Skip to content

Awareness & training

The human factor is the most common breach vector (phishing, social engineering, mistakes). Awareness turns people from “the weak link” into an active layer of defense. It’s not an annual video nobody remembers: it’s a continuous program that changes behavior.

- most breaches start with a PERSON (phishing, credentials, error) -> see se-fund
- technical controls aren't enough: one click can bypass many layers
- goal: people who RECOGNIZE and REPORT, not who just "pass the test"
Base training mandatory and periodic; tailored by role (dev, finance, management)
Simulations simulated phishing (see se-phishing) to measure and train
Communication reminders, newsletters, themed campaigns (not just once a year)
Just culture report without fear; don't punish those who fall -> more reports, sooner
Onboarding security from day one; reinforcement on role changes
- click rate on phishing simulations (trending down)
- REPORT rate and TIME (the sooner reported, the better the culture)
- training coverage/completion; incidents from human error
# measure behavior, not "hours of video"; the goal is to change conduct
Developers secure coding, OWASP, the secure SDLC (dso-sdlc)
Finance/HR CEO fraud/BEC (se-phishing), payment verification
Management risks, accountability (NIS2/DORA), targeted attacks (whaling)
Help desk vishing and MFA reset (se-vishing) -> a recurring target
IT/privileged targeted phishing, credential hygiene, phishing-resistant MFA
- make REPORTING easy (button, clear channel) and thank it, don't punish it
- whoever falls for a simulation -> micro-training, not humiliation
- "if you punish reporting, people stop reporting" -> you lose early visibility
  • A continuous program by role, not an annual video; onboarding from day one.
  • Phishing simulations (Phishing campaigns) to measure and train; focus on the help desk (Vishing & smishing).
  • Measure behavior (click, report, time), not hours; a report-without-fear culture.
  • Link with policies (Policies & governance), social engineering (se-*), and the SOC (fast reporting, SOC operations).
  • DBIR reports place the human factor at the front of the initial breach vector year after year.
  • MGM/Caesars (2023): help-desk training would have mitigated the vishing (Vishing & smishing).
  • Organizations with just culture detect sooner because people report without fear.
  • Continuous program (not annual) tailored by role
  • Training at onboarding and on role changes
  • Periodic phishing simulations (Phishing campaigns)
  • Help-desk-specific training (vishing, Vishing & smishing)
  • Behavior metrics (click, report, report time)
  • Just culture: report without fear, don’t punish
  • Easy report button/channel integrated with the SOC (SOC operations)