Beyond the Firewall shines a light on the complexities and challenges surrounding the importance of human behaviour on Cyber Security and Compliance.
We will explore how people are at the center of information security and data protection and the challenges of truly engaging your users to create change in their behaviour.
Your staff’s split-second decisions, like clicking an innocent link, could be the unsuspecting gateway to a security nightmare! Join Christian Hunt and Robert O'Brien as they delve into effective strategies aimed at shaping staff security behaviours and mitigating the risks associated with security missteps. This 45-minute webcast will discuss: • The intricacies of human behaviour and why people make the choices they do. • Common pitfalls in cyber awareness training and techniques to guide staff towards the correct choices. • Behavioural science strategies to fortify your security measures. • The role of senior leadership in setting an example.
Step into the future with our upcoming webcast as we delve into the intricacies of defence strategy in the age of AI and automation. In this 45-minute session, we will navigate through the challenges that lie ahead, shedding light on the indispensable role played by those entrusted with the security of our organisations and societies. Explore: • The looming threat posed by Gen-AI and deepfakes. • The positive aspects of generative AI and its potential benefits. • Who is responsible for confronting and mitigating these evolving risks. • The critical role of a CISO in safeguarding against emerging threats. • Best practices to fortify against the ever-changing landscape of cyber threats.
Cyber attacks are becoming increasingly sophisticated and frequent, making it critical to adopt a proactive approach to cyber security. Listen to our podcast, ‘How to Make Offensive Security your Cyber Defence Superpower’ and explore how you can identify and remediate security vulnerabilities before they can be exploited by attackers. During this 45-minute session, we’ll cover: • Understanding the concept of offensive security and why it’s crucial for cyber security. • How to integrate offensive security to bolster your defence against threats. • The often-overlooked importance of physical security.Guest speaker - Phillip Wylie, Security Solutions Specialist at CYE.
Privileged Accounts = Targeted Accounts. Once compromised, these privileged credentials give hackers the "keys to the kingdom," allowing them to gain access to your most sensitive and critical information. Listen to our podcast, ‘Privileged User Awareness: The Keys to the Kingdom’ and learn the steps you can take to secure privileged user accounts and mitigate risks. During this 45-minute session, we will cover: • The problem with privileged user accounts • How cybercriminals target and exploit privileged users • The steps organisations can take to mitigate risksGuest speaker: Joseph Carson, Delinea’s Chief Security Scientist and Advisory CISO
Social engineering takes many forms, but email continues to be the most attractive attack vector for hackers to get a footing into our personal and professional lives.
In our podcast, "Could Social Engineering Exist Without Email," we will examine why email remains a favoured target for malicious attacks and explore ways for organisations to fortify their defences.
During this 45-minute episode, we will cover:
· The story of renowned social engineer and email prankster James Linton.
· The reasons why email is a prime target for exploitation.
· Best practices for conducting phishing simulations and avoiding a shame culture.
· Strategies for creating effective email awareness campaigns that engage users.
Guest speaker - Social Engineer and Email Prankster, James Linton.
Our smartphones are always an arm’s length away, but how aware are we of the security risks they pose? Smartphones are a portal into our increasingly digital-first lives. Should they fall into the wrong hands, they’re a potential treasure trove of information.
Our podcast, ‘Get Smart about Smartphone Cyber Security’, explores the cyber risks posed by smartphones and how to mitigate them.
This 45-minute podcast discusses:
• The impact smartphones have had on our lives
• How smartphones have evolved to become a significant risk vector
• The cyber risks smartphones potentially pose
• How organisations can minimise smartphone security threats
Guest speaker: Jenny Radcliffe, The People Hacker
C-suite engagement is essential to embed the culture and tone necessary for effective cyber risk management.
Despite the reality that cyber attacks are evolving and becoming more complex, making cyber security a C-level priority is no easy endeavour.
Our podcast, ‘The Reality of Securing C-Suite Support for Human Security’, explores the challenges with leadership support in cyber security, and the approach to gain buy-in at an executive level.
