Effective Cybersecurity Training – Maria Bada, AwareGo
Dr. Maria Bada, a behavioral scientist for AwareGo, explains what’s required to make cybersecurity training effective.
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We're here with Maria Bada. Who's a Behavioral Science expert working with a wear go and we're going to be talking about what happens with end users in terms of security and also maybe the security people themselves and maybe we're all just driving each other nuts and some sort of circle, but Maria welcome the show Hi. Hello.
Thanks. Thanks for inviting me so you guys conducted a study and you've been looking into what goes on with both end users and also how people respond on the cyber security side. But why just give us some of the highlights of the study?
When did you guys found and what surprised you? Yes, definitely and to be honest, we had a couple of surprises there. So our goal has been providing training and awareness for Many many years so a couple of years back we started considering K.
We need to kind of identify what currently is happening. What are the needs because so many people are actually talking about how awareness training and programs like that are not effective. They're not working in the long term.
So we might kind of succeed in changing short term behaviors of employees, but that doesn't last long and we know in Psychology and Behavioral Science that that is a bit challenging and it does take time and effort. So we wanted to really kind of Review the current situation so we went back to our clients and we conducted a survey and also interviews in order to really understand their current needs whether you know, things are changing whether we see something else that we need to cover and basically just to begin with that most of our clients were mentioning the need for more personalization in training programs. So usually most companies will have one of training but it won't necessarily cover the needs of specific departments within organization or specific employees and here I will bring in the discussion of you know, employees working for HR and employees working as information security officers, for example or CEOs.
So when I talk about personalization, I really In all the levels and the needs the different needs of different employees within organizations. So we run this study. We actually collected and we had 160 participants in our survey and we run 10 interviews as well mainly with either Information Security Experts and Security Experts within companies or CEOs see those Educators.
So we kind of have a breath kind of participants there and we kind of try to identify their knowledge but also aspects such as you know, do they run it awareness raising program in their company, or if they do how often do they run that program if they don't why not? And I guess it was not a surprise to see that the majority of these organizations were running actually an awareness program and that was coming and as coming out as a strategic decision either from the kind of board level of the Season level. So they were really considering awareness as an important aspect within their organization.
However, these trainings were either running a couple times a year or I don't know once a month which is not necessarily a negative. Aspects at all and really what we are trying to do and I will talk about that a bit more is identify. What is the golden kind of solution how often or how rarely do you need to train employees to avoid security fatigue?
But apart from that we we were also interested in for example, why are they running this programs? What is them kind of goal of having and conducting ours program for employees and the main aspect there was again as a strategic decision and of course out of the need for compliance to either gdpr or other standards and best practices. And mainly what our participants mentioned as really the focus of this trainings were of course fishing fishing simulations that were running but also around passport handling sensitive data and overall.
I think the majority was talking about compliance overall as I mentioned. It was not a surprise as well that the majority of participants as I mentioned coming from different levels different expertise where very confident around understanding what sensitive data is for example that they would never use an unsecured Wi-Fi or that they could recognize a fishing email so that confidence can sometimes be problematic and here comes the first kind of surprise because out of really out of this study and really the We we conducted we saw that some of the participants they were not really able to identify a phishing email or they fell really for one of the kind of tricky questions. We had on the strength of a password and we were asking them to check the strength of their password and they some of them typed it in and the trick was they shouldn't even type the password in even if someone asks you to do that.
So we saw some really problematic behaviors in some surprises there and just to mention that when we tested our product the human risk assessment again with experts or employees from different departments. We saw an overall kind of resilience reaching maybe 70% out of hundred in really across all our threat areas. So And I guess password strength was one of them which I mentioned but that again kind of causes a question in terms of okay, how can you be so confident that you have?
You know, you have the answers you have the knowledge and of course, then you kind of show the kind of secure behavior when needed when we actually so using the human risk assessment that this is really not the case and this is really how we utilize the results from our study to really start working on developing the human risk assessment, which is something like a fishing simulation. But in we kind of use a completely different approach using fun scenarios, very relevant and personalized as I mentioned to specific employees and and really the outcome All and the results provided out of the human risk assessment can help either managers or whoever is running an organizing an awareness campaign within the company to identify who needs what in terms of training and this is why we can shape more kind of personalized approach in the programs. We we provide and that's briefly very briefly what we did and how this really fed into into our work.
How do we make the training more compelling? I think a lot of people look at the training programs and it's kind of feels like I'm going to traffic school after I got a speeding ticket and and it's just not quite all that engaging everybody's just trying to get through it and go back to their regular jobs. So how do we make this something that more end users are going to look at and say yeah that was interesting or helpful.
Yes, yes spot on this is the case and I mentioned already security fatigue. We can't really push employees to take the trainings unless we follow kind of a more mandatory approach which many organizations do. Yeah, as I mentioned such trainings need to find the golden balance how often or how rarely do you need to provide them?
They need to be personalized. They need to be relevant. So I can't really have scenarios that have nothing to do with a certain employees every day job.
So if they're not relevant and related to what I'm doing, of course, I will not pay attention and many actually of the experts we spoke to or who participated in our study really ignore these trainings because they expect you know, they they know all that they've had so many trainings in the past. They work in cyber security their information security offices. So they pay no attention because usually these trainings provide trivial information basic information.
Usually they're targeting employees who have no experience inside security. So this is really what we're trying to change provide that kind of in Incentive and motivation for employees to actually participate and pay attention. And for that I think where go has managed that for years out of the very funny and short videos whether being used in in the training programs, but now as I said with the human risk assessment, we have another tool to make trainings even more personalized and kind of Target that element kind of motivate and kind of gain attention of employees.
