ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

teissTalk: Can security awareness keep up with the attackers?

teissTalk host Geoff White was joined by Craig McEwen, Chief Information Security Officer, Anglo American; Steven Furnell, Professor of Cyber Security, University of Nottingham; Gema Perez Cortes, Information Security Awareness Lead, Canon EMEA; and Oz Alashe,CEO, CybSafe.

 

Views on news

 

Polling 3,000 individuals across the United States, UK and Canada, The Annual Cybersecurity Attitudes and Behaviors Report 2022 examined key cybersecurity behaviours, attitudes and trends ahead of Cybersecurity Awareness Month.

 

While almost half of respondents state they are “always connected to the Internet”, two-thirds (62%) of users lack access to cybersecurity knowledge altogether and one-third rely on the help of friends and family. The report has found that a high percentage of cybercrime remains unreported to relevant channels and agencies that can help with remediation.

 

Alarmingly, 43 per cent of respondents said that they hadn’t heard of MFA.

 

Unlike in burglaries, where police and the environment show sympathy towards the victim even if they didn’t take all necessary precautions, in the case of cybercrime, finger pointing, and blaming is more common. However, they should also be considered as victims.  Counterintuitively, young people tend to be less wary of phishing and other cyber crime than older generations.

 

Employees, however, are not typically targeted by cyber training based on their age but, rather, in line with the types of access they have to sensitive information. According to AngloAmerican’s survey, there is certainly a correlation between employees failing to complete security training and their susceptibility to cybercrime.

 

How awareness translates into behaviour

 

Organisations are at different levels of maturity when it comes to cyber security. According to a survey, less than 20 per cent of businesses in the UK say they’ve provided their staff with any security training in the past 12 months. Learning is reinforced by practice, but in the case of information security, there is an extra twist, as what should be taught is what users mustn’t do.

 

Therefore, users have to be exposed to threats several times, so they can recognise them confidently. However, training should be also taken a step further by making them understand what they are actually protecting by keeping their guard up, as the same threat may come up in different guises. Overfitting the training will prevent users from recognising risks.

 

Typically, in connection with phishing, there are two types of behaviour that we focus on, clicking and reporting, ignoring other ones that should also be considered such as “are they aware of their digital footprint?” , ”are they unsure about what to do and do they seek advice?.”

 

To get more effective, training can be combined with nudges and prompts at the right place and the right time.

 

The panel’s advice

 

Try to understand why your users click on phishing links despite being trained and aware of the dangers that it entails.

 

Bring disparate data sets together such as attacks, infections, training penetrations, susceptibility to map out the cyber security culture of your business.

 

Awareness is about telling employees what they should know, training teaches them how to deal with a threat, while education also tells them why they need to be aware of certain risks.

 

Watch on-demand here.

 


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543