Security Awareness Training
Example Policy Guide
Introduction
Social engineering and phishing continue to be the top root cause for malicious data breaches by a wide margin as compared to any other cyber attack methods. The percentages vary according to the survey and timing, but in all cases, social engineering and phishing are the number one ranked cybersecurity threat by any objective measure. Most sources place social engineering and phishing as involved in at least 40% of all successful attacks and others place the percentage at over 90%. It is clear that fighting phishing and social engineering should be the top focus for all organizations.
Fighting any cybersecurity threat means crafting a detailed, layered, defense-in-depth set of mitigations, including policies, technical defenses and training. So far, despite over three decades of the best technical defenses, social engineering and phishing attacks continue to get to end users. End users must be taught how to recognize social engineering and phishing threats and how to treat them. Accordingly, security awareness training (SAT) is among the most high-value mitigations any organization can perform to significantly reduce cybersecurity risk.
All security mitigations should have policies directing their application and use. All SAT programs should begin with or be driven by an SAT policy document. Part I of this paper covers the various components which should be covered by any SAT policy and part II gives a generic SAT policy example, which can be used as the basis of your organization’s SAT policy, if desired. You can use this paper to craft your organization’s first SAT policy document or use it to update or modify your existing document.