September 11, 2017 By Brian Evans 3 min read

Information security awareness and training is one of the most effective ways to protect company data since so many security risks are caused by user error, misconfiguration and mismanagement. The primary goal of such programs is to minimize these issues by educating users on their responsibilities for ensuring the confidentiality, integrity and availability of information as it applies to their roles within the company. However, according to a Forrester report titled “Reconfigure Your Human Firewall,” only around one-third of employees receive security training, and less than half are aware of their organization’s security policies.

Developing a Strong Security Awareness and Training Program

An effective security awareness and training program begins with establishing clear and enforceable policies. Since policies are essentially the laws of the company and their role is to influence behavior, they should be:

  • Clear, concise, role-based and enforceable;
  • Developed at a high level, with input and consensus from senior management; and
  • Reflective of business requirements.

Procedures, standards and plans are linked to policies because they describe the steps required to achieve compliance with the policy. For security concerns such as acceptable use and remote access, companies should have one- or two-page policies that are easy to read and understand. Users should then be educated on these documents so that they understand how their responsibilities play a vital part in the overall security strategy.

Keep in mind that users tend to pay less attention to issues that don’t directly affect them. You should take time to educate users on the negative consequences their poor security practices and behaviors can have on the company and themselves. Ensure that security awareness and training is completed by all workforce members, including employees, contractors, consultants and part-time personnel. Initial and annual awareness training should be mandatory and followed up with ongoing education about new and emerging security issues.

Training programs should focus on issues such as:

  • Acceptable use of information assets;
  • Password protection;
  • How to handle sensitive information in both paper and electronic form;
  • Validating requests for information about the company, business partners or other stakeholders;
  • Legal and regulatory responsibilities and consequences;
  • Safe computing practices;
  • How to recognize a threat or security incident; and
  • Who to call in the event of a suspected or actual security incident.

The Power of Positive Reinforcement

Consider creating incentives for your team to act on security threats. One of the best methods for reinforcing security awareness is to reward users for positive behaviors. For example, one company implemented and enforced a policy that required users to log out of their computers by hitting CTRL-ALT-DELETE before they left their seats. Rather than pursuing and punishing the users that neglected to do this, management rewarded those who did, and word traveled fast. Eventually, this positive reinforcement influenced others to do the same.

Another company instituted a program in which they randomly called the help desk and tried to improperly reset a password. If the help desk representative followed procedure, management rewarded him or her on the spot. Ideally, rewards should be material and not merely pats on the back, since gold stars stopped working in grade school; cash, gift cards and discounts never lose their popularity. By rewarding positive behavior, you can influence and motivate more effectively.

Building a Culture of Security

When it comes to assessing user awareness of security violations, ask these three questions:

  • Would the user know if an action was right or wrong?
  • Would the user choose to report a violation?
  • Would the user know how to report a violation?

If users answer yes to all three questions, then you are on your way toward building a strong security culture. On the other hand, if you received a lot of no answers, it’s time to enhance your security awareness and training.

Companies should protect their users against threats such as viruses, phishing attacks and data breaches by implementing appropriate security controls in addition to intrusion detection systems, access management and a variety of other technology solutions.

Still, some of the biggest organizational challenges don’t originate from technology. They stem from the tone, attitude and practices of top management. If business leaders don’t consistently lead by example to promote a security culture or ensure clear, enforceable policies, effective awareness and training are difficult to establish. Executives who never wear a security badge or who share their passwords with assistants can’t expect others to do any better. Those who properly implement security awareness and training programs, however, can nudge their organizational culture in the right direction and reduce the risk of cyberattacks.

More from Risk Management

83% of organizations reported insider attacks in 2024

4 min read - According to Cybersecurity Insiders' recent 2024 Insider Threat Report, 83% of organizations reported at least one insider attack in the last year. Even more surprising than this statistic is that organizations that experienced 11-20 insider attacks saw an increase of five times the amount of attacks they did in 2023 — moving from just 4% to 21% in the last 12 months.With insider threats on the rise, it’s critical for businesses to recognize the real dangers that originate from inside…

What does resilience in the cyber world look like in 2025 and beyond?

6 min read -  Back in 2021, we ran a series called “A Journey in Organizational Resilience.” These issues of this series remain applicable today and, in many cases, are more important than ever, given the rapid changes of the last few years. But the term "resilience" can be difficult to define, and when we define it, we may limit its scope, missing the big picture.In the age of generative artificial intelligence (gen AI), the prevalence of breach data from infostealers and the near-constant…

Airplane cybersecurity: Past, present, future

4 min read - With most aviation processes now digitized, airlines and the aviation industry as a whole must prioritize cybersecurity. If a cyber criminal launches an attack that affects a system involved in aviation — either an airline’s system or a third-party vendor — the entire process, from safety to passenger comfort, may be impacted.To improve security in the aviation industry, the FAA recently proposed new rules to tighten cybersecurity on airplanes. These rules would “protect the equipment, systems and networks of transport…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today