I think this is what everyone is struggling with in this area. They are the first line of defense but we also need cyber security people that are trained. We have a chronic shortage.
What is the real challenging kind of getting more people trained on cyber security to become a cyber security professional. It seems like there's a large uphill curve. Can we kind of reduce that?
Yes, very good question. And there's so many discussions around this and so many different paths that people can follow to actually go into cybersecurity and starting from being an academic or something from doing something completely relevant and then moving in the cybersecurity. I think the discussions now are due to that skills shortage go towards.
Okay, how can we as you said, how can we shorten that path of how can we provide skills and trainings and maybe certifications that will be enough at least for specific positions just to cover that skills Gap and take it from there. So I know that especially for example in the UK there are discussions within the government to actually kind of progress into that. How could this look like, but also for me it's how do you attract young people and Essentially girls and women in kind of joining these, you know the area of cybersecurity and this profession because again, there are challenges there are many problematic issues around this and the amount of work the potential or heavy load of work in this professions, but I think at an international level there is now, you know, we realizing there is a gap and without people to cover the needs we will be in serious troubles.
So I think we will be seeing different Pathways shorter Pathways of people can follow definitely so I don't necessarily need to have a four-year degree to get into the cyber security business per se but we need to find some way to streamline this training for folks. That's easy. We consumed That we're aiming for.
Yeah, yeah, I agree. Definitely. I mean I know that people who that have, you know masters degrees phds.
And the problem is that these people who have the experience and knowledge and of course certificates, they will reach or they will Target high positions, but still we need people who will do programming who will do, you know specific tasks that a manager wouldn't do or CEO. So again, yeah. Definitely we need to find a way that will accomplish that as I said will bring young people into into this professions.
Speaking in diversity. It seems like part of the issue is that it's not necessarily that people or trying to figure out who's gonna get what job based on race Creed or color. It just seems like they're so busy fighting the fight that they don't have time to turn around and train then other people who might come and help them and then it becomes this kind of vicious cycle.
So how do we get the folks that have the expertise today to take a minute or take a breath and help train the next generation of folks that are gonna hopefully lighten the load Yeah, yeah that again goes back to the demand in the market and how organizations are allocating or not funds for positions in information security and cyber security. So if you have one Information security officer in your company and they have to do everything and in many cases in many cases. They actually do privacy compliance.
They do everything. There's no time to train others. There's really no time.
So unless you take and you recruit more people, even if they're Junior in this positions to cover some of the of that heavy load I don't think there is a way so we I think what is coming in the next years as I said is I expect to see Junior positions. Bringing in people and then kind of following different Pathways either providing them training to become a privacy expert or a security expert or kind of in order to cover some of that demand and need but to my mind because of the work I'm doing with the where go and around small and mid demanded prices. The challenge is with them because they usually won't have the resources to do that.
So what do we do there? And that's that's really a challenge that we're already facing. Yes.
Um as we think through this whole problem do you think also we need to train people who aren't quote unquote Security Experts. It seems like we're relying more on it operations people that execute some of the security policies application developers. We talk about shifting left.
And so the whole cybersecurity training education thing perhaps needs to be more pervasive than we think about it today. Yes, totally totally agree. but it's not just as we said the experts we need to avoid at least have a certain level of a firewall a human firewall of Coming from all employees.
So I think at all levels users and employees should have a basic understanding of how to avoid the fishing attack for example, and not to open links not open attachments. But to do that you still need to kind of be aware of the culture of your organization the level of resilience of your employees the potential risks you're facing and to be honest many companies don't really have that knowledge and understanding of their own organizational culture. So I think that's one of the reasons why we work towards developing the human risk assessment which you can use as a standalone tool to run that kind of risk threat assessment and understanding the resilience levels of your employees and then kind of Target that so for me, it's kind of I'm seeing cyber security as Holistic kind of matter it's not just about the training of information security officer.
It's the training of all employees, but also the entire culture of an organization because that can impact so much. So yeah totally agree with your points. So what's your best advice to folks right now who are contemplating all this?
It's kind of a struggle and deals with as much the technology is the emotional components of all the people involved Security Professionals. Clearly don't think like everybody else in the world and that's probably a good thing. But how do we kind of look at this from every behavioral perspective?
Yes, so as I mentioned for me the most important part is kind of looking back at your at the culture the organizational culture focus on employees be aware of the potential risks. We see a lot of denial coming from certain organizations. For example that they won't be a target of Iran somewhere attack or you know, they won't face these types of attacks because there are small company they you know, they're not that important for example, or they're not a big player but we see that for example ransomware attacks are heating smes as well or you know individual users so we kind of need to Pay a bit more attention and take it the step of the time like there's no need to panic.
So there is advice out there. I know that the advice provided is most of the times not coordinated and not really kind of presented in one location where people know where to look for that information. So you have to kind of dig out all that but with a bit of effort you can at least take Basic measures to protect an organization or even if you are an individual user your your kind of online presence.
But yeah, I mean I think for me it's all about understanding that you could be a victim and really take small steps in order to protect your online presence your accounts or even your entire organization and avoid extreme situations because we have many cases now of you know, you you must have heard of zero trust the approach that many organizations are taking and if employees actually fail some of the fishing simulations once or twice, I think that they are out they will be fired. So I think for me that is a very extreme situation you're posting employees away with the Tactical like that. So yeah, we need to really and this is what we're doing.
We're really trying to understand how we can shape behaviors in the long term because it's successful simulation once a year will not really Prove that my employees are resilient. So all right folks you heard it here cybersecurity training is fundamental, but the emphasis needs to be on the word perhaps fun and make an entertaining. Hey Maria.
Thanks for being on the show. Thank you so much. Thank you.
All right back to you guys in the studio.