Thank you for Subscribing to CIO Applications Weekly Brief
A featured contribution from Leadership Perspectives, a curated forum for enterprise technology leaders, nominated by our subscribers and vetted by the CIOApplications Editorial Board.

Tebsa
Antonio Hernández Jaimes, Director Of Information Security And Cybersecurity
Security Awareness Challenges


Most cyberattacks have a vector related to social engineering and, therefore, seek to ‘hack’ the human, before ‘hacking’ a system. In fact, it might be easier, since all human beings are curious, responding to ego, sympathy, fear, or intimidation.
All cybersecurity reference frameworks, standards and good practice guides contemplate and require awareness programs as a fundamental axis to protect processes and information, indicating that employees must be trained at the time of hiring and during their stay in the company, and, that reinforcements be made in positions that handle sensitive or confidential information. Habeas data laws have toughened these demands on companies to protect the privacy of the owners.
• The culture of the organization. Every organization has a ‘personality,’ just like human beings. We must understand that to design our awareness program. It is not the same as talking to lawyers, doctors or engineers.
• Know which are the media in which the messages to be disseminated have the best effect: email, social networks, intranet, information screens, etc.
• Understand the roles, processes, and responsibilities of employees for all functions. Someone who works operating a forklift, for example, is not the same as someone who files invoices in the treasury office. They work in different environments, operate different systems, and are exposed to different risks. Also, they may respond differently to a malicious message. And cybercriminals know this.
• Work as a team with areas with human talent, human management, and internal communications, to design efficient and effective awareness strategies.
Cybercriminals are reinventing themselves and using increasingly sophisticated techniques
• Motivate employees to participate in cybersecurity awareness program activities. Use mentoring and rewards programs.
• Test, test and test, to be able to measure. ‘What is not measured cannot be improved.’ It is necessary to define indicators associated with auto phishing campaigns that show a path of continuous improvement.
Cybercriminals are reinventing themselves and using increasingly sophisticated techniques. CISOs must be creative to improve our protection posture and contain these threats. Mature cybersecurity awareness programs achieve global commitment from all employees, who understand that security is not just a matter of the CISO or his team, but of all employees in the company.

