3.2 Reinforcement Approaches for Cyber Security Education

Video Activity
Join over 3 million cybersecurity professionals advancing their career
Sign up with
Required fields are marked with an *

Already have an account? Sign In »

2 hours 23 minutes
Video Transcription
Lesson two
Reinforcement approaches for cyber security Education
Can you name a cyber risk that we should focus on to maintain vigilance and threat recognition levels amongst our colleagues?
Hopefully, you chose fishing or social engineering as your answer because these are areas where users are most likely to be targeted or caught unaware.
So in this lesson, we're going to look at specific reinforcement techniques that can be applied to security education related to these risks.
The overall learning objective of this lesson
is to understand how to apply reinforcement principles within our security education program so that we can reverse the forgetting curve within our organization
within a security education program. Micro learning interventions can be used to both reinforce education already provided and to develop skills further
in listen three of module one. We showed how we could apply experiential learning techniques to coach uses to recognize different types of cyber threat by giving them the experience of interactively finding red flags in phishing emails.
This concept can be developed further by using interactive experiences as a platform to regularly refresh your colleagues knowledge on threat recognition skills on to help them recognize new threats that may have recently emerged.
I suggest that you develop a schedule of micro learning interventions so that users can receive regular exposure two examples of the cyber threats that they are most likely to encounter on a daily basis.
The material used in these exercises should not be a repeat of the same test that you use in your main education content.
Vary them and adjust the difficulty.
Remember that the forgetting curve kicks in quickly, so consider the frequency of delivery.
Ensure that they are frequent enough to be effective,
but not so frequent that they become a nuisance to everyone.
I would suggest a monthly frequency
based on examples that you have developed in house, augmented by ad hoc interventions when new threats or techniques come to your notice.
In this way, your micro learning initiative becomes responsive to current threat intelligence. On In this way, you are training your colleagues to deal with relevant threats,
and you're also sending out another important message that you are looking out for them on our actually helping them to recognize Fitz as they emerge.
If you have the capability to capture the results of these micro learning exercises,
the threat intelligence led approach has the capability to generate some highly relevant and valuable metrics, which I will expand on in the next lesson of this module.
But for now, let's just concentrate on the concept that small frequent reminders will help to stop the forgetting curve becoming too steep.
The reinforcement approach involves quite a few building blocks that operate together, so it may be helpful to run through a conceptual example to see how it all comes together. The next few slides will show the key stages in the development of a reinforcement program, which is designed to build and maintain threat recognition capability
throughout an organization.
Our aim here is to make the learning curve resilient so that cyber security threat recognition skills grow rather than deteriorate.
We're all familiar with the concept that content is king, and you can't start a micro learning process without content.
Remember that your content needs to be varied and challenging on that you'll need to build a library off, um, so that you have a stock of content to feeding to your micro learning initiative.
Did you take the opportunity to test drive the fishing test example that we showed in less than three of module one.
This example was built with power point using triggers and animation sequences, so you'll need to develop a few examples like these for yourself, making them a specific issue can to your organization.
New examples should regularly be developed based on your current threat intelligence in this area
to ensure that your training and education efforts are focused on current threats.
When you create your content, it's worth considering whether there will be different audiences within your organizations that might have specific needs.
If so, you could think about tailoring your content to different groups. For instance, would procurement have slightly different needs to sales and marketing? Maybe you could start to Taylor content for these specific audiences.
Remember, this gives you a great excuse to get out into the organization to discuss specific needs with particular groups, which makes this a great PR exercise for in for SEC. Sending out the message that you are tailoring security education for the specific threats on risks
face my particular activities within your organization.
decide on a schedule which starts with your usual training approach, bolstered by the shuttle off your micro learning interventions, Remember, vary them
and, if required, taylor them to specific organizational functions where relevant
delivery is the next stage of the process.
Pushing out your micro learning sessions to your colleagues using whatever tools and distribution approach best meets your needs and the resources you have available to you
on the final stage is, of course, measure the results of your micro learning exercises. Remember that our objective is to improve the threat recognition capabilities of our organization.
