<p>Ineffective programs abound, however, with dull, outdated content that fails to engage users — and often misses the mark. This leaves organizations open to unnecessary — and potentially catastrophic — security risks.</p>
<p>CISOs and C-level executives can no longer treat cybersecurity awareness as a recurring training requirement to check a compliance box. An effective cybersecurity awareness program should be treated as a human risk management capability that focuses on the human behaviors that create the greatest cybersecurity risks.</p>
<p>The problem with traditional programs isn't insufficient employee knowledge; it's unmanaged human-related cyber-risk. Employees interact with email, SaaS applications, data, vendors and <a href="https://www.techtarget.com/cybersecurity/tip/What-are-the-most-common-authentication-methods">authentication systems</a> in ways that can increase or reduce organizational exposure. With conventional annual training, completion demonstrates participation, not changed behavior. Plus, generic content doesn't address the organization's actual threat profile. Another problem? Employees encounter social engineering continuously, not once a year.</p>
<p>CISOs: It's time to shift to an effective, structured cybersecurity training approach that <a href="https://www.techtarget.com/data-technologies/feature/Risk-assessment-matrix-Free-template-and-usage-guide">assesses risk</a>, prioritizes business needs, runs continuously and measures outcomes.</p>
<section class="section main-article-chapter" data-menu-title="Assess the organization's cybersecurity risk">
<h2 class="section-title"><i class="icon" data-icon="1"></i>Assess the organization's cybersecurity risk</h2>
<p>Start with a risk assessment that determines which human risks justify investment and which existing controls can address them.</p>
<h3>Identify human behaviors that create material exposure</h3>
<p>Find the workflows where employees can affect organizational risk. These often include the following:</p>
<ul class="default-list">
<li>Disclosing credentials.</li>
<li>Approving fraudulent transactions.</li>
<li>Handling sensitive information.</li>
<li>Receiving phishing or <a href="https://www.techtarget.com/cybersecurity/definition/What-are-social-engineering-attacks">social engineering attempts</a>.</li>
<li>Misconfigurations or improperly using technology.</li>
<li>Bypassing security controls for convenience.</li>
<li>Failing to report suspicious activity.</li>
</ul>
<p>Recognizing these exposures enables more accurate threat mapping. Don't forget to consider contractors, privileged users, executives, remote workers and third parties as they create additional risks.</p>
<div class="youtube-iframe-container">
<iframe id="ytplayer-0" src="https://www.youtube.com/embed/QwRnGJdXGaA?autoplay=0&modestbranding=1&rel=0&widget_referrer=null&enablejsapi=1&origin=https://www.techtarget.com" type="text/html" height="360" width="640" frameborder="0"></iframe>
</div>
<h3>Map threats to business consequences</h3>
<p>Clearly relate behaviors to likely impacts. These could include compromised user or email accounts, data exposure, ransomware entry or operational disruption. Any of these could have reputational or contractual consequences.</p>
<p>Note that not every behavior has an equal impact. Prioritize behaviors based on their likelihood and potential business impact.</p>
<h3>Establish a baseline</h3>
<p>Understand the organization's current exposure. Use existing data, phishing reports, help desk trends, risk assessments, audit findings and security telemetry where available. <a href="https://www.techtarget.com/cybersecurity/tip/How-to-construct-an-effective-security-controls-evaluation">Identify existing controls</a> while noting coverage gaps. This baseline is crucial for measuring the program's success and continuous improvement.</p>
</section>
<section class="section main-article-chapter" data-menu-title="Design a risk-based awareness program that will drive behavior change">
<h2 class="section-title"><i class="icon" data-icon="1"></i>Design a risk-based awareness program that will drive behavior change</h2>
<p>Using a data-driven, thoughtful approach to risk assessment enables the organization to build a business-specific program architecture rather than a generic curriculum. The architecture targets identified weaknesses to enable actual improvement.</p>
<h3>Define the behaviors that the program needs to change</h3>
<p>For each identified priority, define distinct actions and goals:</p>
<ul class="default-list">
<li>The desired employee behavior.</li>
<li>The risky behavior to reduce.</li>
<li>The trigger or situation in
[…]
Content was trimmed to protect the source. Please visit the original article for the full text.
Read the original article:
