Educating Employees About Security (Part 1)
I watched a Webinar on how to educate employees / "users" in a company. It had some data I didn't know, and a couple neat tricks I will add to my process, but mostly it was already what I do, except the way I approach it I believe is more effective and realistic. So related to that post two days ago, here's how I go about this job. Warning: this is long; I may break it up into a couple of posts.
Goal: training & educating employees / "users" about email-based malware, phishing, spyware, and rarely viruses.
Step 1. Set the right constraints. It might make for more work, but it will pay off 10x in how effective it is. Keys are to do the training like a class/lecure: 15-20 people in groups, not bigger. And since studies have shown that 80% of people "tune out" around 50 minutes into any meeting, do three one-hour "classes". Trying to do it all in three hours won't produce much improvement.
Step 2. Set up class/lectures, and the groups that will attend, for 3x 50-ish minute "lectures", training, or seminars. Take note of attendance at all. Explain that on completion of all three classes, employees will receive a certificate saying they completed the training. Be sure to tell them, and promise them it will be fun. Inform them there'll be a "quiz" at the end of the third class, and anyone scoring 90% or higher will be entered to win an iPod Nano or some other desired, inexpensive prize. That $100 for a toy prize will do wonders to make people pay attention and is worth every penny.
Step 3. Given a group and a class, focus on the next three stages:
Stage One: an overview of email and online usage, and the possible outcomes of a security breech. Note attendance, and remind that all three classes are mandatory. If they miss a class, they have to start again with the first one (unless they're not at work that day, sick, et. al.)
Stage Two: give a serious talk about the dangers of email and online security breeches, catered to the audience: tech people get the engineering take, non-tech people get a more general coverage. Field questions, and remind them about the prize contest and quiz for the third class.
Stage Three: go over examples, and let people give answers to what they should look out for. There's many ways to tell if email or online use is risky or a potential threat, so let people answer, and keep giving examples and asking "what should you do?" Near the end, give a 5-10 minute (max.) "quiz", which you can really score or not. The idea is to get people to show they learned from the class; it's only worth really scoring in case people get 60% or less of the quiz right - they'll need additional training.
[... continued in a later post ...]
Since I don't want this original work published or quoted by paid writers as Yet Another Awful (YAA) Web "article" or "news", I'm licensing this post under a under a Creative Commons Attribution-NonCommercial-ShareAlike 3.0 License.
Share and improve, but not for commercial use (that means no quotes, excerpts or copying if you're paid to write/post) and always give proper attribution to me, and anyone who improves it ("Share Alike".)
Educating Employees About Security (Part 1) by Rob Vaughn (CISSP/ISA) is licensed under the
Creative Commons Attribution-NonCommercial-ShareAlike 3.0 License.
Based on a work at robv-blog.tumblr.com.