Security awareness training mostly fails. What to run this October instead.

Cyber Security Awareness Month gets everyone’s attention for four weeks a year. Most organisations spend it on a video nobody remembers. Here is the version that leaves something behind.

October is the one month security gets everyone's attention

Cyber Security Awareness Month runs through October, and for most organisations it means a video, a quiz nobody remembers by November, and a poster about passwords next to the kettle. The intention is sound. The execution usually changes nothing, and everyone involved privately knows it.

It is worth being precise about why, because the failure is not laziness. It is that most awareness training tests recall when the thing that matters is reasoning.

Recall is not the skill

Ask somebody what phishing is and they will tell you. Ask them what to do when their phone buzzes three times with a sign-in approval they did not request, while they are making coffee and late for a meeting, and the answer is less certain. The first is a definition. The second is a decision, made under mild pressure, with an obvious wrong option that feels helpful.

Attacks are built around that gap. Nobody falls for the Nigerian prince any more. They approve the prompt to make it stop, they pay the supplier invoice because the reference number is right, and they install the PDF tool from the first search result because it was the first search result.

Three things make training stick better, and none of them cost money:

  • Use situations, not definitions. A scenario with a plausible wrong answer teaches more than a correct definition ever will.
  • Explain at the moment of the decision. Feedback at the end of a module arrives after everyone has stopped caring. Feedback the instant somebody answers is the part that changes the next decision.
  • Say why the wrong answers are wrong. "That is incorrect" teaches nothing. "That is incorrect because a stolen session cookie skips the password entirely" teaches the next case too.

The half that awareness cannot fix

Here is the part that tends to go unsaid during Awareness Month, because it is not very flattering to the month.

We wrote ten realistic scenarios for this October. Nine of them are survivable because of something technical sitting behind the person, not because the person was alert. Multi-factor authentication makes a stolen password insufficient. Updates applied inside fourteen days close the hole before anyone browses into it. Users without local administrator rights cannot install the thing that was never meant to run. A home router that is not answering the internet is not a route in.

Those are the five Cyber Essentials controls. The whole design of the scheme is that it does not depend on everybody being alert at four o'clock on a Friday.

So the honest framing of Awareness Month is this: trained people and configured systems cover each other's failures. Either one on its own is a single point of failure, and the person is the one who has had a long week.

The tenth scenario

One of our ten is not covered by Cyber Essentials at all, and we tagged it that way deliberately.

A supplier emails to say their bank details have changed. The message comes from their real address, because their mailbox is the thing that was compromised, and it quotes the correct invoice number for the same reason. No technical control on your side stops that. Replying to confirm goes to the attacker, who is reading the mailbox and may well have added a rule to hide your message. A small test payment confirms the account exists, not who owns it.

The only reliable answer is to phone the supplier on a number you already hold, not one from the email. That is a process control, not a technical one, and it is the sort of thing an awareness exercise genuinely can fix.

What to run this month

If you want October to leave something behind, four things are worth more than a video:

  1. Give people scenarios with explanations. Twenty minutes of realistic situations beats an hour of definitions.
  2. Agree the payment rule in writing. Bank detail changes are verified by phone, on a number already held, by somebody other than the person who received the email. Write it down and tell the finance team they will never be criticised for using it.
  3. Check what happens after somebody clicks. Does multi-factor authentication actually cover everything? Do users hold administrator rights? How long can a laptop sit on pending restart? That is the half the posters do not reach.
  4. Keep a record of who was trained. Insurers, client questionnaires and IASME Cyber Assurance all ask. A dated certificate per person is the cheapest evidence there is.

We built the assessment we wanted to exist

Rather than write another post telling you awareness matters, we built the thing: ten scenarios, about six minutes, free, with no sign-up.

Every answer is explained immediately, including why the plausible wrong ones are wrong, and each scenario is tagged with the Cyber Essentials control behind it, so by the end you can see which of the five your own habits support. Pass seven out of ten and you get a named certificate, downloaded instantly and signed so it can be verified later. Fail and you get every explanation and can start again, which is the point: the explanations are the training and the score is only the gate.

Send it to your whole team. Everyone gets their own certificate with their own name on it, there is nothing to set up, and there is no licence to buy.

Take the assessment →

Then do the other half

Once your people have worked through it, the useful question is the one the assessment keeps pointing at: if somebody does get it wrong one Friday afternoon, what happens next?

Cyber Essentials is the answer to that question, and Solusec assesses and issues it directly as an IASME appointed Certification Body, along with IASME Cyber Assurance and Defence Cyber Certification for the MOD supply chain. Awareness Month ends on 31 October. The controls carry on working in November.

Common questions

Does security awareness training actually reduce incidents?

It helps, and on its own it is not enough. Training moves the odds on the decisions a person makes; it does nothing about whether a stolen password is sufficient to sign in, or whether a laptop has been sitting on a pending restart for a week. Organisations that only do awareness are relying on everybody being alert every day, which is not a control.

How often should we run it?

More often than annually and more briefly than you think. A short, realistic exercise a couple of times a year, plus a note when something relevant happens, works better than one long session each October that everybody clicks through.

Is the Solusec assessment really free?

Yes, with no sign-up. Ten scenarios, about six minutes, an explanation after every answer, and a named certificate if you score seven or more. The email box on the results page is optional.

Can we use the certificates as evidence of training?

For most purposes yes. Insurers, client security questionnaires and IASME Cyber Assurance all ask whether staff receive awareness training, and a dated certificate per person is reasonable evidence. Each one carries a verification link so whoever asks can check it themselves. It is not a Cyber Essentials certificate and does not certify an organisation.

What is the one thing to fix if we only do one?

Agree in writing how a change of supplier bank details gets verified, and make it a phone call to a number you already hold. It is free, it takes an afternoon, and it is the attack in our ten that no technical control on your side will stop.

Related

Certify directly, with one accountable team.

Direct from the Certification Body, with one accountable team.