4 tips to boost cyber security awareness in the company

2. November, 2022

Humans as a weak point are a recurring theme in IT security. Lack of awareness, lack of information and human error cannot simply be resolved with an update.

Preparing the relevant information efficiently and in a way that everyone can understand is not as easy as one might think at first glance. Not all employees have a technical affinity, what they hear cannot always be independently applied to practice, and old habits are notoriously stubborn.

4 + 1 tip to create and improve cyber security awareness

We have collected some concrete tips that can help you to make your internal communication strategy around the topic of cyber security more appealing and efficient. [1] [2]

1. Address the right target group(s)

Sometimes the (too) technically prepared information simply does not fit the level of knowledge and information of the addressees. Content is too long and complex–or too mundane and boring. Always keep your target group in mind when creating the information!

Also, avoid fancy technical terms and stick to understandable everyday language. It must be easy for the audience to understand why various precautions are important and what exactly you are expecting of them in practice. An appealing presentation or witty design can also help to attract attention and be remembered.

2. Practical information about risks and threats

Stimulate the curiosity of your colleagues so that they want to deal with the topic out of self-interest, because this is how you achieve the best learning effect! Point out why the new knowledge is worthwhile and what benefits it brings personally – for example, to inform and protect their own family.

Explain in an understandable way about known and new risks and their effects. Make a direct reference to everyday (working) life and give concrete tips and guidelines for the desired reaction and course of action. Organise the information in short, clear modules with the optional possibility to go into more depth. You can also establish a good reference to everyday life with videos or podcasts. [3]

3. Create open communication and space for questions.

Create an open communication atmosphere with the saying “There are no stupid questions” in mind. Especially people who have only very superficial contact with IT are quickly overwhelmed with information that experienced users already take for granted.

The possibility to ask simple, basic questions about all areas without losing face encourages employees to approach the complex topic. At the same time, the questions and feedback give you indications of where there is still potential for explanation or improvement from the user’s point of view.

4. IT security is an ongoing process

Building and training IT security awareness is a continuous process that requires firm anchoring in the company. Content can alternate and take different forms. Important core topics should be repeated. Regular information packed into small “bites” is more effective than less frequent but comprehensive mailings. Also, use freely available resources and share suitable security tips from others – this makes the presentation more varied and shows that the topic of cyber security has general relevance.

Variety also comes from interactive methods and tests that give you additional feedback on possible strengths and weaknesses. These can vary across departments and scenarios to assess effectiveness. A simple starting option is, for example, the simulation of phishing emails. Besides, external specialists can help to conduct appropriate testing, awareness campaigns and individual training. [4]

Extra tip: Make sure you set an example!

The IT department and the management play a key role in the implementation of all security measures. Never underestimate the indirect communication of priorities in everyday life, which you and your colleagues convey and exemplify to other employees through your daily actions!

You might also be interested in this:

Current cyber-attacks screened: How attackers get into your system

Sources:
[1] https://connect.geant.org/2022/10/14/seven-tips-to-run-effective-security-awareness-campaigns
[2] https://www.allianz-fuer-cybersicherheit.de/Webs/ACS/DE/Informationen-und-Empfehlungen/Empfehlungen-nach-Angriffszielen/Faktor-Mensch/Awareness/3-Tipps-fuer-mehr-IT-Sicherheits-Awareness/3-tipps-fuer-mehr-it-sicherheits-awareness_node.html
[3] https://oe1.orf.at/artikel/691941/Gestohlene-Identitaeten
[4] https://www.ikarussecurity.com/managed-it-ot-security-solutions/secutain/

MSSP of the Year 2024

SIEM

What is a SIEM?

Nozomi Guardian Air
HarfangLab Guard
MITRE ATT&CK Framework
v.l.n.r.: Joe Pichlmayr (CEO IKARUS) – Anouck Teiller (CSO HarfangLab) –Alexander van der Bellen (Bundespräsident Österreich) - Frédéric Joureau (Erster Botschaftsrat der französischen Botschaft in Wien) – Christian Fritz (COO IKARUS)
EDR
Cyber Kill Chain
Business Email Compromise
Prognosen für die zehn größten Cybersecurity-Bedrohungen für 2030
E-Mail Verschlüsselung
Schritt für Schritt zum Notfallplan für IT-Security-Incidents
Account Management
Bedrohung
Indicators of Attack
Gefahren durch vertrauenswürdige Services

WE ARE LOOKING FORWARD TO HEARING FROM YOU!

IKARUS Security Software GmbH Blechturmgasse 11
1050 Vienna

Phone: +43 1 58995-0
Sales Hotline:
+43 1 58995-500
sales@ikarus.at

SUPPORT HOTLINE

Support hotline:
+43 1 58995-400
support@ikarus.at

Support hours:
Mon – Thu: 8am – 5pm
Fri: 8am – 3pm
24/7 support by arrangement

Remote maintenance software:
AnyDesk Download