{"id":11640,"date":"2022-10-20T10:39:10","date_gmt":"2022-10-20T04:39:10","guid":{"rendered":"https:\/\/dtasiagroup.com\/?p=11640"},"modified":"2022-10-28T10:26:11","modified_gmt":"2022-10-28T04:26:11","slug":"six-ways-to-increase-employee-engagement-in-security-training","status":"publish","type":"post","link":"https:\/\/dtasiagroup.com\/vi\/six-ways-to-increase-employee-engagement-in-security-training\/","title":{"rendered":"Six Ways to Increase Employee Engagement in Security Training"},"content":{"rendered":"<p>By now most of us understand that employees are cybersecurity\u2019s weakest link and biggest attack vector \u2013 those online criminals are targeting specific people within organizations with access to sensitive data \u2013 instead of traditional perimeter defenses. Yet increasing employee engagement in both security awareness training and application security (AppSec) training still too often meets foot-dragging, procrastination, and collective eyerolls \u2013 when it\u2019s even offered.<\/p>\n<p>In 2021 businesses lost a staggering $7 billion due to cyberattacks and insider threats. Per usual, these breaches can be traced to a single employee \u2013 usually unwittingly \u2013 clicking on the malicious email and ushering in a torrent of trojan horses into his or her company.<\/p>\n<p><strong><b>Six Ways to Increase Employee Engagement in Security Training<\/b><\/strong><\/p>\n<p>In 2021 the\u00a0<a href=\"https:\/\/www.ic3.gov\/Media\/PDF\/AnnualReport\/2021_IC3Report.pdf\"><u>FBI\u2019s Internet Crime Complaint Center (IC3)\u00a0<\/u><\/a>fielded a record 847,376 reported complaints \u2013 a 7 percent increase from 2020. Potential losses exceeded\u00a0<a href=\"https:\/\/www.ic3.gov\/Media\/PDF\/AnnualReport\/2021_IC3Report.pdf\"><u>$6.9 billion<\/u><\/a>. Once again, ransomware and business email compromise (BEC) attacks led the way. For the first time ever the criminal use of cryptocurrency joined the top three incidents reported. BEC schemes alone resulted in 19,954 complaints totaling $2.4 billion.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-vp_md wp-image-11643\" src=\"https:\/\/dtasiagroup.com\/wp-content\/uploads\/2022\/10\/thrivex-800x800.png\" alt=\"\" width=\"800\" height=\"800\" \/><\/p>\n<p>This begs the question: How can something so potentially costly to businesses not carry greater urgency within organizations? Why are so many blowing it off, or being otherwise unserious when it comes to implementing security training?<\/p>\n<ol>\n<li><strong><b> Make it Matter, Make it Believable<\/b><\/strong><\/li>\n<\/ol>\n<p>Some versions of \u201cthis is cheesy,\u201d \u201cwe already know this\u201d and \u201cnot a thing that would happen in real life\u201d have been overheard somewhere during security training. While most employees understand they are the weak link cyber-wise, not every employee knows what to do with this information. They have heard lots of fear mongering, but far fewer solutions. Tell them what they don\u2019t already know. Communicate something of value. Instead of sowing fear, uncertainty and doubt, practice empathy and understanding for the position they are in and show vision for what they are likely to encounter.<\/p>\n<p>In other words, make your security awareness training believable and inspired by real-life attacks. Use actual web pages they are likely to run across in your examples.\u00a0<a href=\"https:\/\/www.malwarebytes.com\/sql-injection\"><u>SQL injection attacks<\/u><\/a>\u00a0don\u2019t happen on login pages, but they might happen in checkout pages. They are even more likely to happen in random, semi-arcane places. Use these as your examples, so that your audience knows that you know what you\u2019re talking about. Teach them to identify, disable and quarantine attacks before they become expensive problems.<\/p>\n<p>For example, ThriveDX\u00a0<a href=\"https:\/\/thrivedx.com\/resources\/news\/thrivedx-acquires-kontra-expanding-its-corporate-training-portfolio-with-best-in-class-application-security-training\"><u>recently acquired Kontra\u00a0<\/u><\/a>which provides application security training aimed squarely at developers. Whereas normally developers find bugs and report them, Kontra teaches them instead how to identify and fix security vulnerabilities and other bugs in real time, saving four or more weeks on the next rev.<\/p>\n<ol start=\"2\">\n<li><strong><b> Practice Radical Candor<\/b><\/strong><\/li>\n<\/ol>\n<p>Acknowledge up front that security training is nobody\u2019s first choice in time management. We get it. At the same time, people generally agree that having jobs is a good thing. If a company falls victim to ransomware, one person\u2019s carelessness could end up costing dozens of people their careers, if not the business itself. So of course, cybersecurity awareness training and AppSec training is going to be mandatory. Let\u2019s make the most of it, shall we?<\/p>\n<ol start=\"3\">\n<li><strong><b> One Size Does Not Fit All<\/b><\/strong><\/li>\n<\/ol>\n<p>Not all employees are equal.\u00a0<a href=\"https:\/\/www.statista.com\/statistics\/1122432\/job-levels-targeted-malicious-cyber-attacks\/\"><u>Some are more likely to be attacked than others.