
In an era where cyber threats are increasingly sophisticated and relentless, organizations must fortify their defences, not just with advanced technology, but with informed and vigilant employees. At Cresset, we recognize our people are our first line of defence against cyber threats. Continuous employee training is not just a policy, but a pivotal component of our cybersecurity strategy.
Mandatory Cybersecurity Awareness Training
Every member of the Cresset team is required to undergo comprehensive cybersecurity awareness training via an interactive online course. This training is designed to:
- Educate employees about the latest cyber threats and how they manifest in day-to-day operations.
- Equip them with the knowledge to recognize and respond appropriately to potential security incidents.
- Ensure compliance with our stringent cybersecurity policies and industry regulations.
At the conclusion of the course, employees must pass a rigorous Q&A assessment to demonstrate their understanding of the material. This isn’t a one-time requirement; staff must retake the course annually and attest to their continued commitment to maintaining our cybersecurity posture.
Real-Life Vigilance: A Culture of Security
Our training programs emphasize practical application, encouraging employees to be vigilant in all situations. A recent incident exemplifies this commitment:
An employee found an unmarked USB stick in the office car park. Being aware of the risks associated with unknown devices and knowing that USB drives are restricted on company devices, the employee refrained from plugging the unmarked USB stick into any computer. Instead, they promptly handed it over to our IT department. This responsible action prevented a potential security breach and sparked a valuable conversation about the importance of constant vigilance.
This incident also serves as a reminder that cyber threats can originate from unexpected places. While we do not employ this tactic ourselves, it’s noteworthy that some security assessment firms use similar methods—such as discreetly placing USB sticks in strategic locations—to test organizational awareness and adherence to security protocols.
Proactive Awareness and Continuous Improvement
To reinforce good practices and ensure our training is effective, we focus on proactive awareness:
Phishing simulations: We periodically send “white hat” phishing emails to our staff. Our goal is to test and improve our employees’ ability to identify and report phishing attempts through these simulated attacks.
Open dialogues: Following incidents like the USB stick discovery, we engage in conversations with employees to discuss the situation and reinforce the correct actions to take. This helps to keep cybersecurity at the forefront of everyone’s minds.
Regular updates: We provide ongoing updates about new cyber threats and best practices, ensuring that our team stays informed about the evolving cybersecurity landscape.
“Think Before You Click”: Our Security Mantra
We have ingrained the philosophy of “Think Before You Click” into our corporate culture. This simple yet powerful mantra serves as a constant reminder for employees to exercise caution with emails, links, and attachments, which are common vectors for cyber-attacks.
The Impact of Continuous Training
Our dedication to employee education has yielded significant benefits:
- Enhanced Security Posture: With a well-informed workforce, we have strengthened our defences against cyber threats.
- Reduced Risk of Breaches: Proactive training and awareness initiatives have minimized the likelihood of security incidents caused by human error.
- Regulatory Compliance: Ongoing education ensures that employees are up to date with industry regulations and internal policies.
Conclusion
At Cresset, we understand that technology alone cannot safeguard our organization. By placing continuous employee training at the heart of our cybersecurity strategy, we empower our people to act as vigilant guardians of our sensitive data.
Our approach shows that educating and engaging employees turns them into invaluable assets in defending against cyber threats. As we navigate the evolving cybersecurity landscape, we remain committed to fostering a culture where we equip and motivate every team member to contribute to our collective security.