Lack of continuing education
Cybersecurity awareness training is conducted in nearly 100% of organizations around the world. However, in my opinion, cybersecurity awareness training is conducted well in fewer than 10% of organizations around the world. Few organizations have a clear plan for what the training is intended to accomplish or how they will measure if the training was effective. If there are no metrics for the training, it should be assumed it wasn't effective. Also, few organizations have a clear goal for what they hope to accomplish.
In Chapter 5, Protecting against Common Attacks by Partnering with End Users, we discussed the process for creating an effective training program along with best practices for how the training should be delivered and reinforced. We will not repeat that content. Instead, we will address issues that make it difficult to maintain relevant skillsets in the modern security landscape. While these challenges apply to all employees, leaders...