{"id":42329,"date":"2020-11-12T11:17:26","date_gmt":"2020-11-12T19:17:26","guid":{"rendered":"https:\/\/www.enxmag.com\/twii\/?p=42329"},"modified":"2020-11-12T11:17:28","modified_gmt":"2020-11-12T19:17:28","slug":"university-research-shows-security-awareness-training-is-a-necessary-layer-of-defense","status":"publish","type":"post","link":"https:\/\/www.enxmag.com\/twii\/the-week-in-imaging-twii\/editors-blog\/2020\/11\/university-research-shows-security-awareness-training-is-a-necessary-layer-of-defense\/","title":{"rendered":"University Research Shows Security Awareness Training is a Necessary Layer of Defense"},"content":{"rendered":"\n<div class=\"wp-block-image\"><figure class=\"alignleft\"><img loading=\"lazy\" width=\"300\" height=\"197\" src=\"https:\/\/www.enxmag.com\/twii\/wp-content\/uploads\/2020\/11\/KnowBe4-Pic.jpg\" alt=\"\" class=\"wp-image-42330\"\/><\/figure><\/div>\n\n\n\n<p>A research paper in the <em>Journal of Computer Information Systems<\/em> says that security awareness training is a necessary complement to technical defenses and security policies, SC Magazine reports. Published by researchers from the University of Sussex and the University of Auckland, the paper acknowledges that technical defenses can help, but they can\u2019t influence the human behavioral responses targeted by social engineering.<\/p>\n\n\n\n<p>Hamidreza Shahbaznezhad, a co-author of the report and senior data scientist in industry at the University of Auckland, said in a press release that technical defenses are helpful but not comprehensive.<\/p>\n\n\n\n<p>\u201cAlthough technical countermeasures such as anti-phishing and spamming tools, email malware detection and data loss prevention are deployed to mitigate the risk of phishing attacks, using these technologies to detect phishing attacks remains a challenging problem,\u201d Shahbaznezhad said. \u201cThis is not least because they often require human intervention to analyze and distinguish between phishing and legitimate emails.\u201d<\/p>\n\n\n\n<p>Dr. Mona Rashidirad, co-author and lecturer in strategy and marketing at the University of Sussex Business School, added that awareness training needs to be factored into organizations\u2019 security budgets.<\/p>\n\n\n\n<p>\u201cSecurity safeguards alone will not protect a company from phishing scams,\u201d Dr. Rashidirad said. \u201cOrganizations and individuals substantially invest in security safeguards to protect the integrity, availability, and confidentiality of information assets. However, our study supports the findings of recent studies that these safeguards are not adequate to provide the ultimate protection of sensitive and confidential information.\u201d<\/p>\n\n\n\n<p>The researchers write that training programs should teach employees how to think about their own behavior, and how attackers can manipulate them.<\/p>\n\n\n\n<p>\u201cIndeed, security practitioners should aim such information security awareness programs to inform users about intrinsic and extrinsic factors which can influence their behavior,\u201d the paper says. \u201cTherefore, employees can be more vigilant to understand how cybersecurity criminals can exploit employee\u2019s perception from different individual\/motivational, organizational, and technological perspectives. Employees may need to know about the existing security arsenals alongside with the security risks that could be exploited by malicious attackers.\u201d<\/p>\n\n\n\n<p>Organizations need to implement a combination of technical solutions, security policies, and employee training to combat these threats. New-school security awareness training can enable your employees to defend themselves against social engineering attacks.<\/p>\n\n\n\n<p><em>This blog originally appeared on <\/em><a href=\"http:\/\/knowbe4.com\"><em>KnowBe4<\/em><\/a><em>.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A research paper in the Journal of Computer Information Systems says that security awareness training is a necessary complement to technical defenses and security policies, SC Magazine reports. Published by researchers from the University of Sussex and the University of Auckland, the paper acknowledges that technical defenses can help, but they can\u2019t influence the human behavioral responses targeted by social engineering. Hamidreza Shahbaznezhad, a co-author of the report and senior data scientist in industry at the University of Auckland, said in a press release that technical defenses are helpful but not comprehensive. \u201cAlthough technical countermeasures such as anti-phishing and spamming tools, email malware detection and data loss prevention are deployed to mitigate the risk of phishing attacks, using these technologies to detect phishing attacks remains a challenging problem,\u201d Shahbaznezhad said. \u201cThis is not least because they often require human intervention to analyze and distinguish between phishing and legitimate emails.\u201d Dr. Mona Rashidirad, co-author and lecturer in strategy and marketing at the University of Sussex Business School, added that awareness training needs to be factored into organizations\u2019 security budgets. \u201cSecurity safeguards alone will not protect a company from phishing scams,\u201d Dr. Rashidirad said. \u201cOrganizations and individuals substantially invest in security safeguards to protect the integrity, availability, and confidentiality of information assets. However, our study supports the findings of recent studies that these safeguards are not adequate to provide the ultimate protection of sensitive and confidential information.\u201d The researchers write that training programs should teach employees how to think about their own behavior, and how attackers can manipulate them. \u201cIndeed, security practitioners should aim such information security awareness programs to inform users about intrinsic and extrinsic factors which can influence their behavior,\u201d the paper says. \u201cTherefore, employees can be more vigilant to understand how cybersecurity criminals can exploit employee\u2019s perception from different individual\/motivational, organizational, and technological perspectives. Employees may need to know about the existing security arsenals alongside with the security risks that could be exploited by malicious attackers.\u201d Organizations need to implement a combination of technical solutions, security policies, and employee training to combat these threats. New-school security awareness training can enable your employees to defend themselves against social engineering attacks. This blog originally appeared on KnowBe4.<\/p>\n","protected":false},"author":178,"featured_media":42330,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[80,1650,82,1638],"tags":[3815],"_links":{"self":[{"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/posts\/42329"}],"collection":[{"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/users\/178"}],"replies":[{"embeddable":true,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/comments?post=42329"}],"version-history":[{"count":1,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/posts\/42329\/revisions"}],"predecessor-version":[{"id":42331,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/posts\/42329\/revisions\/42331"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/media\/42330"}],"wp:attachment":[{"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/media?parent=42329"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/categories?post=42329"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/tags?post=42329"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}