Rethink Cybersecurity Awareness Month: 4 different approaches | TechTarget

https://www.techtarget.com/rms/onlineimages/security_a254815015.jpg

Cybersecurity Awareness Month shouldn't be measured by how much training employees complete. For executives, its value is greatest when October becomes a catalyst for specific actions that reduce risk, simplify security operations and assign accountability.

The familiar Cybersecurity Awareness Month playbook includes mandatory training, phishing simulations, newsletters, policy reminders and other communications. Reframe awareness as an organizational action for greater impact.

Awareness is more valuable when it changes the organization's actual security and risk posture. I repeat: Don't measure October by how much training people complete. Measure it by what becomes safer. Here are four approaches for doing just that:

  1. Four executive fixes in four weeks.
  2. One day returned to the security team.
  3. A "delete day."
  4. One security action for every employee.

Together, these approaches ask a larger question: What could an organization remove, fix, test or improve in October that would leave it measurably safer on November 1?

...

Copyright of this story solely belongs to www.techtarget.com. To see the full text click HERE