So we want to move beyond generating statistics that merely relate to who participated in the exercise on who didn't
I'll be covering the measurement issue and providing a few options in the next lesson.
What you're seeing above is an example of ambient advertising,
which is based on the concept of an encounter with something familiar, but where it is slightly out of normal context or proportion.
The element of surprise prompts a mental double take, which makes us think about the subject rather than subliminally ignoring it.
Looking at the example above a familiar object are familiar brand, but the context off it is unfamiliar, particularly the size
mentally it pauses up short on, makes you spend a little more time processing what we see.
I've deliberately used this example because it shows the use of Ambien influences by a major brand. Ambien Advertising is a major part of the portfolio of persuasion tools used by the advertising industry,
and they use it because they know it works.
These concepts could be applied in your information security education program, too.
Here's a few examples of ambient reinforces for your security education program that can be used to give your colleagues memory a nudge.
You can use mouse mats T shirts, perhaps one by your KN for *** colleagues or seat cushions in touchdown areas.
Your only real limitation is your creativity and imagination. There are literally hundreds of ways to introduce a familiar message on an unfamiliar medium in your workplace.
Just apply the concept of what do you think will work in your organization. For instance, some people just aren't comfortable wearing T shirts with slogans.
Also, don't overdo it. What's fresh today eventually becomes dull,
so select a few options and used them once in a while.
Also on the examples shown note that the logo and strap line, which recovered a module one, are carried through, creating a consistent Touchstone for the program.
If there's one sure fire way to ensure that the vast majority of your colleagues see an ambient reinforce, er, it's by introducing it into their virtual environment.
By adapting the desktop wallpaper to carry your message of prescribed intervals, you may need a little help from your I T colleagues to roll this out, but this is one of the most effective ways to ensure a message. It's seen throughout your organization. It costs nothing
except a few moments to modify the standard desktop background.
A most corporate I T departments have the capability to automatically update all devices to use a different wallpaper for the desktop background.
Again, make sure you vary this. Otherwise it will become stale, dropping the message for a few weeks and then repeating it with perhaps a new background compression everything up.
Another way of using ambient reinforcement is to embed something in a relevant application, such as putting a suspicious email reporting button in the outlook ribbon. This approach has a number of advantages.
Firstly, it makes things easy for everyone. Uses don't have to memorize the correct email to use. If they do see something suspicious, that's just turned up in their inbox.
There's also a positive message for the user in this because it looks like you were trying to support them as part of the Cyber Security education program.
Secondly, it's a constant reminder to the user, and it's positioned above onto the right of the preview pain coming into vision as the user reads or scans through each email.
By the way, although many vendors of simulated fishing chests off a free reporting buttons as part of their offering, it's worth remembering that you came by just the code for the button and insert your own email addresses and customize it for your own usage.
Several organizations supplied these as an actress fix Adin for reasonable prices. So just try searching for Outlook Adan's and you'll soon have a few organizations to choose from.
As with the previous example, you will need some help from your icy department to assist with deployment. But it's well worth the effort to have that constant reminder embedded into which is probably the most commonly used applications in the majority of organizations.
And now a quick post assessment question on this lesson.
What's the best frequency for a schedule off micro learning interventions
or hopefully you said monthly, and you may have added as required for threat intelligence led schemes.
In this session, we concentrated on techniques that can overcome the forgetting curve within your information security education program. We looked at micro learning interventions, which were based on the experiential learning and coaching techniques that we introduced in Module one. We showed how these can be delivered, his short lessons
based on current threat intelligence so that we can keep our colleagues aware of current and emerging threats.
We also locked up using ambient techniques that can be used as Touchstones to keep key messages fresh in the minds of our colleagues. We are now moving on. So lesson three of this module, which will look at how we can extract metrics from their security education program
so that we can go beyond statistics that merely measure participation in courses and exercises
and take us to the stage where we can draw real conclusions on our organization's intrinsic threat recognition capability.
Okay, that's it for this lesson of making it stick. Thanks for watching on. I'll look forward to seeing you in less than three
Up Next
Course Assessment - Creating Effective User Awareness Training