thecybersecurityreview

CYBERSECURITY REVIEW8 MARCH - 2022IN MY OPINIONHOW TO WEAVE SECURITY INTO THE CULTURE OF THE COMPANY?Speak with a group of CISO's after hours and you will inevitably hear war stories about how their state of the art defenses were bypassed because a user in [insert non-technical department] fell for a phishing email. These stories naturally turn to quips about how their users know nothing and are their biggest risk. In that statement there is one thing that is true; users are your biggest risk... But that is not their fault. So how come this age old anecdote hasn't seemed to evolve very much over the years?User Training & Awareness hit the market over a decade ago as the silver bullet for this problem. For a fairly low cost and a little effort, security teams could now pick training materials, send phishing emails, schedule new hire and yearly training, and automatically reprimand users for failing a campaign or not taking a required training. By Chris Holden, CISO, Crum & Forster
< Page 7 | Page 9 >