Security awareness is a critical component of organizational risk reduction, encompassing far more than formal training alone. Policies, communications, simulations, and consistent IT practices all play a role in building a security-conscious workforce.
Security Awareness
Creating security awareness amongst the people of an organization is one of the most critical parts of reducing risk.
One thing we should understand is that there is a difference between awareness and training. What the goal of security training is set out to do is to create awareness. Awareness is the idea that we are aware of our surroundings, aware of security hazards, aware of how we should be conducting business to reduce risk. We should make the people of an organization aware of security risks that are out there and what they can do to avoid those risks.
It doesn't have to be through training. Training is one of the ways that we create security awareness. In fact, it's one of the primary ways we create security awareness, but it's not the only way that we create awareness.
In addition to training, we can create awareness through the policies that we have. Perhaps what we do is we require our employees to be able to read these policies and sign off on them, that there's some sort of agreeing to these particular policies. Of course, we also have the employee handbooks, which can serve as a similar type of purpose. They can read through those and agree to the employee handbook, and then they're agreeing to carry out those security principles, and that's creating awareness.
We could also send extra emails, especially if there's some sort of active campaign or phishing that's going on, to make sure that people are not falling for those phishing campaigns.
There's also meetings. I've announced at meetings specific security concerns or different aspects to security. I've announced that at meetings to create that awareness.
I've also run simulations. For instance, we can run phishing campaigns, false phishing, to see and test people to see if they're falling for those phishing campaigns that they learn about in training.
We could also create some gamification. There's some systems out there that I've used to create gamification or contests. It's great to see people participate in different contests that you can put out there. For instance, one of the contests that I created was a password contest: who could create secure passwords? So I would put that challenge out there, and then we'd do some testing against passwords and then see who would win those contests. And it really got competitive and it was great.
You can just let people know in person, especially if there's a particular person that's continually struggling with security risks, maybe falling for those phishing campaigns that you're testing them on. So we can test them, and then maybe we need to have a follow-up in person with some of them.
There's also different messaging platforms that a company uses to communicate. Really it's any communication avenue that a company does on a regular basis, like the meeting or email or messaging platforms, that we could utilize to get the word out and create awareness around either active campaigns that are happening or other security awareness tips that you want them to be aware of.
One of the questions that we have is, who are we targeting? And yes, definitely the employees of the company, possibly contractors. There's individual contractors, we call them 1099s, and then there's other contracts where we work with other businesses. And so whether we're working with individuals or a business, we want them to be secure as well, especially if they're in our systems. And there might be other stakeholders, partners, users that utilize our systems, or could benefit or could help us mitigate risk by including them in some of this awareness training and these other methods of creating security awareness.
Now, one thing that I've noticed is that many times IT departments will have a double standard. They'll set out password standards, maybe it's a certain length or certain guidelines that employees have to follow to create their passwords. But then what they do, and this would be an example of a terrible password, is they'll hand them a piece of equipment and they've already set it up with a generic password for the first time that user logs in, and then makes that user change that password.
Well, this is not only a missed opportunity, but it really sets the wrong tone for everything to come. Because number one, a lot of those users will actually just accept or use that same password to log into the system and they won't change it. But another even bigger concern is that you're giving them an example of what a password looks like, and it's a terrible password. And this is really problematic.
And the reason why IT departments do this is so that way it simplifies the setup process and makes it easier for them to onboard employees. But it doesn't create security awareness. In fact, it does just the opposite, it degrades our effort on creating security awareness. And so what we need to do is we need to make sure it's a unique password, it's a complex password, something that's not easily get ible, that demonstrates whatever our policies are trying to set users to have good passwords, that it represents that. So make sure whatever you're doing in your IT departments that you are not creating this double standard and degrading from this security awareness that you're trying to promote.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →