Building an Effective and Comprehensive Security Awareness Program

Build a strong blueprint to get started

More Whitepapers

by Joanna Huisman

Building an effective and comprehensive security awareness program seems like a daunting task to those who are fortunate enough to be in the line of fire…I mean responsible for it. There is a lot of information at your fingertips, but how do you turn that information into something useful? Like most security awareness professionals, understanding a program’s critical components and connecting them together to design something comprehensive, continuous and engaging is an overwhelming task. It is a task we are taking on head-first in this white paper in order to provide you with a strong blueprint to get started.

What Is Your Starting Point?

Let’s first take a look at your organization’s current efforts. You may find yourself in one of the following two positions:

  • You have an established program, but it is not effective (you are not alone)
  • A security awareness program does not currently exist (again, still not alone)

To start, let’s determine where your program originates. Many organizations use internal corporate training teams to create program content. Security content is starkly different than other corporate or compliance content. There is a level of security expertise required to understand the critical elements that need to be included in a program and then how to marry those different elements into digestible bites creating one long, neverending meal. You see, whereas some training has a beginning and an end, security awareness training is continuous; there is no end. It is worth evaluating the internally-created content against that of industry providers to see how they measure up.

If you are currently using a provider, it is time to look behind the curtain to better understand what you are paying for. All providers are not created equal. They will be different in approach, content, administrative functionality, reporting, etc… It is worth pausing to ensure that you are partnered with a provider that not only delivers the best, most comprehensive approach, but also helps you measure the outcomes of that program. The contents of this white paper will provide you with some comparative elements to get started.

It is also important to consider who is leading your security awareness team/program. What we find is that these programs are commonly led by security practitioners who drew the shortest straw or someone in security who had extra time to deal with this “training stuff”. You are looking for individuals who understand organizational development, have a background in training and knowledge of how to drive behavior. Look for candidates who have strong project management and communication skills and can lead up and across an organization.

What Are You Trying to Do?

In order to build a strong security awareness program, you first need to determine your objective. Security awareness programs are anchored on having employees act in vigilant and secure ways in order to protect the organization. It may seem simple, but if you do not know what outcomes you want to drive, you will not know how to measure and represent your results.

Who Are Your Advocates?

Capturing C-level support is paramount in both driving a more secure culture and ensuring that everyone within the organization understands their role and responsibility in creating the desired state. Executives are notoriously overlooked in the training ecosystem. The thinking is, because of their elevated role, they must have been trained. Wrong. They need the training as much as you need their support. In order to capture attention at the top, you will need to leverage partners across the organization, be highly persuasive and enact a level of diplomacy that gets to the point without becoming your own blockade.

What language is likely to seize their attention and get them to act with both resources and funding? It is not doom and gloom. It is language that connects the security awareness program to the success of core business initiatives. Many C-levels fall into the “technology will solve the world’s problem” trap and throw all of the investment dollars there. Technology, although helpful and necessary in the fight against cyber crime, just is not enough. The human element is far more critical. Cyber criminals cleverly evade an organization’s security controls, preying on the uneducated, distracted and naïve, knowing that where there are humans, there is also human error.

C-level attention is continuously fought for within an organization, leaving them to sift through what programs are most closely aligned to the core business and that will drive the most beneficial outcomes. A successful security awareness program will enable other parts of the overall business to prosper; and should be communicated that way. Additionally, the C-level’s ability to act as an evangelist and lead advocate for the program will yield lasting benefits in adoption and engagement across the business.

The C-level must drive the organization’s security culture; this is a need-to-have asset in the security toolbox. By assessing employees’ security awareness, behaviors and culture, organizations can adapt their policies and training programs to the constantly-changing threat landscape. The alternative becomes less attractive by the hour: do nothing and see your organization crumble to a halt by ransomware, data theft or business interruption.

Still need help in painting the picture? KnowBe4’s (Phishing by Industry Benchmark Report) provides conclusive data that helps show your industry risk when an organization takes action and does not take action. You will most likely be asked how your organization compares to the industry data… and that is your entry point.

Whitepaper

Security content is starkly different than other corporate or compliance content.