TechKnowSurge
NIST NICE K0638 NIST 800-53 AT-2 CompTIA Security+ 5.6 ISC2 CISSP 1.12 NIST 800-53 IA-5 NIST NICE K0830 NIST CSF PR.AT-01
VideoSecurityFree

Awareness

Security awareness is a critical component of organizational risk reduction, encompassing far more than formal training alone. Policies, communications, simulations, and consistent IT practices all play a role in building a security-conscious workforce.

Complete this video to capture a CTF flag worth 1 point.

About this video

Security awareness is one of the most effective mechanisms for reducing organizational risk, and it is broader than training alone. While structured training is a primary method for building awareness, organizations can also use written policies, employee handbooks, internal emails, meeting announcements, and messaging platforms to keep security top of mind. The goal across all of these channels is the same: ensuring that employees and other personnel understand the risks they face and know how to respond appropriately. The audience for security awareness efforts extends beyond full-time employees. Contractors, third-party vendors, and other stakeholders who access organizational systems should be included in awareness initiatives wherever possible, since their behavior directly affects the organization's overall risk posture. Tactics such as simulated phishing campaigns, gamified security contests, and one-on-one follow-up with individuals who show repeated vulnerabilities can significantly strengthen the human layer of an organization's defenses. Consistency between policy and practice is essential. A common failure point occurs when IT departments set strict password requirements for employees but hand out new equipment with weak, generic default passwords during onboarding. This approach not only creates a missed opportunity to model good security behavior but actively contradicts the standards the organization is trying to enforce. Every touchpoint, including the very first login experience, should reflect and reinforce the security standards the organization expects its people to uphold.

What you'll learn

What's covered

Security Awareness

Aligned to

NIST NICE
K0638 Knowledge of security awareness programs
K0830 Knowledge of password policies and procedures
NIST 800-53
AT-2 Literacy Training and Awareness
IA-5 Authenticator Management
CompTIA Security+
5.6 Given a scenario, implement security awareness practices.
ISC2 CISSP
1.12 Establish and maintain a security awareness, education, and training program
NIST CSF
PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind.

Key terms

Security Awareness
The ongoing effort to ensure employees understand security policies, recognize threats, and apply safe behaviors through multiple communication methods beyond formal training alone.
Security Policy
A formal document that defines an organization's security goals, rules, and responsibilities.
Phishing
A social engineering attack that uses deceptive emails or messages to trick users into revealing sensitive information.
Social Engineering
A manipulation technique that exploits human psychology to trick individuals into revealing confidential information.
Default Password
A generic, preset password assigned to a device or account during setup that has not been changed by the user, representing a significant security vulnerability.
Security Training
A structured program designed to educate employees and stakeholders on security principles, threats, and safe practices to build organizational security awareness.

Topics

Security Awareness Security Training Organizational Security Password Management Cybersecurity Risk Reduction

Transcript

Awareness Is Not the Same as Training

Creating security awareness amongst the people of an organization is one of the most critical parts of reducing risk.

One thing we should understand is that there is a difference between awareness and training. What the goal of security training is set out to do is to create awareness. Awareness is the idea that we are aware of our surroundings, aware of security hazards, aware of how we should be conducting business to reduce risk. We should make the people of an organization aware of security risks that are out there and what they can do to avoid those risks.

It doesn't have to be through training. Training is one of the ways that we create security awareness. In fact, it's one of the primary ways we create security awareness, but it's not the only way that we create awareness.

Other Ways to Create Awareness

In addition to training, we can create awareness through the policies that we have. Perhaps what we do is we require our employees to be able to read these policies and sign off on them, that there's some sort of agreeing to these particular policies. Of course, we also have the employee handbooks, which can serve as a similar type of purpose. They can read through those and agree to the employee handbook, and then they're agreeing to carry out those security principles, and that's creating awareness.

We could also send extra emails, especially if there's some sort of active campaign or phishing that's going on, to make sure that people are not falling for those phishing campaigns.

There's also meetings. I've announced at meetings specific security concerns or different aspects to security. I've announced that at meetings to create that awareness.

I've also run simulations. For instance, we can run phishing campaigns, false phishing, to see and test people to see if they're falling for those phishing campaigns that they learn about in training.

We could also create some gamification. There's some systems out there that I've used to create gamification or contests. It's great to see people participate in different contests that you can put out there. For instance, one of the contests that I created was a password contest: who could create secure passwords? So I would put that challenge out there, and then we'd do some testing against passwords and then see who would win those contests. And it really got competitive and it was great.

You can just let people know in person, especially if there's a particular person that's continually struggling with security risks, maybe falling for those phishing campaigns that you're testing them on. So we can test them, and then maybe we need to have a follow-up in person with some of them.

There's also different messaging platforms that a company uses to communicate. Really it's any communication avenue that a company does on a regular basis, like the meeting or email or messaging platforms, that we could utilize to get the word out and create awareness around either active campaigns that are happening or other security awareness tips that you want them to be aware of.

Who Are We Targeting?

One of the questions that we have is, who are we targeting? And yes, definitely the employees of the company, possibly contractors. There's individual contractors, we call them 1099s, and then there's other contracts where we work with other businesses. And so whether we're working with individuals or a business, we want them to be secure as well, especially if they're in our systems. And there might be other stakeholders, partners, users that utilize our systems, or could benefit or could help us mitigate risk by including them in some of this awareness training and these other methods of creating security awareness.

The IT Department Double Standard

Now, one thing that I've noticed is that many times IT departments will have a double standard. They'll set out password standards, maybe it's a certain length or certain guidelines that employees have to follow to create their passwords. But then what they do, and this would be an example of a terrible password, is they'll hand them a piece of equipment and they've already set it up with a generic password for the first time that user logs in, and then makes that user change that password.

Well, this is not only a missed opportunity, but it really sets the wrong tone for everything to come. Because number one, a lot of those users will actually just accept or use that same password to log into the system and they won't change it. But another even bigger concern is that you're giving them an example of what a password looks like, and it's a terrible password. And this is really problematic.

And the reason why IT departments do this is so that way it simplifies the setup process and makes it easier for them to onboard employees. But it doesn't create security awareness. In fact, it does just the opposite, it degrades our effort on creating security awareness. And so what we need to do is we need to make sure it's a unique password, it's a complex password, something that's not easily get ible, that demonstrates whatever our policies are trying to set users to have good passwords, that it represents that. So make sure whatever you're doing in your IT departments that you are not creating this double standard and degrading from this security awareness that you're trying to promote.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →