{"id":41151,"date":"2022-07-27T05:17:00","date_gmt":"2022-07-27T05:17:00","guid":{"rendered":"https:\/\/cloudnewshub.com\/archives\/41151"},"modified":"2022-07-27T05:17:00","modified_gmt":"2022-07-27T05:17:00","slug":"cyber-security-training-boring-and-largely-ignored","status":"publish","type":"post","link":"https:\/\/cloudnewshub.com\/?p=41151","title":{"rendered":"Cyber security training \u2018boring\u2019 and largely ignored"},"content":{"rendered":"<div><img decoding=\"async\" src=\"http:\/\/cloudnewshub.com\/wp-content\/uploads\/2022\/07\/cyber-security-training-boring-and-largely-ignored.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>While cyber leaders overwhelmingly believe their organisations have a strong security culture, new figures compiled by email security specialist <a href=\"https:\/\/www.tessian.com\/\">Tessian<\/a> have revealed that they are deluding themselves, exposing an alarming disconnect between security pros and the rest of the business.<\/p>\n<p>With three-quarters of UK and US organisations having experienced some kind of cyber incident in the past year, a significant proportion of employees seem to regard training exercises as something to be endured, rather than engaged with.<\/p>\n<p>The report, <em><a href=\"https:\/\/1670277.fs1.hubspotusercontent-na1.net\/hubfs\/1670277\/%5BCollateral%5D%20Tessian-Research-Reports\/%5BTessian%20Research%5D%20How%20Security%20Cultures%20Impact%20Employee%20Behavior.pdf\">How security cultures impact employee behaviour<\/a><\/em>, found that while 85% of employees participate in security awareness or training programmes, 64% don\u2019t pay full attention and 36% consider their organisation\u2019s security training boring.<\/p>\n<p>Overall, the report found a general consensus among security leaders over what goes into making up a strong security culture, but with incident volumes remaining stubbornly high, Tessian said it was clear that those at the top had a lot more work to do.<\/p>\n<p>\u201cEveryone in an organisation needs to understand how their work helps keep their co-workers and company secure,\u201d said Kim Burton, head of trust and compliance at Tessian. \u201cTo get people better engaged with the security needs of the business, education should be specific and actionable to an individual\u2019s work.<\/p>\n<p>\u201cIt is the security team\u2019s responsibility to create a culture of empathy and care, and they should back up their education with tools and procedures that make secure practices easy to integrate into people\u2019s everyday workflows.<\/p>\n<p>\u201cSecure practices should be seen as part of productivity. When people can trust that security teams have their best interest at heart, they can create true partnerships that strengthen security culture.\u201d<\/p>\n<p>The report showed how training exercises \u2013 which in many firms comprise little more than \u201chome-brewed\u201d PowerPoint presentations cooked up by legal and compliance experts who have no real understanding of how people engage with educational materials \u2013 are failing to impact employees across the board.<\/p>\n<p>For example, 30% of respondents said they didn\u2019t think they had a personal role to play in keeping their company secure, while 45% did not know how to, or who to, report a security incident, and only one in three said they were satisfied with their IT or security team\u2019s communications.<\/p>\n<p>Meanwhile, over half of respondents said they saw nothing inherently risky in actions such as downloading apps to work devices, sending sensitive data to their own personal email accounts, sharing passwords internally, or connecting to open or public Wi-Fi networks on work devices.<\/p>\n<p>And even when it came to clearly risky actions, such as clicking on links in emails from unknown sources or opening unsolicited attachments, leaving work devices unlocked and unattended and reusing passwords, well over 40% of respondents said they didn\u2019t see a problem.<\/p>\n<section class=\"section main-article-chapter\" data-menu-title=\"Stop scaring people\">\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>Stop scaring people<\/h3>\n<p>A big source of disconnection seemed to be a tendency among leadership to use security training to spread fear and uncertainty as a motivator.<\/p>\n<p>For example, half of respondents to Tessian\u2019s study claimed to have had a <a href=\"https:\/\/www.computerweekly.com\/opinion\/Phishing-tests-are-a-useful-exercise-but-dont-overdo-it\">\u201cnegative experience\u201d with a phishing simulation<\/a>, as evidenced by the 2021 story of a phishing test at West Midlands Trains <a href=\"https:\/\/www.theguardian.com\/uk-news\/2021\/may\/10\/train-firms-worker-bonus-email-is-actually-cyber-security-test\">which went disastrously wrong<\/a>.<\/p>\n<p>The test appeared to be an email from company leadership detailing a thank-you bonus for employees who had worked through the pandemic, and many people clicked on the link, only to find themselves being ticked off for being insufficiently security-conscious. Union officials described the stunt as \u201ccrass and reprehensible\u201d.<\/p>\n<p>According to Karen Renaud, chancellor\u2019s fellow at the <a href=\"https:\/\/www.strath.ac.uk\/\">University of Strathclyde<\/a>, and Marc Dupuis, assistant professor at the <a href=\"https:\/\/www.uwb.edu\/\">University of Washington Bothell<\/a>, such tactics can \u201ccripple employee decision-making, creative thought processes, and the speed and agility that businesses need to operate in today\u2019s demanding world\u201d.<\/p>\n<p>Tessian said there were several things security leaders should be doing to engage employees better with cyber security procedures.<\/p>\n<p>For example, security leaders need to play more of an active role at key touchpoints during an employee\u2019s \u201cjourney\u201d with the organisation, such as onboarding, role or office changes, and offboarding. Tessian said onboarding new hires represents a great opportunity to capture people\u2019s imagination before they become cynical and jaded, while more thoughtful and comprehensive offboarding processes can help prevent critical data going missing when someone leaves.<\/p>\n<p>Another thing every security leader should be doing as a matter of course is to establish clear and regular lines of communication across the entire organisation, paying close attention to how much information they share, who it comes from, via what channels, and how frequently.<\/p>\n<p>Tessian offered four key pointers on how to do this effectively:<\/p>\n<ul class=\"default-list\">\n<li>Cut out jargon, technical terms and acronyms, and provide only \u201cneed-to-know\u201d information.<\/li>\n<li>Tailor communications to specific people, teams and departments. Someone in marketing, for example, will not have the same concerns or see the same threats as someone in HR.<\/li>\n<li>Identify one person to deliver updates and be a consistent point of contact for everyone.<\/li>\n<li>Develop a consistent format and cadence for security communications.<\/li>\n<\/ul>\n<p>Finally, it said, there are technological solutions which, sensibly deployed, can help establish cyber \u201cself-efficacy\u201d within the organisation.<\/p>\n<p>Tessian\u2019s report was compiled using data gathered by OnePoll, which surveyed 500 IT security leaders and 2,000 working professionals in the UK and the US.<\/p>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>While cyber leaders overwhelmingly believe their organisations have a strong security culture, new figures compiled by email security specialist Tessian have revealed that they are deluding themselves, exposing an alarming disconnect between security pros and the rest of the business. With three-quarters of UK and US organisations having experienced some kind of cyber incident in [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":41152,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[533],"tags":[],"class_list":["post-41151","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it"],"_links":{"self":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/41151","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=41151"}],"version-history":[{"count":0,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/41151\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/media\/41152"}],"wp:attachment":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=41151"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=41151"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=41151"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}