Security Awareness Training

    Why it's time to re-envision security behavior management

    A real solution that transforms the way organizations mitigate employee risk

    by Kurt Werner  

    Key Points

    • Research shows that 80% of security issues are actually caused by just 8% of users.
    • While effective, even the most up-to-date security solutions fail to address the biggest risk – human error – in a practical and useful manner.
    • Mimecast’s Human Risk Command Center changes all of this – allowing security admins to very easily identify the users that pose the most risk.

    Only 8% of users cause 80% of security issues. While all users should be mindful of potential cyberattacks during the conduct of their daily tasks, the fact remains that organizations must properly identify the users that pose the most risk, and be able to take action.

    Organizations tend to invest in disconnected security point products, and while some invest in legacy security awareness training, they should be ensuring that their investment dollars are going towards security behavior management.

    Security awareness training vs. security behavior management

    Security awareness training focuses on informing employees—delivering knowledge about threats, policies, and best practices through courses, videos, and phishing simulations. Success is typically measured by completion rates and quiz scores. It answers "do people know what to do?"

    Security behavior management goes further, focusing on actually changing what people do. It uses behavioral science, personalized nudges, real-time interventions, risk scoring, and ongoing measurement of actual actions (not just knowledge) to drive lasting habit change. Success is measured by observed behavior—fewer risky clicks, faster reporting, better password hygiene—rather than course completion.

    Organizations tend to unwittingly create an environment with security professionals who cannot differentiate risk across employees because they lack the right tools to do so, and frustrated end users who ignore continuous security warnings and bypass disparate controls.

    Ours is an increasingly connected world and employees have access to a myriad of collaboration tools and unlimited access to organizational data, making them prime targets for complex attacks such as phishing and other forms of business email compromise (BEC). In addition, they are constantly multi-tasking and have multiple tools open at the same time. All of these factors make users more prone to errors, and traditional security measures often fall short in addressing these human-centric risks, leading to significant vulnerabilities.

    A command center for human risk
    Traditional security behavior management only measures simulated risk and training engagement – it doesn't measure real risk. To effectively manage human risk, security teams need visibility into employees' real actions, not just simulated phishing and training engagement metrics. Fortunately, at the time when it is needed most, an evolution of risk mitigation – the Mimecast Human Risk Command Center – addresses many of these issues.

    A connected HRM platform is built on a central risk engine and is designed to prevent the evolving and sophisticated threats targeting human error within organizations. The HRM platform offers preventative controls and the ability to take direct actions that mitigate the risk associated with human behavior such as clicking a link that downloads malware, opening malicious attachments, or visiting a website with malicious content.

    In response to customer and market demand for a more effective means of mitigating risk brought on by employee mistakes and user errors, the Mimecast Human Risk Command Center provides unprecedented visibility into an organization's risk profile, scoring users by risk and allowing CISOs to educate and protect the riskiest part of their employee base.

    Human Risk Command Center: unparalleled visibility
    Security teams can surface and centralize risk signals through the Human Risk Command Center. This provides security teams with human risk scoring and visibility based on event data from both native metrics as well as data from third-party tools. Advanced risk scoring assigns risk scores to users, empowering security teams to prioritize efforts on the most vulnerable points within their human network.

    In addition, the Command Center quantifies attack factors measuring the frequency and severity of inbound threats, including analysis of inbound phishing attempts, blocked malware, malicious web content loaded by visited websites, and more. With full visibility into this data, organizations and security professionals can tailor user-specific security strategies, including behavior management initiatives that provide more training to those who need it and less to those who don't.

    Integrating security behavior management
    A key function of the Human Risk Command Center is to integrate findings into an organization's security behavior management program. This redefines how security leaders can manage human risk. Traditional security behavior management programs take a standardized approach, rendering IT leaders unable to identify high-risk employees or effectively mitigate their risky behavior. 

    Now, security professionals can eliminate blind spots by offering extensive visibility into employees' risky behaviors powered by the Human Risk Command Center to adapt interventions to each individual's unique risk profile. Proactive interventions – including real-time Slack and Teams notifications and personalized behavioral nudges – correct risky behaviors and reinforce secure practices at the point of risk. This approach also helps increase productivity as lower risk employees are interrupted far less with training tasks, enabling them to focus on more critical business activities.

    The bottom line
    The Human Risk Command Center is revolutionizing how organizations manage human risk.

    Mimecast is leading the way. Our mission to advance security and transform the way organizations manage and mitigate risk is bolstered by our very own platform, our Human Risk Command Center, and Mimecast Engage. By integrating security into the very fabric of human interaction, organizations can set a new standard for protection in an increasingly complex digital world.

    For more information on how you can benefit from Mimecast's behavior risk management solutions, visit our Mimecast Engage website page.

     

     

    **This blog has been updated from a previous version.

    Subscribe to Cyber Resilience Insights for more articles like these

    Get all the latest news and cybersecurity industry analysis delivered right to your inbox

    Sign up successful

    Thank you for signing up to receive updates from our blog

    We will be in touch!

    Ready to secure the human layer? REQUEST A DEMO
    Back to Top