Select Page

A lesson on security behaviors

CYBSAFE-SebDB Webinar-preblog-221011MS-36

29 September 2022

It’s time you learnt your lesson about security behaviors

Assign all the traditional security awareness training you want. Your people will probably attend every session and tick all the right boxes, but their security behaviors won’t change.

But that doesn’t mean there’s anything wrong with the people. It just means traditional awareness training is ineffective.

In other words, your people aren’t the weakest link, your security solution is.

Keep reading, we’ll explain.

Oh, and if you don’t want to listen to us, maybe you’ll listen to your peers. Find out how they are reducing their human cyber risk at our free webinar, ‘Influencing specific security behaviors: Real-word examples’.

Influencing specific security behaviors meta

Here’s an analogy

It’s the end of the school year. You’re a School Head. And all your students struggled with the practical. For the third year in a row.

“Well, see you all again next year.” You sigh, as you watch them spill out of the building.

They attend every class and pass every test, but they just can’t nail the practicals. You’ve tried everything: longer classes, assigning more homework, threatening them with detention, and even handing out copies of the latest edition textbook. Yet nothing changes. 

It’s baffling. 

You’ve tried everything. 

Except changing the syllabus.

Now, an exercise

Raising security awareness is, undoubtedly, a good thing. But then what? What’s the point of raising awareness if you’re not reducing risk?

That’s what we at CybSafe have been asking for years. But we still haven’t gotten a good answer. 

Probably because there isn’t one. 

The truth is that traditional security awareness training is ineffective. And it doesn’t take much to figure that out. Doubtful? Evaluate your human layer security solution and try to answer these questions:

 

  1. Are you influencing security behaviors? How, and how many? 
  2. Are you measuring your risk? How, how often, and how reliably?
  3. Are you reducing your human cyber risk? How do you know?

Finally, a case study

What’s a lesson without a case study? 

If you’re wondering what a behavior-centered solution to human risk looks like, here it is:

CybSafe platform features include:

  • Behavior-focused reporting
  • Behavior goals
  • Behavior data integrations
  • Nudges and alerts
  • Behavior-focused learning
  • On demand help

We’ll look at how other organizations use CybSafe to help reduce human risk, during our free webinar, ‘Influencing specific security behaviors: Real-word examples’.

Our speakers-pic
Behave Hub newsletter CybSafe

Do one more thing right today. Subscribe to the Behave newsletter:

You may also like

Tool or infrastructure? Why it matters for HRM

Tool or infrastructure? Why it matters for HRM

Tool or infrastructure? Why it matters for HRM Let’s be clear: Not all HRM software is the same. It sounds obvious, right? Yet many people miss the difference between HRM tools, and HRM infrastructure.  And when it comes to compounding security gains and designing for outsized impact, the...

NIS2: Beefing up security for critical industries

NIS2: Beefing up security for critical industries

So, you've probably heard whispers (or maybe full-blown announcements!) about this thing called NIS2.  But what exactly is the NIS2 Directive, and why should you care?  Well, in a nutshell, it's a new set of rules from the EU designed to seriously beef up critical security infrastructure across...

An open letter to CISOs & Security Leaders

An open letter to CISOs & Security Leaders

The human side of cybersecurity is evolving. Fast.But there’s a good chance you might be stuck in the past. You probably have well-established views on security awareness, culture, and human risk.You genuinely believe they matter. But if we’re being honest - you mostly pay lip service to them. And...

Why security awareness still isn’t taken seriously (and how to fix it)

Why security awareness still isn’t taken seriously (and how to fix it)

Let’s start with a painful truth:Security awareness, culture, and human risk professionals are often undervalued. Despite the rising threat of human-enabled cyber attacks, many organizations still treat addressing the human aspect as a checkbox. A communications initiative. A nice-to-have....

Security metrics reboot: Less input, better output, real outcomes

Security metrics reboot: Less input, better output, real outcomes

Unfortunately, most security awareness professionals don’t really understand the difference between: ✅ Inputs✅ Outputs✅ Outcomes But they don’t want to admit it. And honestly? We get it. It’s like pretending to know the plot of Inception when deep down, you’re just as confused as everyone else. No...

The dogma of security awareness: Exposing cybersecurity’s biggest blind spot

The dogma of security awareness: Exposing cybersecurity’s biggest blind spot

“Humans are the weakest link.”“Security Awareness training = better behaviour”"If we can nail engagement, we’ll nail risk reduction.""Security Awareness is *actually* about so much more than awareness.”“Security culture is the golden ticket to risk reduction.”“Good communication, messaging,...