An editorial piece by Jaded Security on why security-awareness training tends to fail and where security budgets are better spent.
Controversial opinion: traditional security-awareness training for employees is largely a waste of time and money.
Before the pitchforks come out, the position is not that employees should be ignorant about security. The position is that the way most organisations approach security training is fundamentally flawed.
The typical approach: once a year, force everyone through a PowerPoint presentation or online module. Check the compliance box. Move on. Then act surprised when someone clicks a phishing link the next day.
The problem is not the employees. The problem is the design. Asking humans to be perfect security sensors in an environment where the attacks are specifically engineered to exploit human psychology is not a training problem — it is a design problem.
Instead of spending millions on awareness training, invest in:
- Better email filtering and sandboxing
- Removing admin rights from end users
- Application whitelisting
- Network segmentation
- Automated patch management
Design the systems so that when — not if — an employee makes a mistake, the blast radius is contained. That is a much better investment than another round of “don’t click suspicious links” training.