Unpopular opinion: mandatory security awareness training is mostly pointless. Employees just retake the quiz until they get the right answer. Better solutions out there?

like
Posting as :
works at
You are currently posting as works at

The problem is that mandatory security awareness training is something that’s required from a legal / risk / compliance perspective. So there’s no getting rid of the exercise itself.

But there’s nothing really mandating HOW you conduct the training itself. There are options ranging to gamification of the results themselves (showing recognition centrally on those who pass those activities on the first attempt, for instance), as well as more punitive measures (click on a phishing exercise link three times, you’re fired).

The most effective method is likely in the middle, with executive leadership setting the right “tone at the top” - if leadership only looks at security awareness training as a compliance activity (most do), it will never be elevated above other “check the box” compliance activities (e.g., HIPAA responsibilities in healthcare, AML/KYC for banking, etc.)

I don’t know about that. I used to run the simulations as part of my side duties. Awareness training for a few orgs help over time. How effective give your training is usually tied to relevance via customization, engagement, and quality. How to measure effectiveness you correlate the click and open metrics over time too. The human really is the weakest link

Related Posts

What kinda hike should I be expecting/asking at KPMG for a new job for compliance and reporting. Currently got two years of experience at EY with pay below 5lpa.

like

Is there any vacancy in pepsico at bangalore location?

like

all - qq I’m currently on an LoA, stuck in India due to personal reasons (on F1 OPT) right now. I have a lot of interest in teaching kids online (coding and such), could I do non contractual job teaching coding online while in India with an indian firm?

like

So I've had 2 hiring managers and several recruiters from Amazon reach out to me about applying for some open positions with the company (android). I completed the coding assessment and now they want me to go through a round of 5 hour interviews next week. Is there a good chance I'll be hired if engineering managers are reaching out to me? I'm really not sure how badly I want to work for them and I don't want to be laid off months after being hired on. Anyone know what Amazon hiring is like?

like

What is the maximum salary Wipro can offer to 4 YOE. Designation - Consultant Wipro

like
Post Gif
like

EY advisory laptops - do you get to choose a model or is one just randomly assigned to you?

like

Late stage analyst 1 at a mid-market heavy TMT focused M&A boutique in London. Keen to increase exit opps and realise it may be worth trying to lateral to a BB / name brand. Any opinions / advice on achievability? If low, what’s the best move here.

like

If I resign from IBM , within 11months 15days what will happen?

like

What should I be considering when evaluating a business analyst role? Are these more accounting than finance, FP&A, or does it change by company?

like

How much do mid-level sales people do in SaaS? (Base Salary and commission structure)

like

I’m in a little of a pickle but a good one. Offer A. Established “start up” doing well financially and projected to hit profitability. 130k base. Stocks offered, unlimited PTO, and 70% Medical covered. Offer B. Is at a business much larger…90k salary with 10% bonus and generous stock offering. Titles are different which is why the pay is much different. I know some may think it is a no brainer but offer A allows me to grow the department ground up whereas offer B id be apart of to just different

like

Not for Just FAANG but also for my personal identification a software engineer. What is expected from an 8 yr experienced professional in IT? I think i am falling short of industry standards while just working on office tasks.

like

What’s the standard RTO (return to office) plan for MBB as of now?

like

I have a valid coe and visa of Japan how to search jobs in Japan from India

like

I’m two years into my role and I’m not having any luck landing new clients. I know wealthy people but I have getting trouble getting meetings because I’m too young. I want to partner with a senior....

like

Just me here hoping that slack never adds the “read” notification on messages.

likefunnysmart

I have joined a company on 4th Feb, through consultancy on contract to hire basis.
I only received the job offer letter from the consultancy, but no Appointment Letter is given yet.
So since it's 10-15 day, since I joined. Can I leave this company, since I've got a better offer, with my suitable location.
PS: I have also received the laptop, but didn't login or do anything yet.
Please help me, can I still leave the company? And return the laptop to them. Or I have to continue here itself?

like

Everyone who I want to like me or to hangout with doesn’t respond to my texts or tells me they are too busy. This weekend I reached out to 12 people to see if they wanted to grab coffee or a drink or go for a walk. The number of people who just didn’t respond astounded me. I ended up eating dinner in bed by myself and getting brunch on my own.

