What security awareness programs do you find helpful for employees?

1.2k views2 Upvotes9 Comments
Sort By:
Vice President, IT & Systems in Software4 years ago
We had been running phishing campaigns every other month, but we still see a majority of users who learn and unlearn. We have to constantly keep educating end users. We have found mailers that have really worked. We try to send at least 4-6 IT tips and security guidance emails every month to keep reminding people on what they should and shouldn’t be doing. Add-on’s like the report phishing feature is also really helpful. Tying security related training to people who fail a phishing or security test helps in the long run.
no title4 years ago
I think helping the company understand that it's everyone's responsibility to keep the company secure (one compromise could in fact take everything down, so to speak) is very important. I think making sure that people understand that they need to take the time to think before doing anything, to have that level of suspicion. We want them to know they shouldn’t be afraid to ask if something is phishing. I think one of the great things we do is that new hires get phishing training and other security training. We see all kinds of poorly formed emails that are legitimate, but they get sent to us now, and it is encouraging to see that. I want to make sure people understand that just because you can't spot the phish necessarily, that is nothing to be embarrassed about. We'd rather you show us what you found because that might help us in general. There's nothing to be ashamed of and there's nothing wrong with pointing out something you see, and just making sure that there's a greater awareness overall.
1 Reply
Vice President, IT & Systems in Software4 years ago

Also in phishing campaigns you've got to be aware of the content within the email. You will be surprised by the sensitivity that surrounds some templatized use cases available especially during certain cycles of the year it’s truly, astounding. So while IT managers are selecting these campaigns, you really need to wear the end user hat as well.

lock icon

Please join or sign in to view more content.

By joining the Peer Community, you'll get:

  • Peer Discussions and Polls
  • One-Minute Insights
  • Connect with like-minded individuals
CIO in Energy and Utilities4 years ago
Continuos education and capaigns like email signature messages, corporate screen wallpapers, etc. We observed a dramatic decrease on phishing/malware tickets since we implemented this strategy.
VP, Chief Security & Compliance Officer in Software4 years ago
We are past the time of awareness, we need to require engagement and ownership. Focusing on defense mind set at the home translates for improved general work place performance. Ownership mind set on secure SDLC translates for better performance in the technical areas.
1 Reply
Field Chief information Security Officer (CISO) for Public Sector & Client Advisor in Finance (non-banking)a year ago

Thanks . I generally agree, and I have written blogs with a similar sentiment. 

But my question is, as a chief compliance officer, how do you train employees on current cyberthreats and stay current? What is required and optional for staff? Also, do you make that content fun, engaging, relevant, etc.? 

Finally, how do address newer topics like GenAI (good, bad, ugly...) 

Director of Network Transformationa year ago
There are a few vendors out there looking to "gamify" security awareness.  Heard positive feedback.  

Content you might like




Alignment with Cloud Provider7%


Alignment with Existing IT Skills4%

Product / Feature Set7%

Vendor Relationship / Reputation

Other (comment)

View Results
5.7k views3 Upvotes1 Comment
Head of Enterprise Architecture MERCK Group in Healthcare and Biotecha year ago
Strategy & Architecture
Read More Comments
39k views5 Upvotes34 Comments

No Increase16%

1-5% increase47%

6-25% increase24%

26-50% increase6%

51-75% increase1%



View Results
1.7k views1 Upvote