This 40-minute podcast will discuss:
• Why buy-in from the top is important for security awareness program success
• Challenges in engaging and maintaining leadership participation
• Tips and tricks to make senior management see the benefit of robust cyber security programs
Guest speaker: Todd Wade is a Chief Information Security Officer for Fintech / Technology companies, with 20+ years’ experience in all thing's cyber security, technology and risk. Author of Cybercrime: Protecting your business, your family and yourself.
The speed at which technology and cybercrime rapidly evolve makes it increasingly difficult for organisations to remain cyber-secure and compliant.
Consequently, the need to implement effective Information Security frameworks has heightened. With these frameworks in place, organisations can define the processes and procedures to assess, monitor, and mitigate cyber risk.
Our upcoming webcast, ‘Business Benefits of Information Security Frameworks’, explores the business value of Information Security frameworks and how to build a robust cyber security strategy.
This 45-minute podcast will discuss:
• The why and what of standards, regulations, policies, and frameworks
• Business benefits associated with Information Security frameworks
• Pitfalls to watch out for when engaging with Information Security frameworks
• How to best approach ISO 27001 certifications
Guest speaker - Brian Honan, BH Consulting CEO
Join award-winning cyber security thought leader and Cyber Security Awareness for Dummies author, Robert O’Brien as he offers a best practice approach to tackling staff awareness campaigns and improving employee security behaviours.
In this podcast we will cover:
Cyber Security Awareness Month, celebrated every October, helps to highlight the importance of cyber security and the collective effort required to prevent cyber attacks.
However, a month-long initiative is not enough to make a real, long-lasting impact on staff security behaviours.
Our podcast, ‘Best Practice for Cyber Security Awareness Month’, explores how organisations can make the most of Cyber Security Awareness Month and keep security top of mind all year round.
This 40-minute podcast will discuss:
• Cyber fatigue and the difficulty of engaging users
• Tips for planning Cyber Security Awareness Month
• Maintaining momentum and employee engagement throughout the year
• Ongoing cyber awareness certifications
• Thinking outside the box when it comes to cyber initiatives
Special Guest: Lauren Zink, Security Culture, Awareness and Training Manager at Indeed.
In the wake of the Ukraine crisis, pandemic challenges, inflation spikes and fragile global supply chains, organisations are faced with a magnitude of risk and uncertainty.
To tackle the threat, organisations must exercise vigilance in understanding emerging risks and in acting to reduce exposure and limit damage.
Our upcoming webcast ‘Cyber Resilience in An Era of Geopolitical Risk’ explores how organisations can improve their cyber resilience, threat detection and incident response in an increasingly hostile world.
This 35-minute podcast will discuss:
· The importance of Policy Management within the macro environment
· Engaging users and improving consumption of policy communications
· The significance of policy-related training
· Issue reporting and minimising the impact of an incident
· Best practice approaches to managing third-party risk
Special guest, Internationally recognised GRC pundit, Michael Rasmussen.
The effectiveness of a Security Awareness Training program ultimately depends upon improving the security behaviours of staff.
However, security training alone will not change employee behaviours. Until and unless awareness training affects how staff feel about the need to secure information, and their security instincts, organisations will continue to be vulnerable to cyber risk.
Our upcoming webcast ‘Beyond Awareness Training: Cultivating A Security Culture’ explores why organisations must go beyond awareness training and instil a security mindset that transforms staff into their frontline defence against cyber attacks.
This 45-minute webcast will discuss:
• Changing how staff perceive, think, and feel about information security
• Ingraining default security behaviours that point staff towards the right course of action
• Understanding the “why” and communicating this across the board
• Embedding a security subculture into the organisational culture• Knowing your audience and making culture-change stick
Guest speaker - Lauren Zink, Cyber Awareness and Culture Manager at Indeed
In today’s fast-changing, digital world, cyber threats are rapidly evolving.
The adoption of new technologies and new ways of working has increased the opportunities for cybercriminals to target employees and launch crippling attacks - which can result in significant operational disruption, financial loss, and reputational damage.
As cyber attacks become more destructive and unpredictable, organisations must build a cyber-resilient posture to effectively prepare, respond, and recover from inevitable cyber disruptions.Our upcoming webcast ‘Resistance to Cyber Resilience’ explores how organisations can remain cyber resilient, overcome inertia and drive behaviour change.
