Ways To Improve: Staff Cyber Security Awareness
Ways To Improve: Staff Cyber Security Awareness
Ways To Improve: Staff Cyber Security Awareness
10
WAYS TO IMPROVE
Staff Cyber Security Awareness
Improve Staff Cyber Security Awareness
Contents
3 Introduction
According to a recent study, the total annual cost of cybercrime for a company has jumped
from $11.7 million in 2017 to a record high of $13 million.
It has also been well documented that employee negligence has been responsible for some of
the worst cyber breaches in history. In fact, it has been reported that 90% of all cyber attacks
are caused by human error. Such statistics highlight the prevalence of security threats that
organisations face and the need to ensure Cyber Security awareness at all levels.
Here are ten best practical tips to help you create the most effective Cyber Security awareness
campaign for your organisation.
Improve Staff Cyber Security Awareness
Cyber Security is everyone’s responsibility, but resilient organisations require strong CEO
leadership. If the CEO is taking Cyber Security seriously, this will permeate throughout the
organisation and help create a culture of enhanced Cyber Security awareness.
Your risk tolerance needs to be defined at the outset, so you can implement the correct security
measures based on the actual threats faced. This avoids resources being directed at threats
unlikely to occur or that will have little or no impact on your business.
Taking time to properly identify the risks can help shape the messaging, delivery and effective
targeting of your Cyber Security awareness program.
Improve Staff Cyber Security Awareness
An information asset is a piece of information that is valuable to your organisation. This can
include Personally Identifiable Information (PII), financial information, intellectual property, or any
other information that is significant to your company.
You need to determine what the most valuable information assets are, where they’re located,
and who has access to them. Every asset should be classified (for example, public, private or
confidential) and protected based on its value. Doing so is crucial when identifying risks and
prioritising the areas that need to be defended.
After you identify these areas, you can focus on how each information asset could potentially
be compromised. Whether it’s a system breach, malware or even an insider threat, you can take
informed steps to improve these processes and reduce the chance of a cybercriminal gaining
access to critical systems.
Your CEO, CFO and senior executives are also popular targets due to their high-level access to
valuable corporate information. If a senior executive were to fall for the scam, the results could
be devastating, undermining the entire security of your organisation.
Improve Staff Cyber Security Awareness
Stories are fundamental to the way people learn; they help create an emotional response that
makes it easier to remember what’s being taught. By making the story relevant to the end-user,
you greatly increase the chance of that person retaining the information, therefore improving the
overall security posture of your organisation.
An effective policy management system is one that has a consistent method of creating policies,
adds structure to company procedures and makes it easier to track attestation and staff
responses. As a result, this system can help you streamline internal processes, demonstrate
compliance with legislative requirements, and effectively target the areas that present the
highest risk to data security.
Improve Staff Cyber Security Awareness
It’s no longer a matter of ‘if’ your organisation is going to be attacked, but ‘when’. You need to
start preparing for the inevitable and put a plan in place that ensures appropriate action when
security is breached.
Establishing an effective response plan helps educate and inform staff, improve organisational
structures, enhance customer and stakeholder confidence, and reduce any potential financial or
reputational damage following a breach.
You need to regularly test your data breach response plan to identify any areas of weakness and
to ensure that everyone on your team understands their responsibilities, both in preparing for
and responding to a breach.
Appointing Cyber Security champions is a great way to empower staff and equip them with the
skills needed to prevent a cyber attack.
Cyber Security champions don’t need to be technical experts; tapping into them is about adding
the human touch to your security strategy and enlisting the help of staff who are committed to
raising awareness and implementing good Cyber Security practices.
Improve Staff Cyber Security Awareness
Supply chains are a vital part of business operations, but often these networks are large
and diverse and span a range of different countries. These suppliers typically don’t have the
same robust Cyber Security defences in place, which means they have lots of weak points for
cybercriminals to exploit.
Every supplier that connects to your business is a potential risk, so it’s vital you carry out
detailed third-party risk assessments to address any issues that could pose a threat to your
security. Doing so can help determine what security measures need put in place to keep your
data secure.
To support compliance with regulators, it is best practice to document the results of all reviews
and make sure to act upon any recommendations for risk remediation. Without these regular
audits, your Cyber Security awareness program might not reflect the threat landscape and could
leave your organisation vulnerable to attack.
Improve Staff Cyber Security Awareness
The MyCompliance suite automates the lifecycle of annual Cyber Security awareness
campaigns within your organisation, helping to save time and provide increased protection.
info@metacompliance.com
www.metacompliance.com