• Skip to primary navigation
  • Skip to main content
  • Skip to footer
  • Vancouver, WA
  • (360)-567-4950
  • Austin, TX
  • (512)-522-5834
  • info@centerlogic.com
  • Customer Portal
  • Facebook
  • Instagram
  • LinkedIn
  • Pinterest
  • Twitter
  • YouTube
Centerlogic IT Services

Centerlogic IT Services

The Customized IT Service Experience

  • IT Services
    • Managed IT Services
    • Managed Cybersecurity
    • Cloud Hosting Services
    • Website Hosting
    • Disaster Recovery
    • Business VoIP
    • Payment Processing
  • Industries We Serve
    • Small Business IT Support
    • Medical IT Solutions
    • Nonprofit IT Solutions
    • Hospitality IT Solutions
    • Government IT Solutions
  • Why Centerlogic?
    • About Us
    • Our Process
    • Careers
  • Resources
    • Customer Portal
    • Centerlogic Forms
    • Cybersecurity for Small Business
    • Blog
  • Contact
  • Support

How often should employees be trained on cybersecurity practices?

Aug 2, 2022 Blog

You’ve just completed your annual phishing training where you teach employees how to spot phishing emails. You’re feeling good about it, until about 5-6 months later when your company suffers a costly ransomware infection because someone clicked on a phishing link.

You wonder why you seem to need to train on the same information every year, and yet still suffer from security incidents. The problem is that you’re not training your employees often enough.

People can’t change behaviors if training isn’t reinforced regularly. They can also easily forget what they’ve learned after several months go by.

So, how often is often enough to improve your team’s cybersecurity awareness and cyber hygiene? It turns out that training every four months is the “sweet spot” when it comes to seeing consistent results in your IT security.

Why Is Cybersecurity Awareness Training Each 4-Months Recommended?

There was a study presented at the USENIX SOUPS security conference that looked at users’
ability to detect phishing emails versus how often they were trained on phishing awareness
and IT security.

Employees were tested at several different time increments:• 4-months
• 6-months
• 8-months
• 10-months
• 12-months

It was found that four months after their training, they were still able to accurately identify and
avoid clicking on phishing emails.

However, after 6-months, their scores started to get worse. Then they continued to decline further the more months that passed after their initial training.

So, to keep employees well prepared to act as a positive agents in your overall cybersecurity strategy, it’s important they get training and refreshers regularly.

Tips on what & how to train employees to develop a cybersecure culture

The gold standard for employee security awareness training is to develop a cybersecure culture.
This is one where everyone is cognizant of the need to protect sensitive data, avoid phishing
scams, and keep passwords secured.

Unfortunately, this is not the case in most organizations. According to the 2021 Sophos Threat Report, one of the biggest threats to network security is a lack of good security knowledge and practices.

The report states, “A lack of attention to one or more aspects of basic security hygiene has been
found to be at the root cause of many of the most damaging attacks we’ve investigated.”

Well-trained employees significantly reduce a company’s risk of falling victim to any number of different online attacks.

To be well-trained doesn’t mean you have to conduct a long day of cybersecurity training every four months. It’s better to mix up the delivery methods.

Here are some examples of engaging ways to train employees on cybersecurity that you can
include in your training plan:

• Self-service videos that get emailed once per month
• Team-based round table discussions
• Security “Tip of the Week” in company newsletters or messaging channels
• Training session given by an IT professional
• Simulated phishing tests
• Cybersecurity posters
• Celebrate Cybersecurity Awareness Month in October

When conducting training,
phishing is a big topic to cover, but it’s not the only one. For more information on our recommendations for topics you should include in your cybersecurity meetings, please contact us today, so we can brainstorm.

Footer

Vancouvers Largest Technology Service and Support Company

Centerlogic is the Largest Technology Support and Service Company of Vancouver, WA

Centerlogic is the Largest Technology Support and Service Company of Vancouver, WA in 2017      Centerlogic is a top ranked MSP

Services

  • Managed IT Services
  • Cloud Hosting Services
  • Managed Cybersecurity
  • Cybersecurity Awareness Training
  • Business VoIP
  • Disaster Recovery

Info

  • Careers
  • About Centerlogic

Connect with Us

Vancouver, WA
7414 NE Hazel Dell Ave Ste B, Vancouver, WA 98665
Phone: (360)-567-4950
Email: info@centerlogic.com

Austin, TX
5555 N Lamar Blvd Ste L111, Austin, TX 78751
Phone: (512)-522-5834
Email: info@centerlogic.com

  • Facebook
  • Instagram
  • LinkedIn
  • Pinterest
  • Twitter
  • YouTube

Copyright © 2023 · Centerlogic, Inc · Privacy Policy