3.7 Baseline for Security – Security Awareness Training

Needed capacities or functions - Security Awareness Training

  1. Provide cybersecurity training to all staff at least annually.  

  2. Implement a security awareness training platform to conduct phishing tests, identify risky users, and improve the organization's overall security and risk posture. 

Important Considerations and Best Practices

Research suggests that human error is involved in more than 90% of security breaches. Educating users on security awareness has become increasingly pertinent and helps improve your organization's first line of security protection. 

Cybersecurity training can help protect the organization against cyber threats by training staff to identify potential risks before inadvertently exposing the organization and its client data. 

Cybersecurity experts recommend staff receive Cybersecurity Awareness Training at least once every six months to stay up to date on the latest threats and best practices. 

In addition to staying up to date on the latest threats, shorter, more frequent cybersecurity training combats "training decay" and improves retention of information.