In recent years, there have been significant changes in the way cyber threats are addressed. The human factor is now taken seriously in security. For example, human error is now recognized as a key factor in an organization's overall risk profile. Security awareness programs are not enough to educate employees.
For years, CISOs have done a remarkable job of educating users to understand the risks of the internet. But companies need to do much more to lay a solid foundation for security!

To move beyond security awareness training programs to changing behavior and embodying a security culture, you need to do the following:
- Create a people-centric security program. Go beyond tactics and create a multi-year, sustainable strategy through a four-step plan that includes: 1) Identify key threats. 2) Determine the target’s baseline behavior and state. 3) Create initiatives that will impact each stakeholder community. 4) Measure and continuously improve the plan.
- Focus efforts inside and outside your organization. Move away from point-in-time engagement activities by creating a strong culture at four different levels within the organization, taking a different approach for each component. Consult with the executive level to gain security insight, rationalize investments with business leaders to ensure security buy-in, engage with employees to create a consistently high level of awareness, and extend your reach by building the necessary trust with external stakeholders.
- Design transformative security awareness initiatives. In addition to making stakeholders aware of security , you need to work to actually get them to behave in a security-friendly manner. To do this, your initiatives need to influence stakeholders and motivate them to behave securely. Consider design principles when creating transformative security awareness initiatives.
- Start by improving the culture and influence of your own security team. The biggest obstacle to security leaders’ efforts today is the image of security itself. So transform your own team. Hire people with good people skills. This is something that is not only lacking in your organization but also in the cybersecurity sector in general.
Information source: zdnet.com
📧
Subscribe to the SecNews Newsletter
