Building a User Awareness, Training, and Testing Program
For those of you who don’t have a user awareness, training, and testing program in place today, I would suggest you make this one of your highest priorities. This program is core to the success of your broader cybersecurity program. Executing one-time onboarding training, a one-time annual phishing campaign, and a one-time annual training event does not constitute having a user awareness, training, and testing program in place. This shows you are simply meeting a requirement enforced and checking a box to show you are in compliance. Unfortunately, this is no longer acceptable, and we need to evolve our user awareness, training, and testing programs to a much higher standard.
For those who do have user awareness, training, and testing programs in place today, there is a need to continue to review and assess your programs to ensure they continue to evolve. The reality is this program needs resources either dedicated...