THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.


Hubert Heng, Director Transport Cyber Security/ Division Manager ICS Cybersecurity, ST Engineering Info-Security Pte. Ltd.How do you prevent bad guys from entering your house? Typically, you will invest in a reputable brand of lock that is tested and proven secure. But does it prevent a bad guy from gaining access? No. It just takes a bad guy a longer time to pick or break the lock to enter.
Same for Enterprises, historically security is always focused on prevention. Large organizations will invest in 101 Security Solutions to ensure that their network and system are secure from bad actors, but is it sufficient? In the current day’s context, a locked door is barely a deterrent; you still need to lock your door, but that needs to be reinforced with detection, alerting, and remediation. AI technologies nowadays have matured in leaps and bounds, but when it comes to cybersecurity detection, alerting and remediation, human is still of utmost importance. It will always be a human response to assess any incident alert to identify the next course of action.
Sighting sources from isaca.org and sans.org, “human is the weakest link”. According to Fortra’s 2022 Pen Testing report, Phishing, Misconfiguration, and poor passwords are still the top few common security concerns, which is a result of Humans being the weakest link.
This is where Staff Cyber Security Education comes into play
Cyber adversaries continually identify potential vulnerabilities within an organization, underscoring the critical need for information security teams to transform these weak points into areas of resilience. To initiate this process, these teams need to adopt a people-centric approach to cybersecurity education. Training must hold significance for all end users, and customized education should be directed toward those individuals most susceptible to attacks.
Achieving this involves a focused effort on delivering pertinent information to the right individuals at the right time. Effective training programs for adult learners incorporate interactivity, reinforcement, and opportunities to practice new skills—principles grounded in proven learning science that yield tangible progress and knowledge retention.
“One illustrative method of educating employees about phishing is to implement a phishing campaign in conjunction with computer-based security awareness training modules. This approach allows users to engage in interactive, hands-on learning. “
One illustrative method of educating employees about phishing is to implement a phishing campaign in conjunction with computer-based security awareness training modules. This approach allows users to engage in interactive, hands-on learning. When a staff member clicks on a phishing email link, they are redirected to an e-learning platform where identification techniques are imparted, and they must accurately answer a quiz to exit. The process of making a mistake, followed by correction, stands out as one of the most potent ways to internalize and retain information.
Continuous Training approach
The Continuous Training strategy underscores aspects frequently overlooked in the implementation of security awareness training initiatives, namely, the importance of frequency, flexibility, and customization. Mere adherence to a training schedule once or twice annually for compliance purposes proves insufficient. This routine fails to integrate cybersecurity into the daily routine, preventing end users from adopting cybersecurity best practices as part of their everyday habits.
Instead, advocate for the consistent delivery of compact, targeted training modules that address specific topics within a brief timeframe. Employing a computer-based training platform, one that enables agencies to provide education frequently and on-demand from virtually any location serves to enhance concentration and alleviate the effects of training fatigue.
Recognizing cybersecurity skills as fundamental life skills extending beyond the workplace is imperative. Information security teams aspiring to enlist user contributions to an organization's broader cybersecurity infrastructure must actively engage in building knowledge and enhancing security postures incrementally, day by day. This approach and sustained efforts are pivotal in establishing the most resilient last line of defense.