This 40-minute podcast will discuss:
• The challenges organisations face when changing their defence against cyber threats
• The human resistance to change
• The effects of influence, senior support and executive buy-in on cyber security
• Addressing resistance and motivating cultural change
Guest speaker: Greg van der Gaast, CISO at Scoutbee
ESG – Environmental, Social, Governance – is getting a lot of attention, and it is time for organisations to build a strategic ESG plan for reporting in 2022.
In this new era of ESG, organisations have a renewed focus on privacy. Privacy is more than complying with laws and regulations. Privacy is about the integrity and accuracy of data, the right of individuals to control and have access to their personal data, appropriate and approved use, and data protection.
Our podcast, with internationally recognised GRC pundit, Michael Rasmussen, titled, ‘Role of Privacy in the S in ESG’ explores privacy in the context of:
• Regulations, what organisations should expect from current and pending privacy regulations
• ESG, the role of privacy in an organisation's ESG program
• Extended Enterprise, how to manage privacy across distributed third-party relationships
• Best Practices, what is needed to manage privacy to be efficient, effective, and agile
When it comes to cybercrime, no industry is safe. However, the financial sector continues to be heavily targeted and is a highly lucrative target for cybercriminals because their data is more valuable.
For financial institutions, the potential damage from cyber attacks extends beyond simply stealing money from customer accounts but also costs firms their revenue, reputation and customer base.
To protect themselves and their customers in an increasingly dangerous digital environment, cyber security has become a vital investment for financial institutions.
Our upcoming webcast, titled ‘Fighting Cybercrime in the Financial Services Sector’, explores the financial industries evolving threat landscape and how it can mitigate cyber risk.
This 50-minute webcast will discuss:
• How cyber risks have evolved as the financial services industry has evolved
• The unique challenges that financial service organisations face
• Cyber training that serves the specific, and changing needs of the financial services industry
• How financial services leaders can keep their operations cyber-secure
Despite the ongoing threat of cyber attacks, Security Awareness Training remains a major challenge for management teams. Identifying what training needs to be delivered, who needs to be trained and a lack of employee engagement are all common obstacles that organisations face when it comes to implementing security awareness training.
As every organisation knows, change management is notoriously difficult. The best security awareness programs approach the task in the same way as other organisational change projects. Change isn’t a given; it takes time and effort.
The reality is cyber security can be a dry topic. As such, it’s vital you find ways to engage your staff if you want to positively impact behaviour within your organisation, raise awareness of cyber security threats, and embed a culture of compliance.
This podcast will explore:
-How to implement staff security training that maintains momentum and encourages engagement
-The importance of getting buy-in in the boardroom
-Tailoring cyber security awareness training for your audience
-Using storytelling to breathe life into your cyber security awareness campaign
Special guest: Ravi Sankar, CISO, ItsDone
User participation is one of the key measures of success in a cyber awareness program. All too often, organisations adopt a one size fits all solution that fails to resonate with the end-user. Incorporating company personality into your cyber awareness program is an effective way to tailor training to suit your audience and develop a campaign that engages employees.
This podcast will explore:
-The role of company personality in your cyber awareness program -Analysing your audience to create an awareness campaign that resonates -How to make your cyber awareness program relatable for your employees -Embedding storytelling to create a culture of cyber security awareness in your organisation -Localisation and other practical steps to engage users in cyber awareness activities
Whether accidentally or deliberately, employees can put organisations at significant risk of a cyber attack. The task of defending against such threats is difficult because insider threats are often difficult to detect.
The pandemic and the shift to remote working have contributed to the growing rate of insider threats in recent years and will continue to be an ongoing challenge for organisations.
This podcast will discuss:
• Internal threats versus external threats
• Types of insider threats and their motivating factors
• The risks that insiders pose
• How to protect your organisation by detecting, deterring, and disrupting insider threats
Special guest: Jake Moore, Global Cyber Security Advisor and Spokesperson at ESET
With cyber security lawsuits on the rise, the probability and financial impact of cyber incidents are ever-growing for organisations.
