are assessed on their likelihood to follow the principles taught. The idea behind awareness training is, Change everyones reflexes, Bihya said. If I see an email Kron recommended that HR departments find with a link, my reflex should be to not click on the ways to automate training assignments and use link. positive messaging when communicating about such programs. Having leadership reinforce the With human error being the path of least resistance importance of education and training programs can for cybercriminals, the need to bring awareness and also improve completion rates and reduce the effort education to employees through security awareness required to ensure people are doing the training. training has been given more priority. It has become Kron favors the deployment of shorter training clear that annual lunch-and-learn trainings are no sessions more often and with a more targeted and longer enough. thought-out approach. While providing people information does have Unlike in the past, different types of training are now value, changing behavior should be the focus of being developed to communicate with employees in an awareness program, said Erich Kron, security the form of games, animation, live-action teaching awareness advocate at cybersecurity training and even season-and episode-formatted shows firm KnowBe4. Education should not be limited that look like high-quality television productions, he to topics that focus on email phishing, but also to said. overall security hygiene, including how to secure accounts with multifactor authentication (MFA) and In addition, AI components are being introduced to how to use tools such as password vaults to create tailor content provided to employees, based on their long, secure, and especially unique passwords. own specific areas of weakness or the latest threat vectors. Another development is point-of-failure The Evolution of Security Awareness Training training to provide real-time guidance as to why an action taken by an employee could be dangerous. In recent years, security awareness training has This helps people better understand the threats evolved to incorporate adult learning principles and they face and the purpose of the policies or security elements such as: controls they may have inadvertently violated, or the reason for the simulated attacks. Continuous awareness, training and education on the cyberthreat landscape. Rather than text, Security awareness has begun to blend into most training modules use audio and visual programs related to physical safety and awareness, elements with characters acting out scenarios Kron said. Just like safety campaigns that have of good and bad behavior. been run for decades to warn people of dangers from machinery, chemicals and other physical An opportunity to apply what has been learned threats, digital dangers will also be addressed in using simulated programs, where fake phishing the same way with signage and coordinated, highly emails are sent out at random times to people visible campaigns. in the organization to see how many are tricked into clicking on malicious attachments and links. Drew Robb is a freelance writer in Clearwater, Fla., specializing in IT and business. Assessments and quizzes. At the end of each section of training, the employee answers a few questions to see if they have understood the concepts. Then at the end of the module, they are assessed on their likelihood to follow the principles taught.