Your Employee's Cyber Awareness Is Critical

As part of the Coronavirus lockdown, non-essential businesses were forced to close their physical premises and move to ways of remote working to continue functioning and because of the less cyber secure home-working in 2020, organisations saw an increase in both ransomware and phishing attacks. On top of all the current cyber security issues with the virus, phishing scams have significantly increased.

Cyber criminals wasted no time in exploiting this opportunity, casting thousands of COVID-related lures onto perhaps more vulnerable than usual users.

According to thier 2021 State of the Phish Report  from Proofpoint, the majority (92%) of UK organisations required or  requested that most employees work from home due to the pandemic, which presented its fair share of teething problems, some of which organisations are still experiencing to this day. Organisational preparedness for remote working is not great and employees were not well-equipped to work remotely. In response, many organisations increased security awareness training and many organisations offered training on how to stay safe while working remotely.

While implementation of additional training is certainly good news, it should not take a global health crisis for organisations to prioritize security awareness.

To be effective, cybersecurity training must take place regularly, continually adapting to address the threats of the moment. It must be a central part of an organization’s security program, all year round. In the first half of 2020 cyber criminals took advantage of the heightened interest surrounding the pandemic, resulting in a flood to phishing email  unlike anything Proofpoint researchers research team has ever seen. While the tactics changed throughout the year, the target remained the same. Some offered cures, others promised speedy tests and priority access to vaccines. Many encouraged victims to hand over valuable credentials.

An appetite for the latest COVID-19 developments was just one factor fueling the phishing fire. Cyber criminals also struck at a time of significant disruption and distraction. 

Many organisations, recognising the elevated risk, conducted COVID-specific security awareness training. Results were good in test conditions too. Average failure rates for the most frequently used COVID-related lures ranged from less than 1% to around 20%. However, awareness is not quite enough. Security best practice behavior only really changes when employees are embedded in the program. For example, an employee receiving a notification to confirm that the potential phishing email they reported was in fact malicious, helps to drive and incentivise a security-first culture, however, this level of training is rare.

Only 64% of organisations conduct formal training sessions, either virtually or in person. For almost two-thirds, training of any sort takes place no more than four times a year. And 36% only train users in certain roles or departments.

Failure to equip employees with the knowledge to detect and deter such attacks is negligent and the response to COVID-related phishing attacks has shown that relevant, targeted, and in-context security awareness training works. Rather than reverting to type once the pandemic subsides, organisations must use this experience to implement long-term training programs that actively seek to change risky behaviors. Programs that focus on the individual and adapt to current, real-world threats.

This is only possible by placing users at the heart of your defence. They are often the only thing standing between the success and failure of an attack. The level of training they receive needs to reflect these high stakes.

Security awareness training must go beyond jargon, definitions of common threats, and multiple-choice tests. It must leave users in no doubt about their responsibilities and the consequences of failing to uphold them. When you deliver this comprehensive, people-centric training regularly, you create a security culture. A culture in which your people understand how simple behaviors can put your organisation at risk. In which all users know how to prevent, detect and deter cyber-attacks and in which best practice becomes standard practice.

The executive business decision-makers are important stakeholders in your organisation, but for security awareness training, users are the most important stakeholders. 

User engagement is critical if you want to make security a core part of your organisation’s culture, making sure that your workforce is aware of the basic cyber security behaviors is also critically important in this new environment. Organisations must have a culture of data security and data privacy and employees need to understand that they are the caretakers of their own organisation’s valuable and often sensitive data, much of which also consists of customer information.

Business need cyber security training and we at Cyber Security Intelligence recommend GoCyber training for all employees and management – it is excellent – please contact us for a free trial.

Proofpoint:   NCSC:   Infosecurity Magazine:   NCSC:       Infosecurity Magazine:     Action Fraud:    Image: Unsplash

You Might Also Read: 

How Has A Year Of Pandemic Changed Cyber Security?:

 

« The European Union Adopts A Cyber Security Strategy
The Satanic Mills of the Fourth Industrial Revolution »

ManageEngine
CyberSecurity Jobsite
Check Point

Directory of Suppliers

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

Directory of Cyber Security Suppliers

Directory of Cyber Security Suppliers

Our Supplier Directory lists 8,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

Perforce Software

Perforce Software

Perforce helps companies build complex software products more collaboratively, securely, and efficiently.

UZCERT

UZCERT

UZCERT is the national Computer Emergency Response Team for Uzbekistan.

Elemendar

Elemendar

Elemendar Artificial Intelligence reads cyber threat reports written by humans and translates them into industry-standard, machine-readable and machine-actionable data.

US Cyber Range

US Cyber Range

US Cyber Range is a scalable, cloud-hosted infrastructure providing students with virtual environments for realistic, hands-on cybersecurity labs and exercises.

Portshift

Portshift

Portshift leverages the power of Kubernetes and Service-Mesh to deliver a single source of truth for containers and cloud-native applications security.

In Fidem

In Fidem

In Fidem specializes in information security management, with a bold approach that views cybersecurity as a springboard to organizational transformation rather than a barrier to innovation.

iON United

iON United

iON United is a full-service IT security solutions provider and one of the most trusted names in cybersecurity in Canada.

FortKnoxster

FortKnoxster

FortKnoxster is a cybersecurity company within the Crypto & FinTech space. Our encryption technologies are blockchain integrated.

Cisco Networking Academy

Cisco Networking Academy

Cisco Networking Academy is the world's largest classroom, bringing technology education, 21st-century skills, and improved jobs prospects since 1997.

PreVeil

PreVeil

We started PreVeil to bring radically better security to ordinary business and personal communication and information storage.

GTT Communications

GTT Communications

GTT are a global network provider that serves thousands of multinational and national enterprise, government and carrier customers with a portfolio of advanced connectivity and security services.

QuantumCTek

QuantumCTek

QuantumCTek is a Chinese pioneer and leader in commercialized quantum information technology (QIT).

Trackd

Trackd

At trackd, we’re re-imaging vulnerability remediation for the benefit of the entire cyber security community. Automating Vulnerability Remediation without the Fear of Disruption.

Vigilant Ops

Vigilant Ops

Vigilant Ops is a leader in Software Bill of Materials (SBOM) Automation. A proactive approach to cybersecurity with continuous vulnerability monitoring.

SUCCESS Computer Consulting

SUCCESS Computer Consulting

SUCCESS Computer Consulting is a leader in managed IT and security services for small and medium-sized businesses in Minneapolis, St. Paul, and the surrounding Twin Cities Metro area.

Synechron

Synechron

Synechron is a leading global digital consulting firm, providing innovative technology solutions for business.