Presentation is loading. Please wait.

Presentation is loading. Please wait.

Employee Security Awareness

Similar presentations


Presentation on theme: "Employee Security Awareness"— Presentation transcript:

1 Employee Security Awareness
Tuesday, April 9, 2019 Louis Stramaglio IT Ops Supervisor

2 Are You Vulnerable? What is the greatest vulnerability in your organization? Electronic Security Perimeter IT Network OT Network Permissions Physical Security

3 YES! Employees End users Clients Customers Contractors

4 Question Does your company have an Employee Security Awareness Program?

5 IT Security Program Understand and comply with company security policies and procedures Be appropriately trained in the rules of behavior for the systems and applications to which they have access Work with management to meet training needs Keep end users aware of actions they can take to better protect their company’s information

6 Security Program Contents
Security Policies Designed to protect the data Business needs Known risks 2. Define responsibilities Who is responsible Staff responsibilities IT/Security responsibilities 3. Establish Processes Monitor the program Review results IRP(Incident Response Plan)

7 Question Do you believe your current Employee Security Awareness Program has Management Buy-in?

8 Management Buy-in Support Budget Reporting Feedback

9 What is Awareness? Not training Addresses concepts and behaviors
Terminology Informational

10 Best Asset/Biggest Vulnerability

11 Create the Awareness Plan
Strategy and Plan Feedback from key groups Assess current materials Create a baseline Review current metrics Analysis of findings and recommendations Current trends Prioritize Schedule, but remain flexible Make it “So Number One”

12 Ransomware

13 We Are Done, Right? Awareness

14 We Are Done, Right? Awareness Training

15 Who Needs Training? Stay flexible End users IT Executives Everyone
Training everyone equally doesn’t always mean training everyone the same way. Stay flexible

16 Where Does Training Come From?
In-house LMS Outsource

17 NOW We Are Done, Right? Awareness Testing & Education Training

18 Why Test Me? Measure your success Report your success to management
Remember, stay flexible Prioritize weak points, add new content Continue the cycle

19 Participant Challenge
Obtain Management buy-in Create your awareness plan based on your IT Security Program Generate a security baseline and prioritize Train everyone Test everyone Stay flexible and prioritize

20 Lou Stramaglio IT Ops Supervisor


Download ppt "Employee Security Awareness"

Similar presentations


Ads by Google