Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

Cybersecurity and the Human Factor


  • Please log in to reply
11 replies to this topic

#1 VH_

VH_

  •  Avatar image
  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:04:48 AM

Posted 28 July 2023 - 12:35 PM

What is your best way to train and create awareness in your organization for the average employee with no IT or cybersecurity background or knowledge? How often do you deploy training and awareness campaigns? Any tips on language or visuals that have the most impact and are the most effective in conveying the importance of good cybersecurity practices?



BC AdBot (Login to Remove)

 


#2 hamluis

hamluis

    Moderator


  •  Avatar image
  • Moderator
  • 63,372 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Killeen, TX
  • Local time:09:48 PM

Posted 28 July 2023 - 12:55 PM

Reads like a SEO pitch to me.

 

Louis



#3 VH_

VH_
  • Topic Starter

  •  Avatar image
  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:04:48 AM

Posted 28 July 2023 - 01:59 PM

I had to search what SEO means... I am new to Cybersecurity and am genuinely interested to know what other people do to mitigate the human factor risk. I am genuinely hoping to spark knowledge sharing and learn something. 


Edited by VH_, 28 July 2023 - 01:59 PM.


#4 cryptodan

cryptodan

    Bleepin Madman


  •  Avatar image
  • Members
  • 32,303 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Catonsville, Md
  • Local time:02:48 AM

Posted 28 July 2023 - 03:44 PM

Implement employee training and test them

My Linux Systems Specifications: My Desktop - https://dpaste.com/AKGGCBGSW - My Server - https://dpaste.com/8M228Z6ZM - My laptop Arch - https://dpaste.com/FKSMU4MM2

-----------------------------------------------------------------------------

Masters of Science in Computer and Digital Forensics - Stevenson University 
-----------------------------------------------------------------------------
US Navy Veteran - 2002 to 2006 - Blue and Gold and Proud to Serve - Honor, Courage, and Commitment
 

#5 VH_

VH_
  • Topic Starter

  •  Avatar image
  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:04:48 AM

Posted 28 July 2023 - 03:51 PM

Implement employee training and test them

How do you test them? Do you purposefully try to trick them into clicking on phishing links or into giving away sensitive data?



#6 cryptodan

cryptodan

    Bleepin Madman


  •  Avatar image
  • Members
  • 32,303 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Catonsville, Md
  • Local time:02:48 AM

Posted 28 July 2023 - 04:01 PM


Implement employee training and test them

How do you test them? Do you purposefully try to trick them into clicking on phishing links or into giving away sensitive data?

Yes there are sites an organization can use to develop an anti-phish awareness training program.

My Linux Systems Specifications: My Desktop - https://dpaste.com/AKGGCBGSW - My Server - https://dpaste.com/8M228Z6ZM - My laptop Arch - https://dpaste.com/FKSMU4MM2

-----------------------------------------------------------------------------

Masters of Science in Computer and Digital Forensics - Stevenson University 
-----------------------------------------------------------------------------
US Navy Veteran - 2002 to 2006 - Blue and Gold and Proud to Serve - Honor, Courage, and Commitment
 

#7 VH_

VH_
  • Topic Starter

  •  Avatar image
  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:04:48 AM

Posted 29 July 2023 - 05:45 AM

Thank you! Any sites you would recommend? Any sites that you have used and have proven to have effective programs? Thanks again for taking the time!


Edited by hamluis, 29 July 2023 - 05:53 AM.


#8 cryptodan

cryptodan

    Bleepin Madman


  •  Avatar image
  • Members
  • 32,303 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Catonsville, Md
  • Local time:02:48 AM

Posted 29 July 2023 - 07:25 AM

The sites I have used have all been used by the places I've worked for like the FBI and Fortra. You can try searching for cybersecurity phishing training sites.

My Linux Systems Specifications: My Desktop - https://dpaste.com/AKGGCBGSW - My Server - https://dpaste.com/8M228Z6ZM - My laptop Arch - https://dpaste.com/FKSMU4MM2

-----------------------------------------------------------------------------

Masters of Science in Computer and Digital Forensics - Stevenson University 
-----------------------------------------------------------------------------
US Navy Veteran - 2002 to 2006 - Blue and Gold and Proud to Serve - Honor, Courage, and Commitment
 

#9 TairikuOkami

TairikuOkami

  •  Avatar image
  • Members
  • 72 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Slovakia
  • Local time:04:48 AM

Posted 29 July 2023 - 10:13 AM

What is your best way to train and create awareness in your organization for the average employee with no IT or cybersecurity background or knowledge? How often do you deploy training and awareness campaigns?

We just had a mandatory training like that. The boss asked me to do it for the rest of the colleagues, since most could not even finish it.

You can not force knowledge on people, it is as bad as forcing changing the password, which proved to be a wrong idea even by NSA.

We are forced to change the password every 3 months, everyone uses stickers on monitors, so they can remember the change.

Attached Files


Edited by TairikuOkami, 29 July 2023 - 10:19 AM.


#10 VH_

VH_
  • Topic Starter

  •  Avatar image
  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:04:48 AM

Posted 31 July 2023 - 01:25 PM

The sites I have used have all been used by the places I've worked for like the FBI and Fortra. You can try searching for cybersecurity phishing training sites.

Thank you! I'll take a look. If the FBI uses them... Thanks again!



#11 VH_

VH_
  • Topic Starter

  •  Avatar image
  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:04:48 AM

Posted 31 July 2023 - 01:27 PM

 

What is your best way to train and create awareness in your organization for the average employee with no IT or cybersecurity background or knowledge? How often do you deploy training and awareness campaigns?

We just had a mandatory training like that. The boss asked me to do it for the rest of the colleagues, since most could not even finish it.

You can not force knowledge on people, it is as bad as forcing changing the password, which proved to be a wrong idea even by NSA.

We are forced to change the password every 3 months, everyone uses stickers on monitors, so they can remember the change.

 

I completely agree you can't force knowledge on people. That's why I'm looking for training and awareness strategies that get the knowledge through in a light/accessible way that doesn't feel "forced".  I may be asking for too much..



#12 MJHubr

MJHubr

  •  Avatar image
  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:10:48 PM

Posted 31 July 2023 - 08:22 PM

This is a very challenging environment. People are so vastly different. Interests, perspectives, views, likes, dislikes and it goes on and on. Given human dynamics, there's never going to be one size fits all and we don't expect there to be. I think it's about consistent awareness. It has to be constant and adapting. I think there's a slight element of "fear" needed, which might be too strong of a word but if people have no consequences for their actions it won't be taken seriously. 






1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users