Mitarbeitenden-Sensibilisierung

Employee awareness

Individual employees are the last line of defence in corporate IT security. In addition to technical precautions, ongoing training and awareness-raising among employees are important factors in protecting against cyber risks. As part of an employee awareness programme, everyone in your company – from the CEO to interns – is made aware of cyber risks and how to deal with suspicious activity.

 

What does this mean in detail?

  • Employees can significantly improve your company’s cyber security at several points of attack.
  • A large number of cyber attacks on companies are carried out via email. In addition to technical measures, sensitised employees are an important protection against the success of such attacks.
  • Aware employees can also protect your company’s security in seemingly harmless situations, e.g. by handling USB sticks with care, managing passwords wisely and exercising caution when using social media in their private lives.

 

Where do I encounter this issue in my everyday work?

It happens quickly in everyday working life: an email attachment is opened because it appears to contain an invoice from a service provider. But it is actually malware that can encrypt the entire network and render it unusable (ransomware). If your employees are aware of this method used by cybercriminals, they will examine such emails more critically and thus prevent cyber incidents. A customer’s USB stick can also quickly be connected to a work computer to transfer a document. However, without the customer’s knowledge, the USB stick may contain malware that cybercriminals could use to spy on data traffic. If employees are aware of this, they will first check external USB sticks with a virus program, which in most cases will find the malware and render it harmless.

 

What can I do to improve my security?

Ideally, regular training courses should be held to raise employee awareness. Specialised service providers are a good point of contact for covering as many aspects of IT security as possible. Digital learning systems have also proven effective. These can be used more flexibly by employees than fixed training dates. But every measure improves cyber security compared to the current status. In the time leading up to professional employee awareness training, you can already identify important starting points for your company and take easy-to-implement measures.

 

Examples could include:

  • Raising awareness of the critical handling of emails, including phishing simulations
  • Raising awareness of the careful use of USB sticks
  • Raising awareness of the use of IT devices that are used for both private and professional purposes (e.g. smartphones)
  • Raising awareness of locking work computers when away from the desk