-department communication.

Computing UK has the full story, registration required : https://www.computing.co.uk/ctg/news/3066984/stop-blaming-the-user-for-cybersecurity-failings


Find out how affordable new-school security awareness training is for your organization. Get a quote now.

 
Get A Quote
Request A Demo
 

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.