Posts

Security awareness topics

Image
Way back in the 1990's when I started doing security awareness, the widely held view and generally accepted method (best practice?) was to run periodic 'IT security awareness and training sessions' that would typically: Be planned as employee communications, corporate events, implying a mechanism for management to communicate (broadcast) stuff  to staff; Force as many "users" as possible (as in IT users, not even all employees or workers) together in a large meeting room, roughly once a year; Last for an hour, or at most three; Cover several topics, generally whatever happened to qualify as 'issues' for the organization or management's 'key concerns' at the time; Lecture at people, mostly describing policies and instructions;  Offer precious little practical advice or guidance other than  d ispensing dire warnings about what would happen in the case of nonconformity (suggesting their primary purpose, although it was seldom acknowledged or state...

Learning styles

Image
A couple of days ago I said I'd blog about "the preferred learning styles of various awareness audiences"*, so here goes. First, a bit about my own learning style. As a former research scientist with an academic bent, I'm a self-confessed bookworm. I read (and write!) loads. I spend countless  hours every day finding, reading, absorbing and thinking critically about stuff - mostly online although there are several heaving bookshelves in the office. Critical thinking is a vital and integral part of the learning process for me, especially in today's online world where anyone can publish anything. Sifting out truth and fact from fiction and fantasy is a very necessary part of the process (one that pre-dates the 'fake news' stuff by, oooh, centuries) so I tend to approach most Web pieces in a fairly cynical frame of mind. It takes a fair bit of effort and time to cross-check things, especially given that so much gets passed on from sources to press-releases t...

Doublespeak

Image
What does this remarkable paragraph, taken from a marketing email on "developing a policy management strategy", tell you about the writer's appreciation of his audience? "Policies and training programs that are managed as dissociated documents, data, systems, and processes leave the organization with fragments of truth that fail to see the big picture of policy and training across the enterprise and how it supports the organization’s governance, risk management, and compliance (GRC) responsibilities. The organization needs to have holistic visibility and situational awareness into policy and training across the enterprise. Complexity of business and intricacy and interconnectedness of policies and obligations requires that the organization implement a policy and training management strategy." Words fail me. Keeping things readable and understandable is certainly challenging in this line of business. Partly that's a result of the specialist terms we use (ofte...

Job descriptions

Image
A few years back we published a generic job description for the "Security Awareness and Compliance Manager" role. Now, we've broken it down into three distinct chunks:  We envisage the Security Awareness Manager running the show, managing the security awareness program and team as a whole, interacting personally with management, planning and man-managing the team. Ideally, one or more  Security Awareness Officers  help the manager prepare for and perform various awareness activities, deliver the awareness materials and messages, present awareness sessions, interact with workers etc. (more below). A number of Security Contacts are typically embedded throughout the business, in much the same way as fire wardens and first-aiders. They may only be part timers but still they are a very valuable part of the social network that distributes security awareness far and wide and (just as importantly) provides useful feedback and direction from the business. They make up the ...

St David's day downunder

Image
Hello reader, welcome. There's not a lot to say about March 1st, except that it was a glorious sunny warm St David's day here in NZ. Consequently I really enjoyed riding this, recharging my batteries and concentrating on the gravel track somewhat munted by the loggers.  An entirely different kind of security awareness!

28 days of awareness: day 28

Image
Well here we are at the climactic end of another successful month.  The ransomware awareness materials were all packaged up and despatched to our customers with our good wishes. Job done for us - well almost.  We've also updated the website and this blog, and generally tidied up in the office.  This is how the completed module ended up: There are 34 files and 56 Mb of content (52 megs zipped), all fresh and most of it prepared from scratch this month. If these awareness materials would be of value to your security awareness program, please let me know. Is ransomware of concern in your organization? Do you have all the relevant controls in place, and are they all working well - including the all-important vigilance of workers using email and the web, competent management oversight and incident responders primed to leap into action at the first inkling of trouble? We can help you with all that, and more. We'd love to help. Meanwhile, there are customers to contact, sal...

28 days of awareness: day 27

Image
We're on the home straight now.  All the writing is done and dusted, proof-read and polished to a gleam. The poster images are winging their way to us through the Internet. The website is being revised with an updated home and 'this month' pages describing the ransomwareness module. We'll take the opportunity to quote Pro fessor Angela Sasse , professor of human-centred technology and director of the UK Research Institute in the Science of Cyber Security at University College, University of London. Angela's comments at a European m eeting resonated with me, in particular: “In most organizations today, awareness training is just background noise. This stuff is being pushed at people but its going past them. They are not engaging with it and not changing as a result.” Agreed, engaging the audience is crucial, Angela, but how ?  Several engagement techniques are employed in the ransomware materials: Rather than attempt to cover everything at once, we've focused on ...