Security Awareness
Employee education programs about cyber threats and safe behavior.
Term
description · examples · notesEmployee education programs about cyber threats and safe behavior.
Description
Cover phishing recognition, password management, and incident reporting.
Delivered through training, posters, internal campaigns, and quizzes.
Measurable results include phishing simulation click rates.
Regulatory requirements (ISO 27001, NIS2) mandate regular programs.
What people often say
- Annual training is not enough — a continuous campaign is needed.
- Awareness does not replace technical controls but significantly reduces human risk.
Covers / does not cover
Covers
- Phishing recognition
- Safe password practices
- Reporting suspicious activities
Does not cover
- Technical system protection
- Detection and response to attacks
- Protection from insiders with technical knowledge
Mentioned in the news
Threats
reduces 21Threats it reduces. Select one to open its page.
- Infostealer→
- Spear Phishing→
- Phishing→
- Accidental Data Leak→
- Credential stuffing→
- Whaling→
- SMS phishing - Smishing→
- Password spraying→
- Typosquatting→
- MFA Fatigue→
- SIM Swapping→
- Evil Twin→
- QR phishing - Quishing→
- Virus→
- Deepfake Attack→
- Pretexting→
- voice phishing - Vishing→
- Keylogger→
- Physical Access Attack→
- Crypto-wallet drainer→
- USB Drop Attack→
Techniques
neutralizes 6Techniques it neutralizes. Select one to open its page.