Security Awareness Training
- •
def
- •
training that gives users the security knowledge needed before they're granted access, tailored to each role's specific responsibilities (including third parties like contractors and suppliers)
- •
- •
topics
- •
phishing recognition — spelling/grammar errors, domain/email inconsistencies, unusual attachments, requests for personal information; reporting suspicious messages promptly
- •
anomalous behavior recognition — risky behavior (modifying hosts files, replacing core OS files), unexpected behavior (logon from another country, spikes in data transfer), unintentional behavior (typos in domain names, misplaced USB drives, misconfigured settings)
- •
password management, removable media/cable hygiene, social engineering awareness, operational security (viewing security from an attacker's perspective), and hybrid/remote work risks
- •
- •
phishing campaigns
- •
many organizations run their own simulated phishing campaigns against employees, using an automated process for centralized reporting and immediate feedback/training on incorrect clicks
- •
- •
development and execution
- •
a dedicated Security Awareness team creates training materials, sets a minimum awareness level, integrates compliance mandates (PCI DSS, HIPAA, GDPR, etc.), defines success metrics, and tracks ongoing training via automated reporting
- •
- •
reporting and monitoring
- •
tracks metrics like phishing click rates, password manager adoption, and MFA use; recurring monitoring helps identify high-frequency issues and repeat offenders needing more training
- •
- •