Select Page

Your cyber security goals are worthless. There, we said it

CYBSAFE-SebDB Webinar-preblog-221011MS-36

11 October 2022

Here’s the thing. Your cybersecurity goals are very noble. You know the risks you want to avoid, and that’s great.

Except it could all count for nothing.

If you’re a security awareness professional, don’t quit your job just yet. We want to get you on your way to making real change.

We’ll tell you a little about how to do that now. But if you want some real insight, register for our free webinar, ‘How to use SebDB to reduce your human risk’.

How to use DebDB to reduce your human risk

Here’s where human risk management is going so very wrong 

1. You think training is the answer

Your people attend regular security awareness training. They pass the tests at the end, every time. But having people tick some boxes won’t dial down your human risk. Never has, never will.

Awareness is good to have, sure, but it doesn’t change behavior. Yet organizations keep assigning more traditional security awareness training to their people. Yes, we’re puzzled too.

To put it plainly, traditional security awareness training is ineffective. It doesn’t influence security behaviors, and anyone telling you otherwise … is probably selling traditional security awareness training.

2. Your focus is too broad

You have your goals and you’re very proud of them. Things like “reduce malware infections”.

But the problem is, that’s only the outcome. That’s not how you get there. To make a real difference, you have to get strategic. You have to set specific goals.

And no, we’re not saying burn your goals down and run off into the woods.

But if you’re not looking at the security behaviors linked to your risks, then you’re not getting specific enough.

3. You’re not using SebDB

Speaking of security behaviors …

We know mapping security behaviors to risk-related outcomes isn’t exactly straightforward. That’s why we built SebDB.

And what’s SebDB, you ask? Only the world’s most comprehensive security behaviors database. No biggie.

Oh, and it’s free.

Academics and industry experts teamed up to create this database that maps over 70 specific security behaviors linked to security risks.

And it exists to help people just like you identify security behaviors and figure out exactly which ones your organization needs to prioritize.

The industry’s been stuck on ineffective approaches to human cyber risk for far too long. But we’re changing that. You want to start reducing your human risk. And we want to show you where to start.

 Punch your risk where it hurts and sign up for our free webinar on using SebDB.

CYBSAFE-SebDB Webinar our speakers section-221011MS-35-35-min
Behave Hub newsletter CybSafe

Do one more thing right today. Subscribe to the Behave newsletter:

You may also like

Wake-up call: the human element in the UK retail cyberattacks

Wake-up call: the human element in the UK retail cyberattacks

The digital landscape has been buzzing with news of cyberattacks rocking the British retail sector. For many organisations, these headlines haven't just been news; they've been a stark, cold splash of reality, highlighting a threat that's not lurking in the shadows, but actively knocking at the...

Tool or infrastructure? Why it matters for HRM

Tool or infrastructure? Why it matters for HRM

Tool or infrastructure? Why it matters for HRM Let’s be clear: Not all HRM software is the same. It sounds obvious, right? Yet many people miss the difference between HRM tools, and HRM infrastructure.  And when it comes to compounding security gains and designing for outsized impact, the...

NIS2: Beefing up security for critical industries

NIS2: Beefing up security for critical industries

So, you've probably heard whispers (or maybe full-blown announcements!) about this thing called NIS2.  But what exactly is the NIS2 Directive, and why should you care?  Well, in a nutshell, it's a new set of rules from the EU designed to seriously beef up critical security infrastructure across...

An open letter to CISOs & Security Leaders

An open letter to CISOs & Security Leaders

The human side of cybersecurity is evolving. Fast.But there’s a good chance you might be stuck in the past. You probably have well-established views on security awareness, culture, and human risk.You genuinely believe they matter. But if we’re being honest - you mostly pay lip service to them. And...

Why security awareness still isn’t taken seriously (and how to fix it)

Why security awareness still isn’t taken seriously (and how to fix it)

Let’s start with a painful truth:Security awareness, culture, and human risk professionals are often undervalued. Despite the rising threat of human-enabled cyber attacks, many organizations still treat addressing the human aspect as a checkbox. A communications initiative. A nice-to-have....

Security metrics reboot: Less input, better output, real outcomes

Security metrics reboot: Less input, better output, real outcomes

Unfortunately, most security awareness professionals don’t really understand the difference between: ✅ Inputs✅ Outputs✅ Outcomes But they don’t want to admit it. And honestly? We get it. It’s like pretending to know the plot of Inception when deep down, you’re just as confused as everyone else. No...