October is Cyber Security Awareness Month; and therefore, the perfect opportunity for individuals and businesses to learn about the importance of having a strong security culture. The idea originally stemmed from the United States and is now becoming widely adopted in many countries across the world, including the EU and here in the UK. This year, the EU Cyber Security Month celebrates its 10th Anniversary around two themes: Phishing and Ransomware. We highlighted the issue of ransomware in our last insight which you can read here.

85% of cyber breaches are directly related to human behaviour (either falling for a Social Engineering attack or human error) but only 3% of security budgets are spent directly on the problem (Carpenter & Roer 2022). It’s a shocking statistic when you think about it: we’ve tried to change human behaviour by implementing tooling and hoped that this would be enough to protect our organisations. Although security tooling is important, if an attacker can get round those defences 85% of the time, then something’s missing.

As with most things, measurement is important; we need to understand how effective our efforts and investments have been if we are to see change and continue to make progress. Typically, awareness programs measure things like attendance at in-person training sessions, computer-based training completion rates, and the number of phishing emails sent vs the number opened. What these measurements don’t tell us is the performance against a particular goal or objective. We recommend starting with the question ‘what are we trying to do?’ this when developing a training programme. Hayden (2010) explains the GQM (Goal, Question, Metric) method in his book IT Security Metrics. This approach starts by defining a Goal – what you are trying to achieve – then setting a Question – what you need to know – followed by a Metric – what you can measure to determine your performance.

For example:

Example of the GQM Method described by Hayden (2020) IT Security Metrics

“Security competence is exactly that – a competence that must be learned, not just something you tell.”

Kai Roer (2015)

What can you do?

Protecting your customers, your data, and your organisation is at the core of cyber security; and educating everyone in your organisation is foundational to those purposes. Here’s a few ideas for where you might want to start:

Remember, cyber security awareness is for life, and not just for a month. All it takes is one moment, one mistake and all your hard work can be undone. ‘Semper Vigilans’ = ‘Always Vigilant’. If you’d like to have a conversation about how we can help you implement an awareness program, or you’re interested in our certification courses contact Jim at jim@principledefence.com

Secret Link