One approach that could help company employees stay safe in cyberspace includes discussing potential mistakes and wrongdoings. The discussion should be conducted in such a way that people realize that almost everyone has, at some point, made a mistake that compromised cybersecurity.
See also: Remote work: Cybersecurity risks and safety practices

Promoting discussion about the threats that various users have faced can help other employees realize what to watch out for so they don't fall victim to criminals themselves.
Even the most experienced cybersecurity professional may have made mistakes at some point, so it is not right to criticize or punish other employees if, for example, they click on a phishing link (whether in a test or in real-world conditions).
" One of my favorite things is to ask large groups of people in information security: 'Can anyone here guarantee they've never clicked on a bad link?' In a room of hundreds of people, no one will raise their hand ," Margaret Cunningham , a principal researcher at Forcepoint , told ZDNet .
“And to me, no matter your expertise, no matter how much you think about security, links, phishing social engineering, or whatever – you can be the person who makes the mistake“.
See also: Cybersecurity: What to do to protect your business
Many companies try to run cybersecurity awareness campaigns, but they do so by threatening employees with potential punishment or shaming those who fail a phishing test. However, according to Cunningham, this approach doesn't help people understand the threats or encourage them to speak up if they make a mistake.

“Helping people understand risk and talk about that risk is a difficult process, especially if the culture of an organization is somewhat punitive – like ‘make a mistake and we’ll talk about it later.’ That’s not really going to help you,” the expert said.
See also: By 2030 AI will replace humans in cybersecurity
Employees about should be encouraged to talk about security mistakes potential cyber threats and shows that everyone can make mistakes and should not be ashamed if they fall victim to a phishing or other similar attack. Also, through the discussion, one can learn how to deal with similar situations more effectively in the future.
Cunningham emphasized that discussion among employees about cybersecurity issues, and especially discussing the mistakes each person has made, is extremely important in order to strengthen an organization's security.
Source: ZDNet
