Banks and other financial institutions have always been burdened with a greater need for security than other industries. In the past, that meant hiring 24/7 guards and locking cash away in reinforced bank vaults. Today, it means having best-in-class cybersecurity teams and state-of-the-art detection and response technology.
However, when it comes to preventing data breaches, having the best cybersecurity experts and the fanciest tech isn’t always enough. Here’s how the FDIC puts it in their Framework for Cybersecurity:
“Even the best-designed security controls cannot fully protect a financial institution from one uninformed employee, contractor, or customer who unwittingly visits a malicious Web site, opens a malicious email attachment, or clicks on a malicious email link. Effective cybersecurity awareness programs should educate employees, contractors, and customers about the threat environment and encourage them to “Think Before You Click.”
Here are some steps security leaders at financial institutions can take to create a cybersecurity awareness culture at their organization:
Understand the Risks
According to Verizon’s 2018 Data Breach Investigations Report, Trojan botnets and denial of service attacks are by far the most common action varieties in financial industry data breaches. However, once these incidents are accounted for, phishing is a factor in many of the remaining cases. Email is still the method of choice for phishing attacks, playing a role in 96% of reported incidents.
[Get Free Ebook: The Secret to Creating a Cyber Risk-Aware Organization]
For financial institutions, employee behavior while interacting with email is a major risk factor for cyber attacks and data breaches. Creating a cybersecurity awareness culture requires training employees to be more vigilant while using technology, especially when working with email.
Go Beyond Training
Security awareness training is an increasingly popular service, and most financial institutions require their employees to undergo some kind of awareness training. However, training alone isn’t enough to truly create a cybersecurity awareness culture.
Whether it’s conducted in seminars, meetings, or online, security awareness training is typically focused on increasing the knowledge of employees. It might teach them about the consequences of falling prey to a phishing attack, or methods for spotting suspicious emails. However, this information is likely to fall on deaf ears if an organization does not also foster feelings of responsibility and accountability for cybersecurity among employees.
So, how does a security leader go about creating feelings of responsibility and accountability? It starts with being able to show results.
Because success in cybersecurity is proven by a lack of negative results, it’s difficult for employees to feel connected to outcomes in the same way they are in other business areas. Without quantitative evidence of the results of their actions or non-actions, there will inevitably be a loss of motivation, no matter how much training they undergo.