ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

teissTalk: Developing a people-centric security programme

Linked InXFacebook
bookmark_borderSave to Library

teissTalk host Jenny Radcliffe was joined by Lydie Ngo Nogol, Chief Information Security Officer, PwC as lead guest, Helen Rabe, Global Chief Information Security Officer, Abcam; and Christian Toon, CISO of Pinsent Masons.

 

 

The importance of tailoring your security programme to end-users’ specific needs and preferences

Security programmes need to be tailored to the characteristics of end-users and the company. For young employees, traditional, static content is an instant turn-off. They need short interactive, animated input. Both young and older generations have their fortes – while the former is well-versed in technology, they are less familiar with privacy and security good practice. For the latter, it’s just the other way round. If you need to train staff without any previous experience in security, ease them into hardcore training. Helen shared a story on how they had familiarised their scientist teams for a year by showing them 5 minute animated videos on a daily basis in preparation for their enrolment in a security training platform.

 

Training should be personal rather than organisational. It’s especially important in remote and hybrid working environments that it’s not just security in the workplace that you want to improve but rather the cyber hygiene of the individual regardless of whether they are at work, socialise on snapchat or make transfers on their bank’s app. In home working settings employees’ family members can be also invited to participate in online security trainings – after all they use the same home network as the employee does. In a smaller physical office, information security experts can observe staff while working and point out which of their habits clash with good security practice.

The panel’s advice

 

The golden rule is to regard security training a learning, rather than a compliance exercise. To achieve better efficiency, leverage gamification. Employees can get extremely competitive to get on the leader board. Make sure, however, that competition doesn’t generate acrimony. For information security to get really people-centric, you need to make your staff feel that they matter. Give them security talks on a regular basis about broader security topics which are genuinely intriguing and can pique their interest, such as the dark web. Or you may want to offer them security sessions where they can discuss topical cyber incidents (e.g., DPD or Royal Mail scam) with experts.

 

To improve CISO’s leverage in the C-suite, it’s a good idea to design and use metrics, as finance may not have an understanding of its workings at a granular level. To take Christian’s example, a line item of £10,000 spent on Jellybeans is hard to explain to Finance unless they understand the role sweets play in a security reward system. Metrics that you may want to use include security engagement, the organisation’s security maturity and the impact of security training on productivity.

                                                                                                                            

 

Views on news

The article up for discussion claimed that security content gets outdated too quickly. If a company doesn’t educate its employees on the latest attacker techniques and how to recognise them, it will undermine the effectiveness of security awareness programmes. Therefore, there must be ongoing, dynamic courses and resources to continually incorporate new materials based on evolving threats.

Cyberthreats do keep changing. However, as the members of our panel have pointed out, there is certainly a fair amount of continuity in information security, considering that phishing and insufficient patching has been issues for decades and they are still included among the top vulnerabilities that open the gates for cyber-attacks. 

Linked InXFacebook
bookmark_borderSave to Library
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543