By: Andrew Hettick (Security+, ISACA Cybersecurity Fundamentals)
Publication: The Kansas Banker, February 2018
You have probably heard this before now, but the greatest threat to an organization's information security is the people. Attackers are aware of the human element, and they create schemes to exploit us. The best way to combat this weakness is to train and test employees.
The goal of information security awareness training is to create a change in employee behavior and to create a security-minded culture inside your institution. A change in culture will not happen overnight, and it may take longer for some employees to make adjustments to their behavior, but it is possible.