You’ve completed your annual phishing training. This includes teaching employees how to spot phishing emails. You’re feeling good about it. That is until about 5-6 months later. Your company suffers a costly cyber attack and ransomware infection due to a click on a phishing link.
You wonder why you seem to need to train people on the same information every year, and your still suffering from security incidents and cyber threats. The problem is that you’re not training your employees often enough.
People can’t change behaviours if training isn’t reinforced. They can also easily forget what they’ve learned after several months go by.
So, how often is often enough to improve your team’s cyber security awareness? It turns out that training every four months is the “sweet spot.” This is when you see more consistent results in your IT security and less breaches of sensitive information.
Why Is Cyber Security Awareness Training Each 4-Months Recommended?
So, where does this four-month recommendation come from? There was a study presented at the USENIX SOUPS security conference recently. It looked at users’ ability to detect phishing emails versus training frequency. It looked at training on phishing awareness and IT security.
Employees took phishing identification tests at several different time increments:
The study found that four months after their training, scores were good. Employees were still able to accurately identify and avoid clicking on phishing emails. But after 6-months, their scores started to get worse. Scores continued to decline the more months that passed after their initial training.
To keep employees well prepared, they need training and refreshers on security awareness. This will help them to act as a positive agent in your cyber security strategy.
Tips on What & How to Train Employees to Develop a Cyber Secure Culture
The gold standard for security awareness training is to develop a cyber secure culture. This is one where everyone is cognizant of the need to protect sensitive data and computer systems. As well as avoid phishing scams, and keep passwords secured.
This is not the case in most organisations, according to the 2021 Sophos Threat Report. One of the biggest threats to network security is a lack of good security practices.
The report states the following,
“A lack of attention to one or more aspects of basic security hygiene has been found to be at the root cause of many of the most damaging attacks we've investigated.”
Well-trained employees significantly reduce a company’s risk. They reduce the chance of falling victim to any number of different online attacks. To be well-trained doesn’t mean you have to conduct a long day of cyber security training. It’s better to mix up the delivery methods.
Here are some examples of engaging ways to train employees on cyber security and cyber attacks. You can include these in your training plan:
Self-service videos that get emailed once per month
Team-based roundtable discussions
Security “Tip of the Week” in company newsletters or messaging channels
Training session given by an IT professional
Simulated phishing tests
Cyber security posters
Celebrate Cyber Security Awareness Month in October
When conducting training, phishing is a big topic to cover, but it’s not the only one. Here are some important topics that you want to include in your mix of awareness training.
Phishing by Email, Text & Social Media
Email phishing is still the most prevalent form. But SMS phishing (“smishing”) and phishing over social media are both growing. Employees must know what these look like, so they can avoid falling for these sinister scams and social engineering.
Credential & Password Security
Many businesses have moved most of their data and processes to cloud-based platforms. This has led to a steep increase in credential theft because it’s the easiest way to breach SaaS cloud tools.
Credential theft is now the #1 cause of data breaches globally. This makes it a topic that is critical to address with your team. Discuss the need to keep passwords secure and the use of strong passwords. Also, help them learn tools like a business password manager.
Data privacy regulations are something else that has been rising over the years. Most companies have more than one data privacy regulation requiring compliance.
Train employees on proper data handling and security procedures. This reduces the risk you'll fall victim to a data leak or breach that can end up in a costly compliance penalty.
Need Help Keeping Your Team Trained on Cyber security?
Take training off your plate and train your team with cyber security professionals. We can help you with an engaging training program. One that helps your team change their behaviours to improve cyber hygiene. For more information on cyber security training, simply call 0330 088 2565 or email firstname.lastname@example.org.
- by Lizzie Clark
- on August 1, 2022