enterprisesecuritymag

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

Under Armour [NYSE: UAA]

Cyber Security Training: Messaging to the right audience matters

Alex J Attumalil, VP, Global Chief Information Security Officer, Under Armour

The average downtime from a cyber-attack has increased from 15 to 22 days. Across the industry, these unplanned downtime costs approximately $300,000/Hr on average. Cyber Incidents are the highest business risk, called out by the Allianz group in their annual Risk Barometer Report. Preventing a cyber-attack or responding to it in a timely manner is the top IT priority for organizations worldwide. According to the Verizon Data Breach Investigations report (2021), 85 percent of data breaches had a “human element,” and 61 percent involved credentials. Low-security awareness among employees is the top barrier for organizations from establishing effective cyber defenses. From a financial impact standpoint, the overall cost of cybercrime globally is over $1Trillion, a 50 percent increase over the past two years. Are these survivable numbers for your business?

Yet, we tend to take a cookie-cutter approach to Cyber Security training in our organizations. We work with HR on our annual cyber training, address the do’s and don’ts during employee onboarding, send emails to call out mistakes, and put-up posters during Cyber Security Awareness month in October. We follow this up with a Phishing Test and take pride when our stats show improvement. But is it effective? Will the training last? On closer inspection, you can see the farther away you are from training, the stats are NOT in your favor. Here are some interesting facts. After 1hr, we retain less than half of the information presented. After six days, 75% of the message is lost, and whatever information is left in our memories continues to fade faster if not recalled again. Given the stats listed above, are we doing enough? Are we doing justice to our #1 business risk? 

We need to message Cyber security awareness in three distinct “languages” and to three “tailored” audiences. Let us dive in.

1) The “Why” and “How” to everyone. This message is for everyone, and it should be simple, consistent, and repeating. A consistent, repeating message is proven to “stick” with audiences vs. a complex and constantly changing message. Elections are won using this method. Regardless of when, where, or how often the audience hears our message, it should be the same and reinforcing every single time. The audience must be aware that they are stakeholders, and we need to ensure that they buy into our convincing arguments. For this to happen, the discussion needs to be interesting and captivating, with reality sprinkled with “war stories.” You do not have to go too far for these stories. Check with your IR teams for a few good ones. We need to explain “why” it matters, tying it back to protecting the business. In all cases, addressing the “WHY” in a message is more important than the message itself. Our employees will buy in when they understand their stake in the game. 

2) Time and Cost impact discussion with the Services and Supplier Teams. The target audience here is the application developers, Tier 1 services teams, and the supply chain partners that support the organization. They become stakeholders when you relate the Time and Cost impact of a security incident to the organization and the partner’s symbiotic relationship. Beyond the technical aspects, they need to better understand the revenue impact on the organization in the event of a security incident. Getting their buy-in and allowing them to be stakeholders is more effective than the traditional “it’s our corporate mandate” approach. The partners and suppliers of our organization require a more targeted security awareness strategy since they are not directly impacted by the corporate policies, standards, and controls governing the employees. Our efforts to extend training to the supply chain partners will benefit organizations that do not have their training programs and can significantly reduce the impact on our business due to a supply chain disruption. We could engage external support from partners like the Center for Global enterprise and their DSCI program to baseline effective and global standards for our supply chain partners. 

“Cybersecurity awareness could reduce the risk of a cyber-attack by 70 percent. For this, messaging should be tailored for employees, services teams, supply chain partners, and leadership teams”

3) Business Risks conversation with corporate leadership teams. The audience here is the leaders in our organization that have P&L responsibilities. The Senior Leadership teams require a less technical, more business risk conversation. They understand the consequences of unintended downtime, revenue loss, and financial impact. Once convinced, they can be the biggest cheerleaders and help with top-down messaging, highlighting the need for security best practices across the organization. Discussions need to address the impact cyber-related risk has on their current business processes and ownership lanes, which drives cyber risk as one of their top priorities during business continuity and resiliency conversations. In a global organization, these discussions will further help us align with regional and local compliance standards and thus reduce the financial risk to the organization.

That brings us to the “how often should we message” question. According to an article by FraudWatch, employees are able to retain their cyber training for up to four months. Facts show that consistent and continuous Security awareness training can reduce the risk of a debilitating cyber-attack by 70 percent. With that much ROI, we need to ensure cyber awareness training is more than an annual compliance checkmark. Training needs to be on a scheduled cadence with a consistent message. For training to stick and have its expected long-term effectiveness, our messaging must contain storytelling, emotions, and imagery and be logical. For global organizations, messaging should contain regionally applicable facts to ensure the audience can relate to and absorb the message. Because our users are focused on their areas of expertise and are not constantly thinking about the latest phishing and social engineering tactics, we need to consistently message cyber risk at all levels. We need to use all available mediums such as internal newsletters, websites, word of mouth, and display screens while ensuring that the message invokes a sense of ownership for the audience. Each time we message, it should be simple, consistent, and addresses the impact on the business function that the audience is responsible for. 

In summary, 85 percent of cybersecurity incidents happen due to a human element. Cybersecurity awareness could reduce the risk of a cyber attacks by 70 percent. Messaging should be tailored for employees, services teams, supply chain partners, and leadership teams. Without continuous reinforcement, we lose 75 percent of what we learned within a week. For training to have the intended effect, we should be consistent, reinforcing, and engaging. Employees are an integral part of securing our organizations. Let’s ensure they have the knowledge and skillset to protect our house.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.