How to establish a Security Awareness program for your Company !



                   There is no security control which can mitigate or compensate human stupidity. What may seem as common sense to security professionals would be not be so simple for common employees to use and practice. It is therefore essential to incorporate security awareness a part of your security program. Majority of the attacks happening on organisation is due to Social Engineering. By spending effort to train employees to be aware of basic security aspects will help avoid costly mistakes


Common methods of security awareness which can be implemented in an organisation include

  1. Awareness e mailers 
  2. Online Quizzes 
  3. Phishing Simulations and training 
  4. Training sessions for new joiners 
  5. Compulsory online training for all employees once a year 
  6. Specialized training for developers, system admins , cloud architects, infrastructure specialists and Senior Management 
  7. Awareness weeks twice  a year 
Themes for Security Awareness 
  1. Privacy of Customer data 
  2. Social Engineering - Physical and against Phishing emails 
  3. Secure Coding for Developers 
  4. Secure practices for Infrastructure team 

Details of Awareness week 
  1. Leadership messages 
  2. Online Quizzes 
  3. Games on Floor 
  4. Theme based Skits 
  5.  Online Skits 
  6.  Posters
  7.  Danglers 
  8. Standees 
Security awareness training for third parties such as vendors, contractors and business partners should also be conducted religiously to ensure that they are aware of the security requirements of the organisation. 


A annual calendar should be prepared and followed religiously.  Additionally key metrics should be defined to ensure that focus on security awareness is maintained throughout the year. The awareness should also be connected with key security risks the business is facing. 







Comments

Popular posts from this blog

API Security - A risk based approach for CISOs

2024 Year Review and thoughts

Key Steps for Building an Effective Data Protection Program: From Analysing Business Needs to Ongoing Protection