I have known most of my life that our learning styles can be different and some like to spend their time on lectures, whereas some might rather read a book. And others just want to try it out in their own way. This undermines the premise that giving standard security training to the whole company actually produces the results that we want. But I never really realised how utterly different we all are until I run into Reiss Motivation Profiles and saw how different motivation profiles people can have.
What does this mean in practise? It means that for some people it is enough that there is a rule and they just want to obey it. But even though it works for me, it does not work for everyone. Some people want their superiors to give the needed information, others might rather hear it from the colleagues or come up stuff on their own. Some might do things to improve their status and others to save the world. Some like games and competitions and others hate them. If we do not accept this, we will not succeed in motivating people to take security seriously enough. And this means that we need to adopt a multitude of approaches.
Generic security awareness training is a start. Role-based learning programs improve the situation a bit as they aim to take into account what information people already have and what information might be relevant in their roles. Some want to get the slides, others might rather watch the video. And everyone should pass some kind of a test at the end to verify that they actually learned something. To make it even more personal, you can use security dialogues I talked about in earlier blog post. But even that is typically one time shot that fades a way quite quickly in everyday life.
To succeed to you need to use multiple channels and repetitions - stickers, hoodies, posters, blog posts, chats, info sessions, podcasts, emails remainder, incident rehearsals, sharing examples of phishing messages, news sessions, security walks, coffee area table stands, tin foil hats, lessons learned from real life incidents, cyber weather, weekly meeting agendas, security checklists, yearly targets, … Basically anything that keeps the security in the upper part of you daily list and not just as an after thought. And on special occasions you can also sing about it :).
I’m dreaming of secure Christmas
Just like the ones I’ve never known
Where defences glisten, employees listen
To hear what CISOs may have shown
I’m dreaming of secure Christmas
With every threat model I write
May your protection layers endure
And may all your Christmases be secure
Secure Christmas for everyone!