Enhancing Your Organisation's Cybersecurity Via Informed Staff
Analysis of successful cybersecurity attacks often shows that human error was the weak link in security. Many organisations have excellent technical protections in place, from the network edge firewalls and intrusion detection systems to endpoint protection tools, often with network detection and response (NDR) and Security Information and Event Management (SIEM) tools in place to monitor and protect the space in between. Other cybersecurity tools like dummy servers from deception solutions, data exfiltration detection tools, and more, get used in many instances. All these do an excellent job of preventing many types of cybersecurity threats and help quickly identify the activities of bad actors who evade protections and gain a foothold on a network.
As the analysis of cyber-attacks shows, we can trace entry for many successful attacks to human error — for example, by clicking on a link in a message that results in a malware install or entering personal information into a spoof webpage visited after reading a Phishing email. Reducing these errors by staff plays a large part in enhancing the overall cybersecurity posture of an organisation and reduces the risk of an attacker successfully compromising the network.
The only way that staff will spot fake emails, messages, and websites is if they get trained to spot them. And not just once in a monolithic presentation, but rather with repetition via short and frequent training. The usecure platform is designed to provide this training to an organisation’s staff in bite-sized and regular sessions that each person completes on their own devices, without the peer pressure sometimes associated with classroom training or group presentations. It is available for MSPs to include in their security service offerings to clients and is a great way to enhance the value provided. Contact Renaissance to find out more about the usecure platform, and read on for a high-level overview of what makes it ideal for cybersecurity awareness training.
The usecure Platform
Finding the right balance between training frequency and end-user overload is tricky, and varies between individuals. You want your training platform to keep cybersecurity awareness high without tipping over the edge into a place where people get fed up and switch off.
Managing this balancing act is where usecure are experts. They have developed cloud-based, automated awareness training for cybersecurity and related areas that keep people engaged with the topic without overloading them. Each individual has training based on their knowledge gaps discovered from short quizzes. The training frequency is also automated via pre-set timescales in five to ten-minute sessions, with completion and quiz scores used to report progress to managers.
usecure Automated Cyber Awareness Training
The usecure cyber awareness training has four modules:
- uLearn - Measure, boost and monitor employee cyber awareness.
- uPhish - Identify phish-prone users and drive human resilience.
- uBreach - Monitor the dark web for exposed employee credentials.
- uPolicy - Eliminate policy distribution pains and automate staff approvals.
uLearn is the core of the usecure platform. It is an online cloud-based cyber-awareness training solution that is simple to deploy, easy to configure for each organisation's needs, automatically tailored to each individual's skill level, and scored so that managers can ensure that everyone is up to speed. This latter feature also helps to demonstrate to C-level executives and external auditors that cybersecurity awareness training and procedures are in place.
uLearn sends individually tailored cybersecurity awareness training to all staff members. Each training session is only 5 to 10 minutes in length and has a multiple-choice quiz to track understanding. The first step in the process is to get everyone to complete a cybersecurity awareness questionnaire on 12 subjects. These get scored and presented on a chart like the one below.

Each training schedule is adjusted to preferentially send individuals lessons in the areas they score poorly on. In the example above, that would be Phishing first, then Security at Home, and Public Wifi, then the other topics further down the line.
The frequency for the training is fully customisable by day and for how many weeks between each session. This ensures that people are not continuously bombarded with reminders to do training — a sure-fire way to annoy people and deter them from raising their awareness.
Once a schedule is defined, the usecure cyber awareness platform handles all the details of generating the training, sending emails to staff to let them know, and tracking responses and quiz scores. There is no time-consuming hands-on management required.
Testing Awareness
The uPhish module within the usecure platform provides organisations with tools to send simulated phishing emails to staff to see who interacts with the emails or spots and reports them as dangerous. uPhish can send single targeted phishing emails to specific recipients or send them to a random selection of users. It comes with multiple templates that organisations can use to mimic well-known sites. We should note that these simulated emails to users do not do anything damaging if a user does interact with them. They are just used to see who fails to spot the phishing attempt after they have trained with uLearn.
Monitoring for Data Leakage
The uBreach module monitors for information that may be freely available or for sale on the Dark Web. It runs in the background and monitors for any information related to users’ work email addresses. This provides organisations with a snapshot of what information may have been leaked or compiled from public sources. Information made available on the Dark Web gets used to plan future cyberattacks. The monitoring is an automatic process that just needs each user in an organisation to have their email address entered into uBreach. From then on, scanning and reporting are automated.
Managing Cybersecurity Policies
uPolicy makes it simple for organisations to create, distribute, and store agreement responses for policies related to cybersecurity. For example, mobile device usage policies, data handling, and many more. The solution comes with templates that cover all of the main areas that an organisation would need to have a policy in place. These templates are editable as required to reflect each organisation, or you can import existing policies if they exist.
The policies can be automatically emailed to all staff, and their reading and agreement can be tracked and reported on to ensure that everyone is aware of them. Organisations can set this agreement to recur on a period that suits. For example, annually or whatever period makes sense.
uPolicy reporting can be used to demonstrate to executives and external auditors that cybersecurity policies are in place and that staff have read and accepted them. They can also be used as part of the awareness training process for staff.
Contact us for More Information
Continuous and user-friendly cybersecurity training is a vital part of any security strategy. The usecure platform makes it easy to deliver tailored training without many of the annoyances usually found with training systems. Combined with the other core deliverables in the solution, usecure is the ideal platform to enhance staff security awareness. Contact us to find out more and how MSPs can include usecure in your portfolio of services.

