Urgent.News

What's breaking now, across thousands of outlets.

Tech

Cyber security is everyone’s problem. Here’s how to build a security culture that lasts

The organisations that get security right are those that stop treating it as a technology problem and start treating it as a people problem, says Galix.

Cyber security is everyone’s problem. Here’s how to build a security culture that lasts

Cyber security is not just a one-time task for companies in South Africa; it's a long-term challenge that extends beyond mere investment in training programs. Many businesses still view it as a compliance checkbox, leading to forgetfulness and vulnerabilities as threats evolve. To truly secure their operations, companies must shift their perspective, treating cyber security as an integral part of their business operations rather than a standalone issue.

This cultural transformation starts at the top, with leadership visibly championing the cause and supporting those who fall short, rather than punishing them.

Making training personal and relevant is a game-changer. Employees are more likely to prioritize cyber security when they understand how it impacts their personal lives, such as the security of their families, homes, and bank accounts. Using real-world examples from social media or daily activities helps employees relate to the threats they face, turning abstract concepts into practical habits.

However, a one-size-fits-all approach is ineffective. Different departments face unique risks—finance teams are often targeted for fraud and phishing, HR manages sensitive employee data, and IT maintains the technical backbone of the organization. Each department requires training tailored to its specific risks.

The training regimen should consist of several layers, including baseline training on password hygiene and phishing awareness for everyone, role-specific content, scenario-based learning that emphasizes consequences, and regular refreshers to keep up with the evolving threat landscape. This approach doesn't necessitate expensive customized systems; organizations can leverage real-world incidents and existing tools to enhance their training programs.

Artificial intelligence (AI) is increasingly being used to deliver security training, offering personalized content, threat simulations, and scalable awareness programs. However, caution is advised. While AI can enhance training, it also introduces risks, such as employees unintentionally exposing sensitive data when interacting with AI tools.

Organizations must ensure that AI-driven training remains grounded in real-world scenarios and is not solely reliant on automated content.

Ultimately, the effectiveness of cyber security training hinges on whether employees act on the knowledge they gain. Training should aim to instill emotional impact, making the potential consequences of lapses tangible and real rather than just intellectual. Experiential learning, such as simulated phishing tests and mock ransomware incidents, can help employees develop the critical thinking and skepticism needed to identify and respond to threats effectively.

Encouraging a culture of seeking help and advice from experienced cybersecurity professionals rather than relying on quick online searches is also vital. In essence, cyber security awareness is not just a program; it's a mindset that requires ongoing commitment, relevance, and the recognition of every employee as the first line of defense against cyber threats.

Written by urgent.news from ITWeb's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at itweb.co.za →

More in Tech

More from Tuesday 6 October →