home.social

#security-awareness-training — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #security-awareness-training, aggregated by home.social.

fetched live
  1. Being subjected to some 'security training' at work, like "how to spot false domains" and "phising emails".

    The courses are so poor that I think they harm more than they benefit because people fall into false sense of security of their ability to spot them because it's so easy in the training.
    It's just "next, next, next - pick obvious silly answer - next next next".
    No need to read or think about the material.

    It's mandatory to fulfil safety standards measurements, but such training does not need to be so poorly made - it just makes it more dangerous than not.

    And yes, I know some people fall for the obvious and that we as tech people are more knowledgable, but still.....just targeting lowest common denominator is not a good benchmark.

    #phising #securityAwarenessTraining #spam

  2. Today I referred to my SEcurity AWareness TRaining program as "SEAWTR" pronouncing it Sea Otter. No one knew what the hell I was talking about. And apparently I'm the crazy one?

    #infosec #seaotters #cybersecurity #securityawarenesstraining

  3. Learn to let certifications expire when they’re no longer needed. For example, I received my second reminder email today:

    “Your credential for Logical Operations Certified Virtual Educator (CVE) will expire on 2023-07-03. If you haven't already, you should start the renewal process with CertNexus.”

    At the beginning of the pandemic I thought it might be useful to take a class on teaching in a virtual environment. I'm glad I did. I got lots of useful tips and advice from this course, and many of the things I learned are now automatic for me. I do them all the time, in all of my virtual course preparation and delivery.

    But…

    No one has ever asked me if I’m a Certified Virtual Educator.
    No one has ever asked me for proof of certification.
    My certificate has not “clinched the deal” with any student or business.

    So…

    I’m not spending money on renewal.
    I’m not taking the time to study for a refresher.
    I’m not taking the exam again.

    Be aware, there are times when you should absolutely renew your certifications.

    If there have been lots of changes in a particular domain of expertise, keep your training current. Using Certified Virtual Educator as an example, let’s suppose that VR headsets become a routine part of virtual education. That’s a significant change, and it would be well worth my time and money to get some training on how to make the most effective use of that technology for education.

    Maybe next year, or the year after that. But not yet.

    #callmeifyouneedme #fifonetworks

    #onlinecourses #cybersecurity #informationtechnology #securityawarenesstraining

  4. Attack Simulation Training is an intelligent phish risk reduction tool that now provides enhanced user telemetry to enable administrators to view additional details on how their targeted users are interacting with the phishing payload from simulation campaigns. It also allows users to measure behavior change and automate the deployment of a security awareness training program across an organization. techcommunity.microsoft.com/t5 #AttackSimulation #PhishRiskReduction #SecurityAwarenessTraining