Frequently Asked Questions
What is security awareness?
Security awareness training refers to employee understanding of cyber hygiene, identifying the many ways attackers try to breach critical business systems or personal accounts, and how users play a critical role in stopping attacks to protect their organization.
Why do we need security awareness training?
Research suggests that human error is involved in more than 90% of security breaches. Security awareness training mitigates user risk by educating employees about the potential mistakes and proper procedure they need to follow when utilizing email and the web. It promotes more secure behaviors to protect personal and organizational data.
What are best practices for how to develop security awareness training?
Companies look to security awareness to mitigate user risk. But traditional methods take on a one-size-fits-all approach and struggle to produce tangible results.
For security awareness to be effective, it needs to be powered by real-world risk insights that consider what kind of training and intervention an employee needs and when they need it.
By leveraging risk insights from across an organization, human risk-powered awareness & training programs can tailor a security awareness program specific to each individual employee. This includes responding to real employee actions with timely intervention that can address negative behaviors or reinforce positive behaviors.
Security awareness programs should also provide persistent and consumable training with broad coverage for the security concerns that are most relevant to an employee’s work environment. Training should be engaging and interactive to ensure learning retention while not over-burdening employees too much.
How long should a security awareness training program be?
The length of security awareness training programs varies widely. Mimecast's approach is to provide short training sessions on a monthly basis, delivering ongoing education that keeps security best practices fresh on employees' minds.
What awareness topics should an effective security awareness training program include?
Security awareness trainings need to be reimagined for human risk factors, taking complex topics and making them fun and understandable through humor.
Users should be trained on the risky behaviors they exhibit, which generally relate to phishing, information protection, office hygiene, data in motion, and data privacy and protection. In addition, awareness topics can deliver role-specific content for DevSecOps, healthcare, and executives, and they should align with key industry standards such as ISO, NIST, PCI DSS, GDPR, and HIPAA.
What is a human attack surface?
The human attack surface is the entirety of risk an organization faces because of humans and their actions (or, inaction). Everyone plays a unique role in the day-to-day operation of a business. Some people have privileged access to systems, data, information, or financial processes.
All of these factors represent opportunities to threat actors who may seek to exploit human behavior – whether by complex attacks or cunning social engineering tactics. What's more, these threats don’t just originate from outside the organization. Security teams must also be mindful of both unintentional and intentional insider threats. The challenge is assessing all these dynamic factors to develop an effective human risk management strategy.
Why should human risk management and security awareness training be brought together?
Historically, security awareness is a siloed function, separated from the rest of the organization’s security strategy. As leaders scrutinize investments in security awareness, they find themselves asking tough questions like:
- Does training work?
- Are employees' behaviors changing?
- Who are our riskiest employees?
The reality is, traditional security awareness training solutions have a hard time answering these questions. But why? In general, security awareness takes on a one-size-fits-all approach, it’s largely output-oriented and doesn’t measure real-world behaviors.
When security awareness adopts a human risk management approach, it gives security teams the opportunity to revolutionize security awareness, starting with unprecedented risk visibility. When training is powered by a human risk management platform, it can be tailored to each employee’s unique risk profile.
The result? Re-envisioned security awareness, featuring hyper-personalization, alignment with real security outcomes, and real-world risk insights.