Contributor

Good vs Bad Security Awareness Training

Opinion
Jul 31, 20082 mins

Every corporate policy on security I have seen and most best practice guides demand an active security awareness training program.  I have never been a fan of the concept because it seemed like perfectly good money being wasted both in hard dollar terms (the cost of training material, posters, CBT, and teachers) and the soft but equally real costs (taking people away for from their jobs on an annual basis).

But it has been pointed out (by me) that most of what I do: public speaking, this blog, and my columns is actually security awareness training as I inveigle corporate leaders to pay more attention to the threats from cyber criminals, extortionists, and now spying nation states.

So, yes, there is good security awareness training. But I do not include teaching Bobby in reception how to avoid being taken in by Kevin Mitnick.  It is futile and silly to expect your average employee to become paranoid enough to ward off social engineering attacks.  Rather than invest in posters in the elevators exhorting people to stop strangers in the hallway, you should be investing in better security technology.  Need to train people to change their passwords every three weeks? Just institute an Identity and Access Management solution that forces them to.  Need stronger passwords?  Go for one time tokens.

What kind of security awareness training do I like? I love training IT administrators and developers in hacking techniques. If they see how simple it is to break in or bypass applications they will institute better controls and write better code.  There are lots of hacker training classes.  I will compile a list and post it here. If you have a favorite class let me know either by email or leave a comment.  

Richard Stiennon is chief research analyst at IT-Harvest, the firm he founded in 2005 to cover the 1,600 vendors that make up the IT security industry. He is the author of Surviving Cyberwar (Government Institutes, 2010) and There Will Be Cyberwar: How the Move to Network-Centric Warfighting Set the Stage for Cyberwar. He is a member of the advisory board at the Information Governance Initiative and principal of TrueBit Cyber Partners. He also serves on the R2-TAC, the technical advisory committee for the Responsible Recycling standard for e-waste.

Stiennon was chief marketing officer for Fortinet Inc. and vice president of threat research at Webroot Software. Prior to that, he was vice president of research at Gartner Inc. He has a B.S. in aerospace engineering and an M.A. in war in the modern world from King’s College, London.

The opinions expressed in this blog are those of Richard Stiennon and do not necessarily represent those of IDG Communications Inc. or its parent, subsidiary or affiliated companies.

More from this author