SHARE
Facebook X Pinterest WhatsApp

Expectations vs. Reality: Five Ways to Improve Cybersecurity Awareness

Raising awareness and training employees on cybersecurity is hard. It’s draining. It’s thankless. And all too often, it’s ineffective. A big part of the problem is that IT approaches it with unrealistic expectations, and with tactics and messaging that may resonate with them, but not their audience. As a result, there’s often a disconnect between […]

Written By
thumbnail
ITBE Staff
ITBE Staff
Oct 6, 2015

Raising awareness and training employees on cybersecurity is hard. It’s draining. It’s thankless. And all too often, it’s ineffective. A big part of the problem is that IT approaches it with unrealistic expectations, and with tactics and messaging that may resonate with them, but not their audience. As a result, there’s often a disconnect between the security team’s motivations and priorities and those of the rest of the company.

In an ideal world, IT would be recognized by management and co-workers as the esteemed guardians of the system and sage-like purveyors of critical knowledge they clearly are. The reality is a little bit different. However, security experts can take steps to bridge the gap and help to reinforce best practices among their colleagues. In this slideshow, Jack Danahy, co-founder and CTO of Barkly and 25-year veteran of the security industry, has identified steps you can take to improve cybersecurity in your organization.

Expectations vs. Reality: Five Ways to Improve Cybersecurity Awareness - slide 1

Improving Cybersecurity

Click through for five steps you can take to improve cybersecurity in your organization, as identified by Jack Danahy, co-founder and CTO of Barkly.

Expectations vs. Reality: Five Ways to Improve Cybersecurity Awareness - slide 2

User Adoption

Expectation: Everybody will do what’s right: our people, and the people and organizations we partner with too.

Reality: “Right” doesn’t always mean safer. It’s often about being cheaper, easier or faster.

Try this: When security teams make better security available, there is a misconception that the rest of the company will quickly and willingly adopt it. Because this is a new domain for many employees, don’t judge those who don’t understand it. Instead, expose and explain – in layman’s terms – security choices, and create avenues to reinforce these values.

Expectations vs. Reality: Five Ways to Improve Cybersecurity Awareness - slide 3

Computer-Based Training

Expectation: We can knock out security training in a one-and-done computer-based training (CBT).

Reality: Effective training requires consistent reinforcement and exposure to real-world scenarios.

Try this: Think of CBT as one of many tools in your tool box. Realistic phishing tests that show what it is like to get phished and how to report it will help employees better understand security processes and emphasize positive security practices.

Expectations vs. Reality: Five Ways to Improve Cybersecurity Awareness - slide 4

Make It Personal

Expectation: Name-dropping big, scary breaches in the headlines will hit home.

Reality: No one cares because it happened to someone else.

Try this: Make training and security education personal. Give examples of breaches that have occurred, how they could have been prevented and what the damaging effects were.

Expectations vs. Reality: Five Ways to Improve Cybersecurity Awareness - slide 5

Outline Consequences

Expectation: Security is one of every employee’s top priorities.

Reality: They have jobs to do.

Try this: Continually drive home the message that data equals cash. Lax security that results in a loss of data equates to poor business performance. This affects raises, promotions and job security.

Expectations vs. Reality: Five Ways to Improve Cybersecurity Awareness - slide 6

Be Clear

Expectation: We speak the same language.

Reality: We might as well be speaking Blorg.

Try this: Educating your colleagues doesn’t mean that they will become security experts. Avoid acronyms and jargon-heavy emails. Be clear and concise when explaining security warnings employees should watch for, and provide simple instructions for how they should handle them.

Recommended for you...

Unifying Data Management with Data Fabrics
Litton Power
Jun 17, 2022
5G and Industrial Automation: Practical Use Cases
Kashyap Vyas
Apr 22, 2022
Understanding the Relationship Between 5G and Edge Computing
Collins Ayuya
Apr 19, 2022
Building a Private 5G Network for Your Business 
Kihara Kimachia
Apr 18, 2022
IT Business Edge Logo

The go-to resource for IT professionals from all corners of the tech world looking for cutting edge technology solutions that solve their unique business challenges. We aim to help these professionals grow their knowledge base and authority in their field with the top news and trends in the technology space.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.