Is your training set up to improve outcomes or just check a box? Most companies, as they apply for their cyber security insurance, see a question which asks: “do you do annual security awareness training? Yes or No.” They know the answer needs to be yes, so they find the cheapest vendor who offers the service and they enroll everyone. Then, once a year, everybody is required to watch a 45-minute video about how to recognize and report phishing, avoid malware, and not get fooled by scammers. After those 45 minutes are up, everyone goes back to their day job.
Congratulations, you have now spent the cost of that service for the privilege of getting cybersecurity insurance. But it’s unlikely the training will truly prevent bad things from happening the rest of the year. And you also might not have met the full training requirements your business is required to follow. Training is effective when it changes behavior. When an email comes in which looks like a vendor trying to get an invoice paid, does the recipient stop and follow the process to see if it’s valid? Or do they just scroll through the email chain, see the vice president approved it (which was fake), and go ahead and pay it? If the email looks like how business is done, then they might not notice its fake.
Also, a lot of compliance frameworks require more than annual security training for certain roles. For example, software developers often are required to be trained on writing secure software. Finance teams may be required to be trained on detecting these fake vendor scams. The generic “don’t click links” annual training won’t meet the requirements of these specialized requirements. The risk becomes twofold. First, your current training program may be insufficient to meet your compliance goals. Second, ineffective training can lead to actual breaches and vulnerabilities. Both of these should be on your risk register, even if you’re already doing some training.
What’s the mitigation? Work with your IT and cyber teams to make sure you have robust and effective training. Look for programs which are year-round, not once a year. Smaller, more frequent lessons are better at helping keep security awareness top of mind. Make sure you’re covering multiple channels too, SharePoint/Teams/Slack posts, emails, all-hands-meetings, and more are where training should be shared. And test too. Not punitively, but constructively. When doing tests, make sure they reward correctly identifying risks and not just punishing people who miss them. If they do, use those as a chance to do some targeted reminders.
Bottom line: Having a basic annual security awareness training might check a box, but it doesn’t remove some very real risks. Make sure you’re looking at the types of training you’re required to have and spending time and money on training which changes behavior and reduces the real risk of a breach.
Companies are people. All the technologies, intellectual property, processes, and policies can’t achieve anything without humans to make it happen. (I am ignoring AI agent and automation as a substitute for human work. They have their own compliance and security risks, which we’ll deal with later.) Product design, development, delivery, sales, customer success, and more all have a person or a team responsible for making sure the technology and business stay aligned to the mission and vision. But whether they’re successful depends on how much they believe in the governance, technology, and operating procedures set before them. If they believe its optional, then the failure rate will be high. When they believe in it and live it, quality and efficiency are high, and risk is low.
The definition of culture inside the Four Pillars framework is “ensuring the right people are doing things the right way.” At its core, it’s about how you find people, treat them, and keep them doing a good job for the company. Big companies call this “Human Capital Management” but this phrase will make it hard to get people to believe in your IT governance, risk, compliance, and security programs. So, instead, it’s important to look at what sort of culture you’re creating around these important topics. For a while, it was the in thing to say you were building a “culture of security” and training people to always be aware, report suspicious things, and be their own champion of keeping the company security. To be clear, this is still a good thing, but a “culture of security” is just one facet of a company’s culture.
Building culture starts at the top, and we’ll see how this ties into Governance with next week’s Issue, with the first topic in Governance, “Leadership.” Culture has to be shared with and promoted by the leaders of the company. If they ignore security rules, don’t complete training, use personal devices on the company network, then it’s hard to convince everyone else the rules matter. But culture also has to be grown from the bottom. People have to see it matters to them. They have to be a stakeholder in the success of these programs, not just a cog in the machine. And so, building a culture supporting good IT risk, compliance, and security can be the hardest of the four pillars to implement.
“when the security program takes care of the people, the people take care of the security program.”
To make it easier, we break culture down to the “employee lifecycle” which starts with how recruiting is done, follows the hiring, promotions, lateral moves, and ends when the employment does too, at some version of off boarding the person from the company. Each of these steps is critical to maintaining a good risk, compliance, and security program, and also to ensuring the most positive experiences for the people who have to make it happen. To borrow a phrase, “when the security program takes care of the people, the people take care of the security program.” And by implementing strong controls across the lifecycle of employment, you end up with a strong culture too.
In the Culture pillar you’ll find information about training, onboarding and offboarding, employee growth, and also how you encourage people to practice the procedures and prove both their knowledge and that the processes are working. There are at least nine subtopics under Culture, making it an equal peer to the other pillars in terms of what you should be considering. But it’s easy to argue that it’s the most important pillar because a bad culture here will derail all the other pieces you’ve built. And in practical terms, this could lead to a breach, a system failure, a critical vulnerability, resulting in serious losses and damage to the company. So, while Culture is fourth in the list, we land with it because of its importance to your success.
Today is the last free weekly issue of The Risk Register. Free subscribers will continue to get a monthly issue with the Risks to Register and other important updates and news. Paid subscribers will continue to receive the weekly issues, diving into all the components of the Four Pillars. Next week we return back to Governance, and explore its first topic, Leadership.
Whichever subscription you are on, we hope you continue to find value in The Risk Register and appreciate all feedback to ensure it is helpful to you!
We’ll keep today’s Mitigation Monday simple: do you know what security training you’re doing today? If not, it’s time to put together a list of what’s offered, what’s required, and who is participating. And if you’re not doing any training, let’s start by getting a program going.
If you’re not sure what training you might be required to be doing, check your most insurance applications, and then also what compliance frameworks you might be following. Standards such as PCI DSS, ISO 27001, and SOC 2 have training requirements, for example.
This week’s goal is to know what you’re doing today and what you might be required to do. With that information, then you’ll be in good shape to fix any gaps or measure how effective your programs are at preventing risk – all topics covered by later issues of The Risk Register.
Happy Mitigating!
Thanks for reading The Risk Register by ComplianceXO! This post is public so feel free to share it.
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.