Summary
This chapter has covered a lot and has hopefully demonstrated the need for a very comprehensive user awareness, training, and testing program for your cybersecurity program and broader organization. We cannot take this function lightly by requiring only a single annual training event and a single user test. This will not improve a user’s ability to reduce risk for the organization. We must provide ongoing awareness, training, and testing to all users. Data also backs this up: the more we provide awareness, require training, and execute testing, the more aware our users become and the less vulnerable and prone to threats they become. Clearly, running an effective program is going to take dedicated resources; this program will not run efficiently with limited resources. It needs dedicated time and commitment to ensure longer-term success.
To begin the chapter, we covered why the human element is the most important. Here, we reviewed multiple sets of statistics to...