Maximising Employee Security Awareness: Discover how traditional Security Awareness Training falls flat
A lot of effort and resources go towards cybersecurity defence. Technology solutions are deployed at all levels of the IT infrastructure stack: in the Cloud, at network borders, on servers within networks, on endpoint devices, plus solutions to monitor network traffic for irregularities. These are all essential and need to be part of an overall cyber defence strategy.
People also need to be part of the defence strategy — all people, not just those tasked with cybersecurity and IT management. Many successful cyberattacks gain entry to an organisations networks and systems by tricking people into clicking on a nefarious link or opening a malware infected document or website. Phishing and ransomware attacks that target people are rampant. The scale of the issue gets highlighted in the data reported in the 2021 Version Data Breach Investigation (DBIR) Report. It shows that 85% of cyberattacks that result in a data breach include a human element.
It's hard to blame the people tricked by cybercriminals. The spoof emails, messages, websites, and other tactics they use are convincing. However, we can't give up, and efforts to ensure all staff and other users of an organisations IT systems know how to spot cyberattack activities need to be ongoing.
Security awareness training solutions for end-users have been available for years. The stats from the latest DBIR, and all the news stories about successful ransomware attacks, indicate that some new thinking is required. The usecure Human Risk Management (HRM) solution is an advanced platform for raising awareness about cybersecurity threats. It takes awareness training to a level beyond other products available, whilst maintaining a simplified approach for deploying, managing, and measuring user programs.
Contact Renaissance to find out how to purchase and deploy usecure HSM. Read on for an overview of the HRM's employee-based solutions and why they are better than traditional security awareness training.
Where Traditional Security Awareness Training Falls Flat
Most security awareness training solutions focus on things like box-ticking to show that awareness training has happened, and that staff have completed it. The real focus should be on making sure that people have learned from the training, not just that they can pass a short multiple-choice test. The main failures of traditional security solutions include:
- Too focused on box ticking - as outlined above. They focus on delivering training content, tracking who has opened it, and sometimes administer simple tests. There is no tracking of whether the people have had their security awareness changed.
- Irregular training timelines - many solutions have one-hour or similar training exercises spread out over long timescales, often once a year, to update the box-ticking data. Most people do not retain information when presented in this manner. Plus, new cybersecurity attack methods and threats are appearing every week. Long gaps between training sessions increase the risks from these new attack vectors.
- Generic unfocused training - not everyone has the same gaps in their security awareness. Most traditional training is generic and has sections on all topics irrespective of a person's current knowledge. This leads to boredom and then the possibility that the material they need to engage with gets skimmed.
- Impact can’t be measured - simple multiple-choice tests are not a good way to determine if security training has raised staff awareness for the future.
- Real world responses can’t be measured - related to the above point. The simpler solutions can't test awareness using scenarios that mimic real-world attacks such as Phishing and other attack methods.
- Cybersecurity policies are omitted - many organisations have agreed cybersecurity policies, and staff at all levels may have designated responsibilities in the event of an attack. Few training solutions can track awareness of these policies and procedures in the training solution.
How usecure HRM does Security Awareness Training Better
HRM offers a full-circle solution for transforming people into a business's most robust defence against evolving threats. It promotes the idea that staff are an organisation's strongest line of defence against cyber threats, then delivers the tools needed to get them to a place where this is the case.
To make sure that employee cyber risk gets tracked continuously, the usecure HRM platform automates the following:
- Regular cyber awareness training - personalised video and interactive training programs are created for every user, with bite-sized courses and follow-up quizzes automatically sent each month. People are only sent training on topics where they are weak. This ensures that they are not bored and turned off with training that they don't need at that particular time. This targeted training across the whole organisation allows security managers to have a big picture of where there are weaknesses - providing an HRM risk evaluation for the organisation.
- Periodic Phishing attack simulations - regular phishing simulations are automatically deployed that assess user vulnerability to a range of attack techniques. Organisations can create custom phishing campaigns in minutes. These present links and other attack vectors like those used by cybercriminals, but the links do not go to any malware or sites that could damage systems or steal information. These real-world attack simulations provide a much better picture of who has absorbed the awareness training than simple tests. Plus, they provide actionable data on how many people fell for the Phishing scam to allow further training or other interventions.
- Clear policy approval process - policies are centralised in one easily accessible place. Staff get automatically notified of any updated policies they need to sign, with staff approval signatures tracked. This simplifies the task of managing policies and tracking acceptance. Freeing up admin staff for more business focused work.
- Human risk monitoring - human risk is continuously tracked, with insight-rich reporting and human risk scoring. Dig deep into training performance and Phishing trends on a dashboard.
- Dark web breach monitoring - many cybercriminals sell and exchange data about organisations on the Dark Web. This information gets used to plan and perform cyber-attacks against organisations. Continuous dark web monitoring detects when sensitive company data (e.g. usernames and passwords) has appeared on the Dark Web. It also provides insights into how they may have leaked, which feeds into future awareness training and direct cybersecurity defence responses.
Adopting HSM is Simple
Many solutions that claim to provide HSM's benefits are often daunting to set up, launch, and manage over time. HSM is different from other solutions in this respect as well. It uses an automated and simplified approach that makes deployment and admin super easy. The graphic below outlines the four-step process used to deploy HSM.
Conclusion
usecure HSM takes security awareness training to the next level. See the HSM landing page for demos and technical details. Then contact Renaissance to find out how to deploy it to your MSP clients or your organisation.