The aftermath of a data breach can have crippling consequences across all aspects of an organisation and there is inevitably a blame game that follows any cyber incident.
This podcast will discuss:
-The role of leadership and setting the tone from the top
-Mitigating the risk of a data breach and limiting the damage if a data breach occurs
-Why data breach prevention is the job of everyone and cyber security is more than an IT issue
-Creating a culture of collective accountability and cyber security awareness
-Finding innovative ways to keep cyber hygiene on the agenda
There’s no denying it - cyber security is serious stuff.
The problem is that many organisations believe that because of the dangers of cyber attacks, Security Awareness Training must also be delivered in a serious manner. But this approach can cause fatigue among a workforce, hurting more than it helps – which is no laughing matter.
One of the best ways to educate staff and ensure key messaging is retained is by incorporating entertainment and humor into Security Awareness Training. This allows organisations to break down barriers, open conversations, make emotional connections, and win hearts and minds.
This podcast will discuss:
• The natural aversion to cyber security training among users
• Making training ‘click’ before employee burnout
• Cybercriminals have no boundaries, and neither should security awareness training
• Taking risks to create security awareness training which users will remember
• Dealing with negative user responses to content
Special guest: Dana Mantilia, Cyber Security Expert
Cyber security in the workplace has become increasingly important as more organisations migrate to digital and the cloud. With the adoption of digital channels growing exponentially across all sectors, so too has the number of high profile data breaches and ransomware attacks.
As regulators and auditors seek evidence of security awareness activities, organisations are under enormous pressure to proactively protect their people, reputation, and valuable assets. Still, many cyber security awareness initiatives fall flat due to a lack of engagement from end users.
To efficiently and effectively build a highly skilled workforce that is prepared to address cyber threats in complex enterprise environments, it is vital to consider security awareness training as more than a compliance checkbox exercise.
This podcast will discuss:
-Best practices for next-generation training
-Taking a targeted, tailored approach to security awareness training
-Building momentum for an awareness campaign and avoiding user fatigue
-Analysing your audience to create an awareness campaign that resonates
-Making your cyber awareness program relatable for your employees
In today’s complex business environment, organisations need to be able to respond rapidly to any changes and adapt policies where necessary.
The only way to adapt to the dynamic, disrupted, and distributed nature of business is to be agile. This requires organisations to have an agile policy management program in place so they can react quickly to changes in risks, regulations, strategy, processes, roles, and responsibilities.
An effective policy management program will provide a framework of governance, identify risks, define compliance, and play a crucial role in organisational success. It should also engage staff and clarify the standards of what is expected of them.
The podcast will explore:
• How to monitor the internal and external environment for changes that impact policy.
• Key steps to defining a policy management program that is agile and dynamic to the needs of the business.
• Engaging employees on policies to ensure they know what is expected of them.
• How to ensure policies are being followed and aligned with the needs of the business.
The aftermath of a cyber attack can be chaotic
An incident response plan enables organisations to detect, contain, eradicate, and recover from an attack effectively, without chaos. By reinstating normal operations as quickly as possible, organisations can limit the damage when an attack occurs.
This podcast will discuss:
• The digital challenges that organisations are facing today
• Training people to recognise and respond to a cyber incident
• Accountability after a cyber attack
• Failing to plan is planning to fail
• How organisations can learn from security incidents
Special guest: Sarah Armstrong-Smith, Microsoft Chief Security Advisor
Despite increased investment in cyber security initiatives, organisations continue to be impacted by cyber attacks. Almost all successful breaches share one variable in common: human error.
The reality is organisations face a very real danger of threat from within.Against the backdrop of a complex cyber threat landscape, the insider threat has intensified as working practices have evolved and cybercriminals launch increasingly sophisticated attacks.
The mitigation of human-born error is key to reducing cyber risk in an organisation and a proactive approach to prevent employee-related threats has never been more important.
This podcast will discuss:
• Why people are at the centre of cyber security threats
• How hackers exploit people for their own gain
• Tactics to improve employee engagement in Security Awareness Training
• The CISO’s challenge in creating a cyber secure workforce
Special guest: Jenny Radcliffe, People Hacker and Social Engineer