
When it comes to email security, technology and processes can only get you so far. While these are essential components to every cybersecurity strategy, without the right people to drive that strategy forward, you won’t have much to show for your efforts.
But at the same time, human error is responsible for almost three quarters of cybersecurity breaches, reports Mimecast. Training your employees can go a long way in protecting your organization from evolving email threats, but how do you educate staff on email security?
The CIO Experts Network, made up of IT professionals and the leading authorities in technology, had a lot to offer on this topic. Here’s their best advice on employee education in email security.
Offer training that’s ongoing and interactive
Effective employee education provides the foundation for a solid email security strategy. However, not just any training will do. Gene De Libero (@GeneDeLibero), principal at Digital Mindshare, LLC, recommends organizations “start with engaging, interactive training sessions that cover key threats like phishing and malware.”
In addition to offering interesting sessions, experts recommend ongoing training to keep skills fresh:
“Let’s face it, employees are not enthusiastically lining up for email security training. That’s why it’s important to conduct regular mandatory training sessions to make sure that all staff are up to date on the latest security threats such as social engineering attacks and phishing attacks.” – Scott Schober (@ScottBVS), President/CEO at Berkeley Varitronics Systems, Inc.
“We provide thorough email security training for all new employees as part of their onboarding process. We also schedule regular refresher courses and updates to keep staff informed about new threats and best practices.” – Nitin Raina (LinkedIn: Nitin Raina), global chief information security officer at Thoughtworks
By implementing regularly scheduled email security training that’s fun and interactive, organizations can ensure that employees are well equipped to identify and mitigate the latest email threats. Next up: test your training effectiveness through planned phishing testing.
Conduct behavioral assessment and risk profiling
Experts agree that phishing simulation programs are one of the top ways organizations can determine whether or not employees understand the concepts they’ve been taught. These real-world applications help employees understand the significant role they play in protecting their organization.
“Security teams must make it clear to staff that they’re on the front lines and that their organization’s security depends on them,” said Rob Hughes (LinkedIn: Robert Hughes), CISO at RSA. “That can mean conducting regular phishing tests that look like what cybercriminals are generating and helping your team improve if they fail a test.”
Hughes cautioned that these tests may be influenced by the amount of junk mail employees receive, emphasizing the need to balance testing with effective security tools.
Tony Foley (LinkedIn: Tony Foley), content management consultant at Wolters Kluwer Legal & Regulatory, agreed that the most effective testing incorporates detailed feedback followed by “refresher training for employees who fail to spot an illegitimate message.”
While phishing simulations can help employees spot malicious emails more easily, Will Kelly (@willkelly), a writer focused on DevOps and the cloud, cautions that “poorly executed tests can erode employee trust.” He encourages “a culture of openness where employees feel comfortable reporting potential threats without fear of retribution.” Which leads us to our next tip: fostering a security-conscious environment.
Create a security-first culture
While phishing tests help employees understand how to protect themselves against malicious emails, a thorough grasp of email security requires a more comprehensive approach — one that’s built into company culture.
“Driving awareness starts by highlighting when employees made good decisions — a phishing email flagged, a malicious attachment not opened, a whaling attempt identified before transactions were compromised,” said Peter Nichol (@PeterBNichol), Peter Nichol, Data & Analytics Leader for North America at Nestlé Health Science.“ “Emphasizing what good looks like not only helps drive a proactive culture but also recognizes and values the efforts of your staff.”
Schober agrees. “When employees realize that they were only a click away from malware but took the right actions, they should be commended and rewarded to reinforce the importance of following protocol.” He also recommends that leaders attend training sessions to “reinforce the importance of everyone getting on board to improve the company’s cybersecurity posture.”
Experts also advise creating a supportive environment where employees aren’t afraid to speak up when something looks off:
“Businesses should encourage a ‘report first’ mentality, making sure that employees err on the side of caution with any email that might seem suspect.” – Tony Foley (LinkedIn: Tony Foley), content management consultant at Wolters Kluwer Legal & Regulatory
“We strive to create an environment where our employees feel comfortable reporting suspicious emails or security concerns without fear of reprimand.” – Nitin Raina (LinkedIn: Nitin Raina), global chief information security officer at Thoughtworks
Scale your efforts with email security technology
While education is crucial, it’s not enough on its own, and organizations should treat employee training individually. “The vast majority of attacks use phishing and human error, and no education program — no matter how good — will account for user behavior all the time,” said Hughes.
In addition to making security part of the culture, he recommends that organizations develop the capabilities to stop an initial breach from spreading. Whether taking a layered approach with defense in depth or leveraging risk signals and behavioral insights to deliver the right intervention to each employee, technology can help protect users as well as sensitive company systems and assets.
“We leverage technology and implement advanced email filtering tools to reduce the risk of phishing and malware reaching staff inboxes,” said Raina.
Nichol also supports a layered approach to email protection. “Companies that combine employee awareness, strong password policies, and making multi-factor authentication the norm are taking strong steps toward limiting the impact of nefarious emails,” he observed.
Train, test, reinforce, and protect
Employee education can significantly cut down on human risk that causes the majority of cybersecurity breaches. With ongoing and engaging training, regular testing, and a security-first mindset, companies can ensure that their people, processes, and technology work in lock-step to detect and respond to email threats before the damage is done.
Click here to find out how Mimecast can help you educate and prepare your teams for evolving email threats.
