A Study of Different Awareness Campaigns in a Company

08/29/2023
by   Laura Gamisch, et al.
0

Phishing is a major cyber threat to organizations that can cause financial and reputational damage, threatening their existence. The technical measures against phishing should be complemented by awareness training for employees. However, there is little validation of awareness measures. Consequently, organizations have an additional burden when integrating awareness training, as there is no consensus on which method brings the best success. This paper examines how awareness concepts can be successfully implemented and validated. For this purpose, various factors, such as requirements and possible combinations of methods, are taken into account in our case study at a small- and medium-sized enterprise (SME). To measure success, phishing exercises are conducted. The study suggests that pleasant campaigns result in better performance in the simulated phishing exercise. In addition, significant improvements and differences in the target groups could be observed. The implementation of awareness training with integrated key performance indicators can be used as a basis for other organizations.

READ FULL TEXT
research
10/23/2019

A Strategic Cyber Crime and Security Awareness Information System using a Dedicated Portal

A real time portal (www.ganamoscybersecure.org) to enlighten people on h...
research
12/12/2021

Evaluation of Security Training and Awareness Programs: Review of Current Practices and Guideline

Evaluating the effectiveness of security awareness and training programs...
research
10/11/2021

Classifying SMEs for Approaching Cybersecurity Competence and Awareness

Cybersecurity is increasingly a concern for small and medium-sized enter...
research
05/01/2020

A Taxonomy of Approaches for Integrating Attack Awareness in Applications

Software applications are subject to an increasing number of attacks, re...
research
10/02/2019

Reviewing National Cybersecurity Awareness for Users and Executives in Africa

There is an unprecedented increase in cybercrime globally observed over ...
research
06/23/2019

Developing cybersecurity education and awareness programmes for Small and medium-sized enterprises (SMEs)

Purpose: An essential component of an organisation's cybersecurity strat...
research
04/08/2022

Gone Quishing: A Field Study of Phishing with Malicious QR Codes

The COVID-19 pandemic enabled "quishing", or phishing with malicious QR ...

Please sign up or login with your details

Forgot password? Click here to reset