It’s Cybersecurity Awareness Month. Does your business have a viable plan yet?
The cybersecurity world is evolving rapidly — perhaps more quickly than at any other time in its history. It would be easy to attribute the cyber hiccups that many businesses face to the fact that they are simply unable to keep up with bad actors.
The facts are more complicated. While it’s true that new threats are emerging every day, more often than not, breaches result from long-standing organizational issues, not a sudden upturn in the ingenuity of cybercriminals.For example, phishing has been around since the mid-’90s. Furthermore, its tactics and strategies are largely unchanged over the last 25 years — save for slightly improved graphics and copyediting. Yet, 75% of organizations experienced a phishing attack in 2020 — and 74% of attacks targeting US companies were successful.
Human error is a significant contributing factor in over 90% of cyber breaches, but too many organizations aren’t using training and awareness content designed for most humans. Humans have short attention spans, are easily bored, like to laugh (cat videos, anyone?), and like things to be easy. And honestly, once you really get into it, cybersecurity is fascinating, so there’s no excuse to be boring.
Here are a few areas that undermine business’s ability to build the strong security training and awareness programs needed for today’s threat environment.
Missing on messaging
Day-to-day backend cybersecurity execution may be technical, but getting people to buy into cybersecurity best practices is not. In a world where most marketing content strategy and activation tactics have become more sophisticated and creative, the same cannot be said for cybersecurity. There are an astounding number of cybersecurity “engagement” strategies today that look like technical manuals. They may work within IT departments where efficient guidance is paramount. But unfortunately, they don’t work well outside the IT sector. Simply saying, “do this, because I said so” is not the way to get everyday people to act. Instead, we need customized strategies to drive engagement much as a sales funnel operates — nurturing employees along the way to conversion. Successful campaigns like this do not exist at many organizations, which is largely why cybersecurity engagement remains a challenge.
Internal politics and disorganization
The way to build cybersecurity defenses is through cohesive and collaborative messaging and tactics. Of course, it can be frustrating when employees fall for phishing emails, but Security departments should provide information on repeat clickers to HR and work on an escalation plan that ultimately HR and the business will own. This will foster mutual respect and lay the groundwork for collaborative progress toward a more secure workplace.
Drab training and awareness curriculum
There is a common misperception in regards to cyber education and awareness training: training materials and sessions are boring, uneventful and easily forgettable. The truth is, cyber education and awareness training is only as drab and forgettable as you make it.
The cybersecurity education and awareness category is light years ahead of where it was even a couple of years ago. With new engagement methods ranging from scavenger hunts and games to live action content, there is no shortage of tools and assets available to businesses looking to bring their preparedness training to the next-level.
Unfortunately, businesses continue to struggle to integrate many of these “new age” tools into their cyber education protocols. Delivering effective cybersecurity awareness education and training is an end-to-end proposition. So while delivering compelling content is a great first step, to truly maximize content strategies they need to be paired with engaging training tools. If not, businesses are depriving employees of the valuable experience that they need on a day-to-day basis.
Post a Comment