كنا نتحدث قبل قليل مع بعض الزملاء في أحد غرف ال Clubhouse في موضوع ال Cyber Security Awareness , سألخص لكم مداخلتي معهم في هذا الثريد في ٤ نقاط رئيسية أعتقد يجب أن يحتوي عليها أي برنامج للتوعية:
#الامنالسيبراني #أمنالمعلومات
1- Cyber Security awareness programs should target different audience with different content:
- Executives
- Developers
- IT Staff
- End Users
- ......
- Interactive Workshops
- WhatsApp Web as a Risk scenario
- Evil Twin as another Risk scenario
- .....
- Tie it to business units
- Number of phishing attacks per business units
- Behavior Change Metrics
- ......
- Wall of Fame
- Employee of the month
- Financial Incentive
- .....
2- Awareness should be practical and interactive with the user e.g. :
3- Awareness should be measured using metrics:
4- Rewarding Employees Who DID change their practice and behavior :