How to Build Multi-Channel Security Awareness

252 views
•
May 7, 2021
by
RSAC Cybersecurity
YouTube video player
How to Build Multi-Channel Security Awareness

TL;DR

Security awareness should use multiple communication channels and continue over time because remote work has decentralized employees, changed media habits, and expanded opportunities for social engineering. Organizations can strengthen resilience by adapting training to current working patterns, addressing attacks across newer communication tools, and treating the human layer as an ongoing cybersecurity priority.

Transcript

Hello, and welcome to this edition of our RSAC 365 webcast series. We're pleased to host today's session, Utilizing Multi-Channel Awareness Measures in Times of New Work, with our guest, Dr. Nicholas Hellemann. During the webcast, all participants will be in listen-only mode. Our guest will be taking questions at the end of the session, and you can... Read More

Key Insights

  • The pandemic created favorable conditions for social engineering because people urgently wanted information and protection while experiencing fear, uncertainty, and widespread disruption. Attackers rapidly incorporated coronavirus themes into malware, fraudulent applications, and phishing campaigns designed to exploit those heightened emotional and informational needs.
  • The human layer became an especially attractive target during the pandemic because chaos and unanswered questions could influence employee decisions. Phishing campaigns impersonated official sources, including the World Health Organization, and offered coronavirus protection advice while functioning as conventional attempts to compromise recipients.
  • Remote work decentralized company workforces and changed how employees collaborated. The rapid transition to working from anywhere also increased reliance on newly adopted communication tools, exposing people through more channels and requiring security awareness programs to address risks beyond traditional workplace settings.
  • Attackers adapted quickly to pandemic conditions and showed substantial activity shortly after lockdowns began in Europe. Data presented with the AV-Test Institute indicated a marked jump in newly detected malware types between February and March, with Trojans, including ransomware, remaining prominent categories.
  • Healthcare and critical infrastructure were especially vulnerable targets during the pandemic. Interpol and Europol warnings highlighted attacks affecting hospitals and the vaccination value chain, while several European hospitals reportedly had to close after ransomware incidents disrupted their operations.
  • Media consumption patterns and channel preferences have changed over the preceding five to ten years. Security awareness therefore needs to reflect where employees receive information and communicate, including messenger tools that attackers have begun exploiting as additional delivery channels for social engineering.
  • Modern security awareness is an ongoing, multi-channel process rather than a one-time, one-directional measure. A resilient program should repeatedly reach employees through relevant channels while adapting its content to decentralized work, current media preferences, and the changing techniques used by attackers.
  • Behavioral science and learning psychology provide a foundation for designing security awareness around the human factor. SoSafe's approach combines these disciplines with reaction data from attack simulations, using observed employee responses to inform research about social engineering, awareness, and human risk.

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How should companies build multi-channel security awareness?

Companies should replace one-time, one-directional awareness measures with an ongoing program that reaches employees through multiple relevant channels. The program should reflect decentralized workforces, work-from-anywhere arrangements, changed media preferences, and the rapid adoption of communication tools. It should also prepare employees for social engineering delivered through newer environments, including messenger tools, while treating the human layer as a continuing component of organizational resilience.

Q: Why did the pandemic increase human-focused cyber risk?

The pandemic increased human-focused risk because people faced fear, uncertainty, unanswered questions, and an urgent need for reliable health information and protection. Attackers recognized that these conditions made the human layer particularly attractive. They quickly created coronavirus-themed phishing campaigns, malware, and fraudulent applications that appeared to provide official advice, infection data, tracing functions, or protective capabilities while attempting to compromise users.

Q: How did remote work change security awareness needs?

Remote work decentralized employees and changed how organizations collaborated, communicated, and consumed information. Companies rapidly adopted new tools to support work from anywhere, which exposed the human layer through a broader set of channels. Security awareness therefore needs to follow employees into those environments, address attacks delivered through newer communication tools, and continue over time instead of depending on a single workplace-based intervention.

Q: What is an ongoing security awareness model?

An ongoing security awareness model treats employee preparedness as a continuous activity rather than a measure delivered only once. In the approach presented, repeated awareness efforts operate across several communication channels and respond to changing work patterns, media habits, and attack techniques. This supports resilience by keeping human-focused risks visible as employees work remotely, use different tools, and encounter social engineering in multiple contexts.

Q: Why should security training address messenger tools?

Security training should address messenger tools because remote work accelerated the adoption of new communication platforms, and attackers began exploiting these additional channels. Employees may therefore encounter social engineering outside conventional formats and workplace routines. A multi-channel awareness program acknowledges this expanded attack surface and prepares people to recognize suspicious approaches wherever work-related communication and information consumption now occur.

Q: Which sectors were especially targeted during the pandemic?

Healthcare organizations and other critical infrastructure sectors were identified as especially vulnerable targets. Attacks extended from hospitals, which formed a central part of the pandemic support structure, to vaccination providers and the broader vaccination value chain. The presentation also cited European cases in which hospitals had to close after ransomware attacks, illustrating the operational consequences of targeting essential services during a crisis.

Q: How did attackers use coronavirus themes in phishing and malware?

Attackers used coronavirus themes by presenting malicious content as information or protection that people urgently wanted. Examples included malware connected to interest in Johns Hopkins University infection data, applications suggesting tracing or artificial intelligence protection capabilities, and phishing messages impersonating the World Health Organization. These campaigns exploited demand for outbreak updates and safety advice while operating as Trojan horses or conventional phishing attempts.

Q: How can psychology improve cybersecurity awareness?

Psychology, learning psychology, and behavioral science can help organizations understand why people respond to social engineering and how awareness should be structured. The presentation connects these disciplines to the human factor in cybersecurity, noting that attackers have become effective psychologists. SoSafe also uses reaction data from attack simulations to study employee behavior and inform its research, awareness methods, and Human Risk Review.

Summary & Key Takeaways

  • The pandemic created uncertainty, fear, and intense demand for information, conditions that attackers quickly exploited. Coronavirus-themed malware, fraudulent protection tools, and phishing messages impersonating official sources targeted the human layer. Healthcare organizations, hospitals, vaccination providers, and other critical infrastructure faced particular attention because their roles made them especially vulnerable during the crisis.

  • Remote work and work-from-anywhere arrangements decentralized company workforces while organizations rapidly adopted new communication tools. These changes exposed employees through more channels and altered how people consumed information. Attackers adapted by exploiting the resulting uncertainty and expanding social engineering beyond familiar formats, including attacks delivered through messenger tools and other emerging communication environments.

  • Modern security awareness must account for changed working modes, media preferences, communication channels, and attack patterns. The proposed model replaces one-time, one-directional measures with an ongoing, multi-channel program. Its design draws on psychology, learning psychology, behavioral science, and reaction data from simulated attacks to improve organizational resilience against human-focused threats.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