Information security awareness and training is one of the most effective ways to protect company data since so many security risks are caused by user error, misconfiguration and mismanagement. The primary goal of such programs is to minimize these issues by educating users on their responsibilities for ensuring the confidentiality, integrity and availability of information as it applies to their roles within the company. However, according to a Forrester report titled “Reconfigure Your Human Firewall,” only around one-third of employees receive security training, and less than half are aware of their organization’s security policies.

Developing a Strong Security Awareness and Training Program

An effective security awareness and training program begins with establishing clear and enforceable policies. Since policies are essentially the laws of the company and their role is to influence behavior, they should be:

  • Clear, concise, role-based and enforceable;
  • Developed at a high level, with input and consensus from senior management; and
  • Reflective of business requirements.

Procedures, standards and plans are linked to policies because they describe the steps required to achieve compliance with the policy. For security concerns such as acceptable use and remote access, companies should have one- or two-page policies that are easy to read and understand. Users should then be educated on these documents so that they understand how their responsibilities play a vital part in the overall security strategy.

Keep in mind that users tend to pay less attention to issues that don’t directly affect them. You should take time to educate users on the negative consequences their poor security practices and behaviors can have on the company and themselves. Ensure that security awareness and training is completed by all workforce members, including employees, contractors, consultants and part-time personnel. Initial and annual awareness training should be mandatory and followed up with ongoing education about new and emerging security issues.

Training programs should focus on issues such as:

  • Acceptable use of information assets;
  • Password protection;
  • How to handle sensitive information in both paper and electronic form;
  • Validating requests for information about the company, business partners or other stakeholders;
  • Legal and regulatory responsibilities and consequences;
  • Safe computing practices;
  • How to recognize a threat or security incident; and
  • Who to call in the event of a suspected or actual security incident.

The Power of Positive Reinforcement

Consider creating incentives for your team to act on security threats. One of the best methods for reinforcing security awareness is to reward users for positive behaviors. For example, one company implemented and enforced a policy that required users to log out of their computers by hitting CTRL-ALT-DELETE before they left their seats. Rather than pursuing and punishing the users that neglected to do this, management rewarded those who did, and word traveled fast. Eventually, this positive reinforcement influenced others to do the same.

Another company instituted a program in which they randomly called the help desk and tried to improperly reset a password. If the help desk representative followed procedure, management rewarded him or her on the spot. Ideally, rewards should be material and not merely pats on the back, since gold stars stopped working in grade school; cash, gift cards and discounts never lose their popularity. By rewarding positive behavior, you can influence and motivate more effectively.

Building a Culture of Security

When it comes to assessing user awareness of security violations, ask these three questions:

  • Would the user know if an action was right or wrong?
  • Would the user choose to report a violation?
  • Would the user know how to report a violation?

If users answer yes to all three questions, then you are on your way toward building a strong security culture. On the other hand, if you received a lot of no answers, it’s time to enhance your security awareness and training.

Companies should protect their users against threats such as viruses, phishing attacks and data breaches by implementing appropriate security controls in addition to intrusion detection systems, access management and a variety of other technology solutions.

Still, some of the biggest organizational challenges don’t originate from technology. They stem from the tone, attitude and practices of top management. If business leaders don’t consistently lead by example to promote a security culture or ensure clear, enforceable policies, effective awareness and training are difficult to establish. Executives who never wear a security badge or who share their passwords with assistants can’t expect others to do any better. Those who properly implement security awareness and training programs, however, can nudge their organizational culture in the right direction and reduce the risk of cyberattacks.

More from CISO

CEO, CIO or CFO: Who Should Your CISO Report To?

As we move deeper into a digitally dependent future, the growing concern of data breaches and other cyber threats has led to the rise of the Chief Information Security Officer (CISO). This position is essential in almost every company that relies on digital information. They are responsible for developing and implementing strategies to harden the organization's defenses against cyberattacks. However, while many organizations don't question the value of a CISO, there should be more debate over who this important role…

Everyone Wants to Build a Cyber Range: Should You?

In the last few years, IBM X-Force has seen an unprecedented increase in requests to build cyber ranges. By cyber ranges, we mean facilities or online spaces that enable team training and exercises of cyberattack responses. Companies understand the need to drill their plans based on real-world conditions and using real tools, attacks and procedures. What’s driving this increased demand? The increase in remote and hybrid work models emerging from the COVID-19 pandemic has elevated the priority to collaborate and…

Why Quantum Computing Capabilities Are Creating Security Vulnerabilities Today

Quantum computing capabilities are already impacting your organization. While data encryption and operational disruption have long troubled Chief Information Security Officers (CISOs), the threat posed by emerging quantum computing capabilities is far more profound and immediate. Indeed, quantum computing poses an existential risk to the classical encryption protocols that enable virtually all digital transactions. Over the next several years, widespread data encryption mechanisms, such as public-key cryptography (PKC), could become vulnerable. Any classically encrypted communication could be wiretapped and is…

6 Roles That Can Easily Transition to a Cybersecurity Team

With the shortage of qualified tech professionals in the cybersecurity industry and increasing demand for trained experts, it can take time to find the right candidate with the necessary skill set. However, while searching for specific technical skill sets, many professionals in other industries may be an excellent fit for transitioning into a cybersecurity team. In fact, considering their unique, specialized skill sets, some roles are a better match than what is traditionally expected of a cybersecurity professional. This article…