Any recommendations for educating employees about insider risks? What are some best practices you've found effective / what resonates most?
Sort By:
Oldest
CISO in Softwarea year ago
Based on my experience, one of the best practices companies can perform is to create and (mandate) employee training based on real world scenarios and events that have occurred previously inside the company (with names and people anonymized). Information and Security Office & Enterprise Data Governance/AI in Finance (non-banking)a year ago
Just to be clear: Not all Insider Risks materialize into Insider Threats, but all Insider Threats originate from an Insider Risk. Educate Users as part of the Cybersecurity Training and Awareness program (annual or bi-annual training). Ensure it is aligned with organizational risk appetite.
Chief Information Security Officer in Healthcare and Biotecha year ago
Couple suggestions - 1. Continious employee training program
2. Incentivise the positing reporting
3. Provide sample use cases, if possible from past incident without disclosing the employee details
4. Create sense that security team is monitoring.
Strategic Banking IT advisor in Bankinga year ago
We have a pretty good training strategy that includes many different topics: insider risks, security, data protection, accountability, etc.It's always interactive with videos and some questions to answer (kind of an exam).
Some training are mandatory and dashboards are available to managers.
With this, everyone will not only see the training but need to succeed the final exam (5 or 6 questions).
All year long, new material is being produced on multiple subjects.
And it's all managed through Workday.
Finally, every employee could access its Security Dashboard where a gauge indicates his level of awareness. And mandatory trainings also show up on the dashboard.