Security awareness training content should be driven by current threat intelligence and risk levels, covering topics like social engineering, phishing recognition, password management, and insider threats.
Security Awareness Training
If we're developing content for security awareness and training, what is it that we're going to include in this training?
One of the first steps in this process is that we need to develop our training. Ultimately, a lot of these topics are going to be whatever the hottest topics are of the time, and so we're going to have to do some research to figure out what it is that we need to really watch out for. What are our risk levels, and deliver training based off of those risk levels and whatever is the highest risk at that time.
So we're going to take a look at things like news articles and blog posts, top vulnerability lists, training material that others have, and cyber security organizations out there that post this type of information. We're going to see what exactly are the hot topics and what is the content we should be delivering.
One of the main topics is going to be around social engineering. It's one of the biggest risks when it comes to our employees: somebody using social engineering to trick the employees into divulging some sort of information or doing something nefarious.
What we need to do is teach our employees about situational awareness, how they can identify that somebody is trying to use social engineering. So we're going to show different techniques, and really drive home the point that a lot of social engineering is going to be to evoke some sort of emotion, something like urgency. They're going to evoke some sort of urgency for them to perform something or do something, and that is the type of behavior that they're going to look out for.
We call it anomalous behavior, so we're looking for that anomalous behavior, things that are out of the ordinary — things that seem risky or unexpected or unintentional, things that they don't usually encounter. If they do encounter it, there should be a little warning bells going off.
A lot of social engineering comes through phishing and emails, so recognizing phishing emails and what those look like, and being able to identify them so they can ignore them or report them. A lot of companies are going to ask you to report them, either reporting them to your IT department, or maybe a lot of systems will have a little phishing button that you click on to report spam and also these phishing emails.
Other topics could include:
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →