166 terms · 75/46/45
Defense № 037 · class: people

Security Awareness

Employee education programs about cyber threats and safe behavior.

Term

description · examples · notes

Employee education programs about cyber threats and safe behavior.

Description

Cover phishing recognition, password management, and incident reporting.

Delivered through training, posters, internal campaigns, and quizzes.

Measurable results include phishing simulation click rates.

Regulatory requirements (ISO 27001, NIS2) mandate regular programs.

What people often say

  • Annual training is not enough — a continuous campaign is needed.
  • Awareness does not replace technical controls but significantly reduces human risk.

Covers / does not cover

Covers

  • Phishing recognition
  • Safe password practices
  • Reporting suspicious activities

Does not cover

  • Technical system protection
  • Detection and response to attacks
  • Protection from insiders with technical knowledge

Mentioned in the news

Composite

Threats

reduces 21

Techniques

neutralizes 6