\u00a0<\/u><\/a>Acknowledging up front you understand this basic truth should increase employee engagement. Specifically, people with privileged access to sensitive data are much likelier to be targeted. Your training should account for these human heightened risks by separating them off from the group and walking them through the most likely scenarios they might encounter.<\/p>\n<ol start=\"4\">\n<li><strong><b> Tighten It Up<\/b><\/strong><\/li>\n<\/ol>\n<p>Why spend 20 minutes making a point you can convey in five? People are smarter than you think. Approach training like it\u2019s not their first day with a computer and an internet connection. By now most folks have a general understanding of what threats await them after making bonehead decisions online. What they do not have is a lot of time.<\/p>\n<p>Gyan Chawdhary is the founder and CEO of Kontra, which he calls Application Security Training by developers, for developers. \u201cNobody has time for security training\u2026least of all, developers,\u201d said Chawdhary. \u201cThat\u2019s why one of our key differentiators is that every part of our training runs five minutes, max.\u201d<\/p>\n<ol start=\"5\">\n<li><strong><b> Tell A Story<\/b><\/strong><\/li>\n<\/ol>\n<p>In addition to showing an attack and how to fix it, include a narrative. Tell an interactive story of real-life attacks. Many devs are curious as to how attackers found this bug in the first place. What tools did they use? What code were they looking for? How did this security vulnerability come to be discovered? Kontra shows them this back story and walks them through the steps from the perspective of a cybercriminal. It shows them a hacker\u2019s tricks. Square that circle, and good code follows.<\/p>\n<ol start=\"6\">\n<li><strong><b> Scale your content by integrating w\/ other LMS software<\/b><\/strong><\/li>\n<\/ol>\n<p>All too often both security awareness training and application security training are standalone courses sitting outside of a company\u2019s Learning Management Software (LMS). This effectively means you can assign training without enforcing any compliance. If developers are writing code while AppSec Training runs in the background, how would you know, and what could you even do about it?<\/p>\n<p>The other problem is many times security training will force companies to adopt\u00a0<em><i>their<\/i><\/em> LMS systems, in order to give the companies visibility into employee compliance. This presents several problems. First of all, why would a developer want to log in to yet another system in addition to their own LMS to complete the training? This also gets at the fact that many enterprise LMS systems are much more sophisticated and complex than anything offered by cybersecurity training. While an organization might gain some enforcement and compliance capabilities, they\u2019ll more than lose in overall functionality.<\/p>\n<p><strong><b>A final word on increasing engagement<\/b><\/strong><\/p>\n<p>There is no silver bullet to getting everyone to expert level in combating today\u2019s threat landscape. Ultimately it comes down to how much organizations value a security-conversant workforce and strive to implement the above tips. Making the content shorter, more relevant, and more customized should significantly increase employee engagement in security training \u2013 ultimately saving the company money in the form of attacks that never happened. Who knows, you might even discover upskillable employees to add to your security team.<\/p>\n<p>Written by Christopher Dale, Content Marketing Manager, ThriveDX, 8 September 2022<\/p>\n<p><em>Source: <a href=\"https:\/\/thrivedx.com\/resources\/article\/six-ways-to-increase-employee-engagement-in-security-training''\">https:\/\/thrivedx.com\/resources\/article\/six-ways-to-increase-employee-engagement-in-security-training&#8221;\u00a0<\/a><\/em><\/p>\n<p><strong><b>About DT Asia<\/b><\/strong><\/p>\n<p>DT Asia began in 2007 with a clear mission to build the market entry for various pioneering IT security solutions from the US, Europe and Israel.<\/p>\n<p>Today, DT Asia is a regional, value-added distributor of cybersecurity solutions providing cutting-edge technologies to key government organisations and top private sector clients including global banks and Fortune 500 companies. We have offices and partners around the Asia Pacific to better understand the markets and deliver localised solutions.<\/p>\n<p>&nbsp;<\/p>","protected":false},"excerpt":{"rendered":"<p>In 2021 the\u00a0FBI\u2019s Internet Crime Complaint Center (IC3)\u00a0fielded a record 847,376 reported complaints \u2013 a 7 percent increase from 2020. Potential losses exceeded\u00a0$6.9 billion. <\/p>","protected":false},"author":1,"featured_media":11643,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[56],"tags":[],"class_list":["post-11640","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles"],"_links":{"self":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/11640","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/comments?post=11640"}],"version-history":[{"count":0,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/11640\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media\/11643"}],"wp:attachment":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media?parent=11640"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/categories?post=11640"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/tags?post=11640"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}