Security awareness topics
Way back in the 1990's when I started doing security awareness, the widely held view and generally accepted method (best practice?) was to run periodic 'IT security awareness and training sessions' that would typically: Be planned as employee communications, corporate events, implying a mechanism for management to communicate (broadcast) stuff to staff; Force as many "users" as possible (as in IT users, not even all employees or workers) together in a large meeting room, roughly once a year; Last for an hour, or at most three; Cover several topics, generally whatever happened to qualify as 'issues' for the organization or management's 'key concerns' at the time; Lecture at people, mostly describing policies and instructions; Offer precious little practical advice or guidance other than d ispensing dire warnings about what would happen in the case of nonconformity (suggesting their primary purpose, although it was seldom acknowledged or state...