In simple terms, how to go about designing a cyber security awareness program for an organisation?

Step 01 – Identify target groups

The first step is to identify specific target groups based on their job roles and likely exposure to cyber attacks. For eg., the awareness needs will be different for employees in finance & accounts compared to software engineers.

Step 02 – Assess Risks and define goals

Assess your company’s security risks, main threats to business interruption and regulatory requirements. This will already be a part of your internal policies and procedures.

Clearly define the behaviour goals in identified target groups aligned to their respective job roles. 

Step 03 – Build the core training modules

Create a universal module for all target groups where the behaviour goals are common (eg. Data handling for privacy and confidentiality, Multi-factor authentication, password policies)

Create target group based curriculum, training modules and delivery mechanisms for best results (eg. train developers on software development secure coding practices and finance guys on wire frauds)

It is very important to ensure the training modules are not lengthy and boring. Keep the modules short, crisp and informative to create a micro-learning culture within the organisation.

Step 04 – Engage learners during training

Use short videos, interactive quizzes or games to engage the learners during training to enhance the learning for best results.

Step 05 – Training assessments and continual improvements

Run tests and simulations to measure the progress on security awareness

Ensure upgrading the training modules to make it relevant to real-time scenarios to continuously blend the culture to adapt to securing against the present trend of attacks.

Scroll to Top