The only people who reach out to me, I don’t want to hangout with. I don’t have the same interests as them and have to try really hard… cont below

like

Interviewing with a recruiting firm. What is an “normal” base salary? TIA

like

Additional Posts in Cyber Security Bowl

What’s a good taxonomy for defining requirements for logging & monitoring? (i.e., apps, db, infra, etc.)

likefunny

Is there a demand for privacy professionals? Been seeing this discussed more and more recently

like

As more and more companies institute a work from home policy, I think it will gradually become the norm. As a 28 year old man who wants to settle down soon, which city would you recommend I look into, assuming me and my partner can work from home? I work in Cybersecurity so would prefer to be closer to the jobs in my field without having to live in the same city.

like
like

CohnReznick hiring for cyber/tech risk/privacy team. Looking for seniors and managers. Anyone interested?

funnylike

Currently working in an IT audit role, what is the best way to transition into cyber ?

like

CCSP (cloud security certification) is it worth to do ?

like
like

Anyone work in KPMG Cyber doing IR and willing to chat? 😊

like

How much does Deloitte pay for cybersecurity or devops senior Deloitte roles

like

Hey all, I have been working in Identity and access management space at EY for past 4 years. Need help with understanding best exit opportunities?

AWS Cloud question- what the difference between an SCP and IAM? Thanks in advance

like

New to the U.S., is the Healthcare Industry (via HIPAA), the only industry in the U.S. that legally mandates having a designated Privacy Officer? So for example, although GLBA has obvious privacy requirements, unlike with healthcare, financial institutions in the U.S. are not mandated by law to have a designated Privacy Officer?

like

Anyone familiar with Istari-Global and their collective of cyber risk companies? What’s their perception in the market? Opportunity to join US team. Thanks!

like

Anyone in a FAANG looking for a cyber manager. DM me please! (Generalist - Focus on governance, compliance, risk and strategy)

like

is CRISC worth it? dont see it coming up as much as others

like

Can anyone recommend a good book/materials to prep for the CIPP/CIPM? 🙏🏽

Message me if you need a referral to PwC cybersecurity, financial crimes, or regulations. Please no noobs. Only experienced professionals with at least 1 YOE

likefunny

Currently stuck in risk but interested in Cyber. Have done one related engagement from a regulatory perspective. But a lot of posts here making me think it’s harder to break into than I expected (non-technical background). If you had a six sigma green belt / supply chain degree/exp., would you still go through the effort of going into Cyber or take easy risk money being offered / easier transition back to supply chain? 2-3 YOE and trying to decide career course, any advice highly appreciated

like

Any recommended study material for CIPP and/or CIPM (still debating the two)?

New to Fishbowl?

Download the Fishbowl app to
unlock all discussions on Fishbowl.
That was just a preview…
Sign Up to see all discussions
  • Discover what it’s like to work at companies from real professionals
  • Get candid advice from people in your field in a safe space
  • Chat and network with other professionals in your field
Sign up in seconds to unlock all discussions on Fishbowl.

Already a user?
Login here

Share

Embed this post

Copy and paste embed code on your site

Preview

Download the
Fishbowl app

See what’s happening in your industry
from the palm of your hand.

A phone with Fishbowl app

Scan your QR code to download
Fishbowl app on your mobile

Download app

Sign up for free to view this conversation on Fishbowl

By continuing you agree to Terms of Use and Privacy Policy

Already have an account? Log in

Sign up for free to continue using Fishbowl

By continuing you agree to Terms of Use(New) and Privacy Policy(New)
Messaging rates may apply

Already have an account? Log in

For account settings, visit Fishbowl on Desktop Browser or

General

Legal