How to Make Security Training Engaging with Demos

588 views
•
July 16, 2018
by
RSAC Cybersecurity
YouTube video player
How to Make Security Training Engaging with Demos

TL;DR

Live hacking demonstrations can make security awareness training more engaging by showing an attack, explaining each step, and giving users practical protection techniques. Monterey County’s program combined current events, themed attack scenarios, and defensive guidance, while its measured phishing click rate fell from 21 percent in 2011 to roughly 3 or 4 percent.

Transcript

Everybody tired yet? Been a long week, huh? Well, we're gonna jam through this and have some fun today. Uh, quick agenda. We're gonna do the story of how we started doing these. We're gonna talk about themes for hacking demos. We're gonna talk about making these demos effective in educating your end users, and we're gonna talk about some creation t... Read More

Key Insights

  • Security awareness training is more engaging when users can watch an attack unfold rather than only hear abstract explanations. Monterey County adopted live demonstrations after employees specifically asked to see how advanced attacks worked from beginning to end.
  • An effective hacking session is structured in three parts: an introduction using industry developments or current events, a hacking demonstration in the middle, and a final walkthrough that connects each attack step with practical protective tools and techniques.
  • Security guidance is more relevant when it addresses both personal and business security. The county’s initial live sessions combined explanations of malware, nuisance attacks, targeted attacks, persistent intrusions, and attacker movement through an enterprise with concrete methods users could apply themselves.
  • Targeted phishing works by using reconnaissance to construct a persuasive message for a particular person. In the 2014 demonstration, participants helped develop an enticing email, compromised an account after the target clicked, exploited a Flash vulnerability, escalated privileges, and reached sensitive HR information.
  • Separate administrative credentials make privilege escalation more difficult. The Star Wars-themed demonstration contrasted Darth Vader, who favored one convenient sign-in for everything, with Yoda, who used a separate account and nonmatching credentials to access the most important resources.
  • One weak password can create organization-wide exposure. The 2016 demonstration used internet reconnaissance and password spraying to compromise one account, exfiltrate Outlook address books, obtain additional account names, and abuse Outlook rules to create remote access without further action by the victim.
  • Measured phishing behavior improved as live awareness training developed. The county’s click rate was 21 percent when the Zeus Trojan struck in 2011, later declining to roughly 3 or 4 percent, although the presenter emphasized that only a few users are needed to enable entry.
  • Employee reporting is an important measure beyond click rates. During the county’s latest phishing test discussed in the presentation, more than 70 percent of users recognized the message as illegitimate and submitted it through the proper channels.

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How can hacking demonstrations improve security awareness training?

Hacking demonstrations turn abstract cyber risks into visible sequences that users can understand. Monterey County began using them after employees asked to see how attacks actually worked. Attendance increased significantly, and employees started telling colleagues that they needed to attend security awareness training. The demonstrations also let instructors connect every attack step with tools and techniques users could apply for protection.

Q: How should a live hacking demonstration be structured?

The county structured each approximately hour-long session in three sections. The opening introduced industry developments and current events, sometimes using an attack video to build interest. The middle presented the hacking demonstration itself. The final third walked through the attack step by step and gave participants tools and techniques for protecting themselves against the behaviors and weaknesses they had just observed.

Q: Why did Monterey County replace stock awareness presentations?

Stock awareness presentations, even after being adjusted for the organization, did not motivate enough employees to participate. Completion was sometimes as low as 55 percent, and training often felt like a boring checkbox requirement. The county also contained about thirty businesses with different data, risk tolerances, and levels of concern, making a single generic presentation poorly suited to its diverse audience.

Q: What happened in the targeted phishing hacking demonstration?

Participants performed reconnaissance on a selected user and assembled an especially persuasive email intended to make that person click a link. After the click, the demonstration gained access to the account, exploited a Flash vulnerability, escalated privileges, and moved through the network until it reached sensitive HR information about the victim. The scenario made the complete attack process visible to users.

Q: Why should administrators use separate accounts and credentials?

The Cyber Wars demonstration showed that routine computing with administrator access can make privilege escalation easier after an account is compromised. Darth Vader represented convenience through one sign-in with broad access. Yoda used a separate account to elevate privileges and ensured that its credentials did not match. That separation made it much harder for the demonstrated attacker to reach the most important information.

Q: How can one weak password compromise an organization?

In the 2016 demonstration, attackers identified accounts through internet reconnaissance and used password spraying until one account was compromised. They then entered the organization, exfiltrated Outlook address books to collect additional account names, and continued password spraying. Finally, they abused Outlook rules to make the victim’s computer provide a remote shell, without requiring the user to take another action.

Q: What organizational changes followed the password demonstration?

The demonstration about exposed cloud credentials and one bad password led to a major update of the county’s password policy. It also contributed to the implementation of two-factor authentication in the relevant instances. These changes followed a scenario showing how reconnaissance, password spraying, address-book exfiltration, and Outlook rule abuse could turn one compromised password into broader organizational access.

Q: What results did Monterey County measure after live security training?

The county measured awareness through regular phishing tests. Its phishing click rate was 21 percent when it encountered the Zeus Trojan in 2011, close to the stated government norm of 20 or 21 percent. As live training developed, the rate declined to about 3 or 4 percent. In the latest test discussed, more than 70 percent recognized the message as illegitimate and reported it properly.

Summary & Key Takeaways

  • Monterey County needed security awareness training for about thirty businesses with different data, risk tolerances, and attitudes. Stock presentations attracted participation rates as low as 55 percent and felt like checkbox exercises. Live sessions covering computer crime, personal security, business security, malware, targeted attacks, and protective techniques generated stronger interest.

  • After users asked to see attacks actually happen, the organization introduced hacking demonstrations in 2014. Each hour-long session opened with industry developments or current events, continued with a live attack demonstration, and concluded by reviewing the attack steps while providing tools and techniques that users could apply to protect themselves.

  • Demonstrations covered targeted phishing, privilege escalation, unsafe administrator use, Wi-Fi man-in-the-middle attacks, exposed cloud credentials, password spraying, address-book exfiltration, and Outlook rule abuse. Attendance increased, employees recommended the training to colleagues, password policy was updated, two-factor authentication was implemented in some instances, and phishing reporting improved substantially.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