
Step 01 – Identify target groups
The first step is to identify specific target groups based on their job roles and likely exposure to cyber attacks. For eg., the awareness needs will be different for employees in finance & accounts compared to software engineers.
Step 02 – Assess Risks and define goals
Assess your company’s security risks, main threats to business interruption and regulatory requirements. This will already be a part of your internal policies and procedures.
Clearly define the behaviour goals in identified target groups aligned to their respective job roles.
Step 03 – Build the core training modules
Create a universal module for all target groups where the behaviour goals are common (eg. Data handling for privacy and confidentiality, Multi-factor authentication, password policies)
Create target group based curriculum, training modules and delivery mechanisms for best results (eg. train developers on software development secure coding practices and finance guys on wire frauds)
It is very important to ensure the training modules are not lengthy and boring. Keep the modules short, crisp and informative to create a micro-learning culture within the organisation.
Step 04 – Engage learners during training
Use short videos, interactive quizzes or games to engage the learners during training to enhance the learning for best results.
Step 05 – Training assessments and continual improvements
Run tests and simulations to measure the progress on security awareness
Ensure upgrading the training modules to make it relevant to real-time scenarios to continuously blend the culture to adapt to securing against the present trend of attacks.
