ABC+
Articles on security awareness, behaviour and culture.
Why security awareness training sometimes fails – and what you can do about it
To demonstrate why security awareness training so often fails, it’s worth conducting a quick thought experiment. Imagine you’re a smoker and, one day, you find out you’re genetically susceptible to lung cancer. Thanks to your genes, you’re two-three times more likely...
Measuring The Effectiveness of Security Awareness Training
Online security awareness training is now the most popular form of security awareness training in the world. As we noted here, that’s good news when it comes to measuring the effectiveness of security awareness programs and training. Offline, things aren’t so easy to...
Security Awareness Training: The Old Definition and the New
At the time of writing, Google tells us security awareness training is “a formal process for educating employees about computer security.”You can bet it’s a prevalent definition: the search engine sifts through every indexed web page ever written on the topic to...
The ‘ABC’ guide to improving information security
Most security awareness training attempts to raise awareness only. To decrease risk, Security awareness training must raise awareness, change behaviour and build a culture of security. It’s an unfortunate fact, evident to both those who work in security and those who...
Is “domain dependence” limiting our cyber security awareness?
Domain dependence causes our points of view to change in different domains – and it could be limiting cyber security awareness campaigns... Let’s talk domains. Not web domains, but domains in life. Areas, specialisms, disciplines – call them what you want. As humans,...
Traditional cyber awareness programmes are failing to keep people safe online
Here’s how to markedly increase their effectiveness At some point in recent history, firefighters were tackling a domestic kitchen fire in Cleveland. After locating the fire, the firefighters doused the modest flames with water. But, for some reason, the small fire...
How our desire for consistency could prevent more cyber attacks
The human preference for consistency could boost security – but in practice it often does the exact opposite Why does folklore suggest we spend 3 months’ salary on an engagement ring? Why, when we get married, do we vow to stay together for life, no matter what...
What actually is “the human aspect of cyber security”?
The definition of the human aspect of cyber security is changing. Here’s what it means in a traditional sense, as well as what it will mean in the future As today’s CISOs will know, cyber security strategies are typically...
Why it sometimes makes sense to throw cyber security out the window
And what cyber security professionals can do to make sure it never happens When is it a good idea to commit a crime? Some say never. Some say properly adhered to laws are what allow societies to live harmoniously and prosperously. But consider something as simple as...
“The best way to avoid £17m fines is to stop trying to avoid £17m fines”
Advice for companies affected by the upcoming NIS Directive On the 28th January, 2018, the UK’s National Cyber Security Centre published guidance on the upcoming Network Information Systems (NIS) Directive, which is set to come into force on the 9th May this...
10 ways to get your people interested in cyber security
Get your people interested in cyber security and you become more resilient. Here’s how to go about it, starting with the potential end of the world. Uranium centrifuges facilitate either nuclear power or nuclear weapons. They’re powerful, valuable and extremely...
Protecting the people running on autopilot
How people can take proper precautions online without even having to think I imagine you’ll have experienced something like this before. You’ve been tied up in a report for the last hour or two. Your concentration is waning and you need a change of pace. So you turn...
10 of the most important cyber security articles of 2017
With new laws, new threats and data breach cover-ups, 2017 was another big year for cyber security. Here are the stories everyone was talking about. 1. New Bill Forces Cybersecurity Responsibility Into the Boardroom In March, a new bill introduced to the US senate...
3 mistakes people make with cyber security training
A 2017 survey revealed 52% of organisations’ cyber security budgets are increasing, with 23% of the increases dedicated to training. At the same time, the UK’s 2017 cyber security breaches survey revealed the number of UK businesses that suffered a breach or attack in...
How the ‘cocktail party effect’ leaves us vulnerable to cyber attack
How the ‘cocktail party effect’ leaves us vulnerable to attack – and what the cyber security industry might be able to do about it With Christmas fast approaching, many of us will soon be attending our annual Christmas parties. At such parties, it’s impractical for...
How to keep your company secure this Black Friday
Black Friday and Cyber Monday are notoriously conducive to cyber scams. In this article, CybSafe founder Oz Alashe offers five tips on staying safe during the annual sales. ‘If something seems too good to be true, it probably is.’ That’s the mantra cyber security...
If you want my national insurance number, just ask!
Why we’re so comfortable handing out personal details online – and how we may be able to reverse the trend On a mild July evening in 2010, Leo Hickman set out to meet a woman named Louise. At the time Louise, a 30-something recruitment consultant with straight, auburn...
Gains, losses and unconscious calculations
Our attitudes to loss make us vulnerable online. Here’s how we can nullify the risks – starting with a question. Which of these two generous offers would you rather take up? The first is £1000 in cash with no strings attached. The second is the chance to win £2000 –...
Large enterprises beginning to question SME cyber security, Inaugural CybSafe Supplier Cyber Security Study finds
1 in 3 SMEs say they needed cyber security precautions to win new contracts in the last year alone Large enterprises are beginning to scrutinise the cyber security of their suppliers. As part of our Inaugural CybSafe Supplier Cyber Security Study, we looked into the...
How CybSafe turns a perceived cyber security risk into another line of defence
Your people are often cited as one of the greatest cyber security risks your company faces. By changing their behaviour, CybSafe turns them into a resilient line of defence For cyber criminals, it must seem so easy. Step 1: Gather personal informationStep 2: Send a...
10 ways to make cyber security part of your working culture
How can cyber security professionals use psychology to help people prioritise cyber security in the workplace? 1. Increase face-to-face interaction Unsurprisingly, the vast majority of messages from IT security departments are written and sent digitally. Emails and...