Cybersecurity Awareness Month in October is a great time to remind employees that cybersecurity is everyone’s responsibility. It is also a great time to remind security teams that nobody wants to sit through a 47-slide presentation about password complexity.
Security awareness is important, but there is a big difference between educating people and simply checking a compliance box. The goal should not be to turn every employee into a cybersecurity expert, but to give them enough knowledge to recognize when something does not look right, slow down before making a potentially risky decision and know what to do when they suspect something is wrong. That does take a bit more than an annual training course, but it does not have to be a negative experience for everyone involved.
Here are seven key concepts to keep in mind when working to instill a culture of security awareness in your organization.
People tend to pay attention when something applies to them, so when we teach employees about phishing, we should probably be showing them the types of attacks they are likely to actually encounter. Fake Microsoft 365 notifications, payroll changes, QR-code phishing, bogus DocuSign requests, help-desk impersonation, MFA fatigue attacks or a frantic message supposedly from an executive asking for something unusual are all good examples.
It is also important to remember that not everyone in an organization faces the same threats. Someone working in finance is going to be targeted differently than someone in HR, development, IT or the executive team. Because cybercriminals understand this very well, our training should too.
Most people are not going to remember the textbook definition of social engineering a week after they learn it, but they may remember the story about an employee who received a convincing call from “IT,” approved an MFA request and accidentally gave an attacker access to the network.
Stories put cybersecurity concepts into context, so instead of simply telling employees to verify unusual requests through another communication channel, explain why that matters, at a high level and show them what can happen when someone does not verify the request. People tend to remember lessons much better when they understand why the lesson exists in the first place.
The annual hour-long security awareness training marathon is not exactly something most employees look forward to. The problem is that threats change constantly and expecting someone to remember something they saw 11 months ago when a convincing phishing email suddenly appears in their inbox is asking a lot, especially if they do not understand how it benefits them personally.
Shorter, more frequent education can help and a two or three-minute lesson about a current phishing technique may be much more useful than an hour of generalized cybersecurity content once a year. Think drip campaign, not fire hose and you are likely to get a lot more engagement.
Phishing simulations can be extremely valuable when they are used correctly. But there’s a fine line between trying to trick employees and potentially making them enemies and letting them practice what they have learned. If your phishing simulation requires someone to inspect message headers, decode a URL, identify a tiny font difference at 400% zoom and possibly consult the phases of the moon, that may be going a bit too far.
Yes, it is true that cybercriminals can do that too, however, the goal of a phishing simulation should be to give people a chance to practice what they have learned, see whether employees recognize realistic warning signs and, just as importantly, whether they know what to do when they see them.
One of the most valuable things an employee can do is not necessarily “never click anything.” It is recognizing that something may be wrong and reporting it quickly. This means giving employees an obvious phishing-report button or another simple way to notify the security team. Just as importantly, make sure somebody is paying attention to those reports.
Employee reports can be valuable threat intelligence. If several people report the same phishing campaign quickly, the security team may be able to find and remove similar messages before more employees interact with them. On the other hand, if reporting something suspicious requires opening a helpdesk ticket, choosing from 37 categories, attaching the original email and sacrificing a printer toner cartridge to the help-desk, people are probably going to stop reporting things. People will not engage in a high-friction, optional process, period. Would you? So, make the secure action the easy action.
Security teams sometimes spend an enormous amount of time tracking who clicked on a simulated phishing email, then they spend very little time recognizing the people who correctly reported it. That just seems backward. If someone reports a suspicious message, questions an unusual financial request or catches something that could become a security incident, recognize it.
The goal is to build a security culture, not a wall of shame, so people should feel comfortable raising their hand when something looks wrong, even if they already clicked on it, well, especially if they already clicked on it. Shame will not get you there and the sooner the security team knows about a potential problem, the sooner they can respond.
Phishing click rates can be useful, but they do not tell the entire story. Organizations should also keep track of:
Consider two employees who click the same simulated phishing email, one immediately realizes something is wrong and reports it 15 seconds later. The other enters credentials and never tells anyone. Technically, both employees clicked, but from a risk perspective, however, those are two very different situations and context matters.
Also consider that a large part of a click rate is measuring the person doing nothing. On the other hand, an employee that quickly reports a phishing email or even a simulated attack, has taken the time and put forth the effort to do that. That can be an important indicator of how your security culture is developing.
People are frequently described as the “weakest link” in cybersecurity, but I have never been a big fan of that description. Yes, employees are certainly targeted heavily by cybercriminals, especially through phishing and social engineering, but that means we need to give them the tools and knowledge they need to defend themselves. That is on us to do.
A well-trained employee can spot a strange request, question an unusual login, report a suspicious email or notice something that slipped past technical security controls. That is what makes people another critical layer in the organization’s defense.
Security awareness should not be about turning everyone into cybersecurity professionals. It should give people enough knowledge to recognize when something feels wrong, slow down before taking a risky action and know where to go for help. We should teach employees that it is okay to question unusual requests, it is okay to verify something before sending money or sensitive information and it is absolutely okay to report something suspicious, even if they are not sure it is malicious. That is the behavior we want.
If Cybersecurity Awareness Month helps reinforce those habits and makes employees a stronger part of the organization’s defenses, then we have accomplished something useful. If all it does is remind everyone that their mandatory annual cybersecurity training is due Friday at 5:00 PM, we may want to rethink the strategy.