The different building blocks
“You clicked on the phishing link!” How many times have we come across someone who clicked on phishing links from unknown recipients? Even though training after training was conducted, not to mention the occasional phishing exercises conducted company-wide or with targeted groups, someone in the company is bound to say, “Oops! I accidentally clicked on that unknown link. Sorry.”
Is security-awareness training an avenue to enhance security culture? It definitely is. As a CISO in the digital telco space, Noordin shares that security-awareness training, and conducting phishing exercises have become part of their business as usual (BAU) process. Even though it is treated as a de facto, the need to continually make the training more enticing is important to maintain user engagement.
Building a company-wide healthy security culture is an uphill battle. It is also pretty much dependent on the nature of the business you are involved...