User Awareness, Training, and Testing
In this chapter, we will be moving on to what I consider the most important functions within your cybersecurity program: user awareness, training, and testing. The human element is critical to the success and ongoing operation of any organization, but they are the most vulnerable as it relates to cybersecurity. Our cybersecurity programs need to evolve to put our users first and not treat the user awareness, training, and testing program as a check box to ensure we meet compliance or regulations. Traditionally, an annual cybersecurity training requirement along with an annual testing exercise is most likely what is currently being executed. This provides very minimum benefit to our users. The user awareness, training, and testing program needs dedication to provide users the attention they need to be better informed and prepared for today’s current cybersecurity risks. Throughout the chapter, we will provide you with details on what should...