Perspectives
Why annual cyber security training isn't enough
Cyber security training is an important part of protecting an organisation. It gives people a common understanding of the risks they may encounter, the behaviours expected of them and what to do when something doesn't look right.
For many organisations, training follows a familiar pattern. Once a year, colleagues complete an online course. Completion is monitored, the target is reached, and the process starts again the following year.
That provides an important baseline. But completing a course isn't the same as changing behaviour.
Annual training is the foundation
A well-designed annual course can introduce common threats, explain individual responsibilities and establish the behaviours an organisation expects.
It is also a practical way for smaller businesses to give everyone a consistent level of understanding without creating a large or complicated training programme.
The problem comes when completion becomes the objective rather than the starting point.
A dashboard showing 100% completion tells you that everyone completed the training. It doesn't necessarily tell you what somebody will do when they receive an unusual payment request or spot something suspicious six months later.
Reinforce what matters
Most people aren't thinking about cyber security throughout their working day. They are thinking about customers, deadlines and getting their job done.
Important security behaviours therefore need occasional reinforcement.
That doesn't mean another hour-long course. It could be a short reminder, a five-minute team conversation, a timely message or a simple scenario.
Relevance matters too.
Someone working in finance may need greater awareness of payment fraud and impersonation. Managers may need to understand access, information handling and their responsibilities when people join or leave. People with privileged system access may require more specific learning.
Not everybody needs more training. They need the right learning at the right time.
Give people opportunities to practise
Knowing something in theory and recognising it during a busy working day are different things.
Phishing simulations, short scenarios, team discussions and manager conversations can give people opportunities to apply what they have learned.
These activities shouldn't be designed to catch people out.
A phishing exercise, for example, can help identify where additional support is needed, whether people recognise suspicious messages and whether they know how to report them.
Reporting should be reinforced alongside recognition. People need to understand what to report, where to report it and feel comfortable speaking up when something has gone wrong.
The earlier an organisation knows about a potential issue, the sooner it can respond.
Measure whether it is working
Completion rates still matter, particularly where training is mandatory. But they should not be the only measure.
Reporting rates, recurring questions, exercise results and areas where people remain unsure can all provide useful information about whether awareness is translating into everyday behaviour.
Smaller organisations don't need complicated security culture dashboards to do this. A few useful measures and regular conversations can often tell you much more.
What this means for your organisation
Start with three questions. When did colleagues last hear about cyber security outside mandatory training? Does your training reflect the situations people actually encounter in their work? Do people know what to do and where to report something when it doesn't look right?
If you're unsure about some of the answers, the solution isn't automatically another course.
Good baseline training, proportionate reinforcement and practical opportunities to apply the learning can make a much bigger difference.
Cyber security training
Cyber security training that fits your organisation
H Change helps smaller organisations develop practical cyber security training and awareness that reflects their people, risks and ways of working.