+91 98726 60544 hello@mitstech.co Mon–Sat · 09:00–18:30 IST

Security training people do not ignore

Security By Mits Engineering Team 2 min read
Security training people do not ignore

Security awareness training exists in most organisations as an annual compliance exercise: a slide deck, a multiple-choice quiz, a completion certificate for the auditor. It reliably produces a hundred per cent completion rate and no measurable change in behaviour, because a person who watched a video in April is not more suspicious of an email in September. The exercise satisfies the requirement and misses the point.

What changes behaviour is frequency and specificity. Short, regular material — a few minutes monthly rather than an hour annually — about the attacks your organisation is actually seeing, with real examples. If your finance team is receiving invoice redirection attempts, that is the training, not a generic module about password hygiene. Using your own incidents, anonymised, is more effective than any vendor's content because people recognise the context.

Simulated phishing is the most useful tool available and the easiest to misuse. Done well, it gives you a real measure — what proportion of people click, and how many report it — and it moves both numbers over time. Done badly, it becomes a trap: unrealistic lures, public shaming of people who clicked, or a simulation about a bonus payment that makes staff distrust the company rather than the email. The purpose is to build a reporting reflex, not to catch people out.

Which is why the metric that matters is the reporting rate, not the click rate. A workforce where a quarter of people click but nearly everyone reports it within minutes is in much better shape than one where few click and nobody says anything, because the reports are what let you contain a real attack early. Make reporting one click, thank every person who does it including when it was legitimate, and never make someone feel foolish for a false alarm.

Train the roles that are actually targeted, differently. Finance staff receive payment redirection and invoice fraud. Engineers receive credential harvesting and malicious dependency lures. Executives receive convincing, well-researched impersonation. HR receives attachments purporting to be CVs. A single course for everyone addresses the average employee, who does not exist. Twenty minutes tailored to a specific function is worth more than an hour of general content.

And accept that training has a ceiling. Sufficiently convincing attacks defeat trained people, including careful ones, which is why the technical controls matter more: phishing-resistant multi-factor authentication, a payment process that requires verification through a second channel, and least-privilege access so a single compromised account is not a catastrophe. Training reduces frequency; the controls decide the consequence. Investing only in training is asking humans to be the last line of defence, which is the position every attacker is counting on.

Need help with this? Explore our Cybersecurity & Compliance services. Learn more Back to all news

Keep reading

More on Security