3 ms·
I don't find it very surprising that providers of security awareness programs don't agree with Schneier's arguments against their offering. But since they have
by febeling 14y ago
I don't find it very surprising that providers of security awareness programs don't agree with Schneier's arguments against their offering.
But since they have a strong financial incentive to disagree with him I'm doubtful about their arguments.
Their arguments were also not convincing to me. Let me quote a random and very shallow bit from the first linked post:
"An education and awareness PROGRAM is not a one hour CBT and clicking through something. It’s education and awareness just like your HR department helps you navigate to your expenses."
That sounds desperate.
- iuguy 14y ago> I don't find it very surprising that providers of security awareness programs don't agree with Schneier's arguments against their offering. Erm... I wasn't talking about commercial providers of security awareness programmes. I'm talking about people who work in security who actually implement security awareness programmes as part of their security management processes, and the risk of a higher up being convinced that it's not worthwhile because schneier said so. I've actually had a phone call this morning with one of my clients where this article was raised as justification for cutting the security budget next year by reducing spend on security awareness. This is for a major european defence manufacturer who's under pretty much constant attack by people looking to steal their IP. In reference to your quote, that's not desperate, it's fact. A proper security awareness programme is created and maintained by the organisation itself on the basis of trying to find the best way to counter the threats the organisation faces. Some organisations will find that the need for this is relatively low and that the biggest threats they face are things like password sharing and internal things with disgruntled employees. Others may find that they're under constant attack from external threat actors and need to train people to help support their detection capability. In either situation it's definitely not a one hour CBT, it's more complex, it's more nuanced and it's ongoing.