• Sacramento Region Managed IT and Cloud Services
  • 1 ‪(916) 905-0874
  • [email protected]
locutis_logolocutis_logolocutis_logolocutis_logo
  • HelpDesk
    • Business Tech Support in Sacramento
    • Mobile Computer Repair
    • Virtual CIO
    • Disaster Recovery
    • Recommended Technology Platform
  • Reputation
    • Listings Management
    • Listings Distribution
    • Customer Voice
    • Reputation Management
    • Social Marketing
    • Advertising Intelligence
  • LocalAds
    • Targeted Video & OTT Ads
    • Targeted Display Ads
    • Phone Call Leads
    • Store Visits
    • Form Fill Leads
    • Weather Based Advertising
  • Cloud
    • Web Site Design
      • E-Commerce Development
      • Recent Projects
    • Hosting
      • Managed Hosting
      • Managed E-Mail
      • Self Managed Hosting
      • Servers
      • Business E-Mail
    • Domains
      • Register Domain
      • Transfer Domain
    • SSL Certificates
  • About Us
    • Industries
      • Startup Companies
      • Non Profit Organizations
      • Food Services
    • All Legal Agreements
      • Privacy Policy
      • Terms Of Service
      • Refund Policy
  • Get Help
    • Support Portal
    • Submit A Ticket
    • Remote Support Session
    • By Appointment
    • By Phone
    • By E-Mail
    • Get A Refund
  • Login
    • SoLoMo
    • CloudFilter Quarantine
    • XtraMail
    • CloudMail
    • Plesk WebMail
    • Endpoint Manager
    • Plesk Hosting Panel
    • Domain Control
  • Radar
✕
Free photos of Computer
Home Security: Why You Should Put IoT Devices on a Guest Wi-Fi Network
August 15, 2022
Free illustrations of Cyber
Did You Just Receive a Text from Yourself? Learn What Smishing Scams to Expect
August 25, 2022

How Often Do You Need to Train Employees on Cybersecurity Awareness?

Free illustrations of Security

You’ve completed your annual phishing training. This includes teaching employees how to spot phishing emails. You’re feeling good about it. That is until about 5-6 months later. Your company suffers a costly ransomware infection due to a click on a phishing link.

You wonder why you seem to need to train on the same information every year. But you still suffer from security incidents. The problem is that you’re not training your employees often enough.

People can’t change behaviors if training isn’t reinforced. They can also easily forget what they’ve learned after several months go by.

So, how often is often enough to improve your team’s cybersecurity awareness? It turns out that training every four months is the “sweet spot.” This is when you see more consistent results in your IT security.

Why Is Cybersecurity Awareness Training Each 4-Months Recommended?

So, where does this four-month recommendation come from? There was a study presented at the USENIX SOUPS security conference recently. It looked at users’ ability to detect phishing emails versus training frequency. It looked at training on phishing awareness and IT security.

Employees took phishing identification tests at several different time increments:

  • 4-months
  • 6-months
  • 8-months
  • 10-months
  • 12-months

The study found that four months after their training scores were good. Employees were still able to accurately identify and avoid clicking on phishing emails. But after 6-months, their scores started to get worse. Scores continued to decline the more months that passed after their initial training.

To keep employees well prepared, they need training and refreshers on security awareness. This will help them to act as a positive agent in your cybersecurity strategy.

Tips on What & How to Train Employees to Develop a Cybersecure Culture

The gold standard for security awareness training is to develop a cybersecure culture. This is one where everyone is cognizant of the need to protect sensitive data. As well as avoid phishing scams, and keep passwords secured.

This is not the case in most organizations, According to the 2021 Sophos Threat Report. One of the biggest threats to network security is a lack of good security practices.

The report states the following,

“A lack of attention to one or more aspects of basic security hygiene has been found to be at the root cause of many of the most damaging attacks we’ve investigated.”

Well-trained employees significantly reduce a company’s risk. They reduce the chance of falling victim to any number of different online attacks. To be well-trained doesn’t mean you have to conduct a long day of cybersecurity training. It’s better to mix up the delivery methods.

Here are some examples of engaging ways to train employees on cybersecurity. You can include these in your training plan:

  • Self-service videos that get emailed once per month
  • Team-based roundtable discussions
  • Security “Tip of the Week” in company newsletters or messaging channels
  • Training session given by an IT professional
  • Simulated phishing tests
  • Cybersecurity posters
  • Celebrate Cybersecurity Awareness Month in October

When conducting training, phishing is a big topic to cover, but it’s not the only one. Here are some important topics that you want to include in your mix of awareness training.

Phishing by Email, Text & Social Media

Email phishing is still the most prevalent form. But SMS phishing (“smishing”) and phishing over social media are both growing. Employees must know what these look like, so they can avoid falling for these sinister scams.

Credential & Password Security

Many businesses have moved most of their data and processes to cloud-based platforms. This has led to a steep increase in credential theft because it’s the easiest way to breach SaaS cloud tools.

Credential theft is now the #1 cause of data breaches globally. This makes it a topic that is critical to address with your team. Discuss the need to keep passwords secure and the use of strong passwords. Also, help them learn tools like a business password manager.

Mobile Device Security

Mobile devices are now used for a large part of the workload in a typical office. They’re handy for reading and replying to an email from anywhere. Most companies will not even consider using software these days if it doesn’t have a great mobile app.

Review security needs for employee devices that access business data and apps. Such as securing the phone with a passcode and keeping it properly updated.

Data Security

Data privacy regulations are something else that has been rising over the years. Most companies have more than one data privacy regulation requiring compliance.

Train employees on proper data handling and security procedures. This reduces the risk you’ll fall victim to a data leak or breach that can end up in a costly compliance penalty.

Need Help Keeping Your Team Trained on Cybersecurity?

Take training off your plate and train your team with cybersecurity professionals. We can help you with an engaging training program. One that helps your team change their behaviors to improve cyber hygiene.

—
Featured Image Credit

This Article has been Republished with Permission from The Technology Press.

Share
0

Related posts

Free photos of Ransomware
November 25, 2022

Simple Guide to Follow for Better Endpoint Protection


Read more
red padlock on black computer keyboard
November 20, 2022

Insider Threats Are Getting More Dangerous! Here’s How to Stop Them


Read more
Free photos of Checklist
November 10, 2022

Checklist for Better Digital Offboarding of Employees


Read more
Free Person Shopping Online Stock Photo
November 5, 2022

9 Urgent Security Tips for Online Holiday Shopping


Read more
Free Close Up of a Keyboard Stock Photo
October 25, 2022

What Is Microsoft Defender for Individuals & What Does It Do?


Read more

    Our Services

    • HelpDesk
    • Reputation
    • LocalAds
    • Cloud
    • About Us
    • Get Help
    • Login
    • Radar

    Get Help Now

    How Often Do You Need to Train Employees on Cybersecurity Awareness?
    Customer Service

    1-916-905-0874
    [email protected]

    We are on a mission to help small businesses, recording studios, religious organizations, and entrepreneurs with teams of 5 to 20 members with the hard to understand technological components of their businesses to meet industry standards, allowing them to reach their full potential, so we can grow together.

    © 1998-2022 Locutis IT Services. A Service of Front Line Media inc. All Rights Reserved.
    All Trademarks and Indica are properties of their respective owners.
    • Sacramento Region Managed IT and Cloud Services
    • 1 ‪(916) 905-0874
    • [email protected]

    First Name

    Last Name *

    Company or Family *

    Title

    Email

    Phone


    Fax

    Mobile


    Website


    Industry

    No. of Employees

    Street

    City

    State

    Zip Code

    Country

    Message