Cybersecurity blog Cybersecurity blog
Is Security Awareness Training getting outdated?
Facebook Twitter LinkedIn

Is Security Awareness Training getting outdated?

blank
Ragnar Sigurðsson
4 min read ∙ May 2, 2019
blank
blank

If you are a CISO or a DPO, chances are you’re responsible for security awareness training. But you’re not a teacher. Am I right?

So why are you responsible for training, when it is your responsibility to protect the company’s data?

The truth is, hackers, like most people, tend to choose the path of least resistance when they compromise the security of organisations. This path is very often through people, and cyber security threats are exploited through human behavior. It is usually the uninformed employees that lead to the breaches. Unfortunately human behavior is predictable and we are thus vulnerable to attacks. The good news is that through training and awareness the risk from these threats can be reduced. 

Back to the training part. What you need to understand is that some of your employees are lazy. They might recognize that security awareness training is essential, but they want it to be over as fast as possible. Employees don’t want to struggle to read and digest boring security awareness text. They want to be able to understand it quickly and efficiently and continue with their day-to-day job. Just because they want to absorb this content quickly doesn’t mean quick training programs are ineffective. A video, however, is a tool that can take your security awareness training from boring to exciting. 30 seconds of video is capable of conveying much more information than any text. 

Videos have been used for marketing purposes for some time now. According to HubSpot, video is here to stay [1]. YouTube is also the world’s second largest search engine, which supports that. According to a report from HubSpot Research, 54% of consumers want to see videos from brands they support. [1]

blank

 

 So it’s strange, then, that some people don’t understand how useful it is to include videos in their training program. In the same way, people use images to separate points and make text easier to understand, people use video to hold people’s attention. Especially when an employee needs to go through several security awareness topics. (Remember I said some employees are lazy when it comes to security training.) When people are presented with a wall of text, the first thing they will do is try to avoid it and find excuses for not participating in the training. Even if your security study material isn’t as long as in other companies, if it looks too difficult to read, they are not going to bother. Even though the actual study material is the same, which of the two pieces of training below would you like to take part in?

Example 1: Everyone makes mistakes. Even as simple as forgetting to shut the faucet… or sending an email to the wrong person. But it‘s what you do next that matters. If you lose, or leak classified information. It is your responsibility to report it, even though it was an accident or not even your responsibility… By not reporting the leak your company might be liable to fines or get other people into trouble. Be extra careful when working with personal information even if only one record leaks out it can have severe consequences for that individual and can lead to hefty fines for the company.

Example 2:

 

The video is infinitely easier to consume and comprehend. According to HubSpot, video content was the most memorable (43%) in comparison to text (18%) and images (36%). [1]

blank

 This is good news because you want people to remember the training material and be able to put their training into action. The attention competition We all know there is a massive competition for peoples attention today. Just because a video is easy to watch, it doesn’t mean people will. But, the shorter the video training and by using effective storytelling, you will get more people to complete the whole training versus just a few seconds.  

So why aren’t you using video?

blank
Ragnar Sigurðsson
4 min read ∙ May 2, 2019

Become cyber secure

You and your employees are going to love AwareGO. It’s a modern, cloud-based system for managing human risk, from assessment to remediation. We’ve made it super easy — schedule your first assessment or training in minutes.

Get started for free and give it a go right now.

You’ll love the way AwareGO can fit into your existing infrastructure. Our robust APIs, widgets, and content available in SCORM format make sure that the integration is seamless. We also integrate with Active Directory, Google Workspace, and popular tools like Slack and Teams.

Contact us and our experts will recommend the best way to integrate.

Upgrade your cybersecurity business by adding human risk management to your existing portfolio of services. Increase your deal size by leveraging Human Risk Assessment or offering Security Awareness Training to your current customers and creating a new revenue stream.

Contact us to become an AwareGO partner, and we will support you every step of the way.

Join top companies worldwide in the mission to make workplaces cyber-safe

Get started free
blank blank blank blank blank blank blank blank blank blank