Latest / Tech Talks With Kinsoft / Enhancing Cybersecurity Through Effective Awareness Training
Transcript
- 0:00Welcome to Tech Talks with Kinsoft. We're here
- 0:02to help you cut through the noise and really
- 0:04get to the heart of what matters in this fast
- 0:07-paced world of tech. Today, we're tackling a
- 0:10topic that, well, it often gets overlooked, but
- 0:12it's arguably the most critical piece of cybersecurity.
- 0:15We're talking about the human element. That's
- 0:17exactly right. We hear so much about, you know,
- 0:20these super sophisticated cyber attacks, right?
- 0:22Complex stuff. But the surprising truth and what
- 0:25we're going to dig into today is that the biggest
- 0:28vulnerability often just, well, walks right in
- 0:30the front door. Or maybe more often now, logs
- 0:33in from home. We'll be exploring why people are
- 0:35both a company's greatest asset and its biggest
- 0:38cybersecurity risk. Yeah. And we've gathered
- 0:40some really fascinating insights for you. We
- 0:43looked at cybersecurity experts, industry reports,
- 0:45even some government guides. So our mission today
- 0:48is to unpack those. honestly startling statistics
- 0:52behind human error and data breaches, and then
- 0:55crucially show you how organizations are trying
- 0:58to flip that script, turn people from, you know,
- 1:01potential weak links into their strongest defense.
- 1:04Get ready for maybe some aha moments that might
- 1:07just change how you think about digital security.
- 1:09So let's unpack this a bit. You might invest
- 1:11in the absolute latest firewalls, the best antivirus
- 1:14software, but what if the biggest threat isn't
- 1:17some, you know, shadowy hacker collective, but
- 1:19just A single misclick. Is it really that simple
- 1:22sometimes? It's not just simple. It's overwhelmingly
- 1:25the case. The data is quite stark, actually.
- 1:28Study after study, sources like InfoSecurity
- 1:31magazine and others, they consistently show that
- 1:33a staggering 90 to 95 percent of cybersecurity
- 1:36breaches, they're tied back to human error. 95
- 1:38percent. Yeah. I mean, this isn't just a small
- 1:40factor. It's the dominant cause. Wow. So it's
- 1:43almost always involved. Pretty much. Think about
- 1:45almost any major breach you read about. Chances
- 1:49are there was a human moment, an error, right
- 1:52at the core of it somewhere. When we talk human
- 1:54error, I guess the classic example comes up,
- 1:56right? Fishing. And here's where it gets really
- 1:59interesting for me. The Verizon Data Breach Investigations
- 2:02Report, year after year, points to phishing as
- 2:05the number one threat. Number one. It's so common
- 2:09that apparently one in three employees are likely
- 2:11to click links in phishing emails. And maybe
- 2:14even more worrying, one in four actually admit
- 2:17they've clicked on one at work. Think about that
- 2:19for your own team. Right. And it's not just about
- 2:21the clicking, is it? Our sources show that about
- 2:23one in eight employees might actually go further
- 2:25and share information if the phishing email asks
- 2:28for it. Oh, wow. Yeah. And think about this.
- 2:30Nearly half, 45%, admit clicking suspicious emails
- 2:33just in case it's important. That FOMO, the fear
- 2:35of missing out. Exactly. That fear or just missing
- 2:38a critical work thing, it's a huge psychological
- 2:41lever for attackers. And add to that, a similar
- 2:44number never reports suspicious messages to IT.
- 2:46That's, well, it's a massive blank. spot. It
- 2:49really is. It means these things can just spread
- 2:51undetected. And leads to real consequences. Like
- 2:54one stat mentioned 74 % of U .S. orgs had a successful
- 2:58phishing attack leading to a data breach just
- 3:00in the last year. 74%. That's huge. And attackers
- 3:04are getting smarter too, right? They're not just
- 3:05sending generic spam anymore. Oh, definitely
- 3:07not. They're getting incredibly sophisticated.
- 3:09They leverage human psychology using those emotional
- 3:12triggers, urgency, fear. Like those urgent account
- 3:16issue. emails precisely or impersonating brands
- 3:19you trust or even colleagues they use publicly
- 3:22available info sometimes to make it look incredibly
- 3:25real and the attachments the links they look
- 3:27totally legitimate makes it really hard not to
- 3:29click sometimes and now there's ai getting involved
- 3:32yeah that's the uh the newer, perhaps more concerning
- 3:35development. We're seeing the rise of AI -generated
- 3:38phishing attempts. As of, well, fairly recently,
- 3:41March 2025, the data suggested AI is about 24
- 3:45% more effective than humans at actually crafting
- 3:47these messages. 24 % more effective. Because
- 3:50they can often bypass the traditional filters,
- 3:53they're grammatically perfect, contextually appropriate.
- 3:56You know, all those little telltale signs we
- 3:58used to look for, the weird phrasing, the typos.
- 4:01Yeah, they're gone. Pretty much gone. Which means
- 4:03recognizing the really subtle cues, understanding
- 4:06the context, just having that slightly heightened
- 4:09sense of vigilance. It's more vital than ever.
- 4:12That gut feeling becomes more important. It really
- 4:14does. That smell test because the obvious flags
- 4:17are just disappearing. Okay. So with these external
- 4:21attacks getting so clever, exploiting our psychology,
- 4:24using AI. It really shines a light on another
- 4:27critical area, doesn't it? The insider threat.
- 4:31And this isn't just like spies or disgruntled
- 4:34employees planting bombs, right? It's broader
- 4:35than that. Exactly. It's much broader. CISA,
- 4:38the Cybersecurity and Infrastructure Security
- 4:40Agency, their guide defines an insider pretty
- 4:44clearly. It's basically any person who has or
- 4:47had authorized access or knowledge of an organization's
- 4:50resources. Resources meaning? Meaning personnel.
- 4:54Facilities, information, equipment, networks,
- 4:57systems, everything. These are people the organization
- 5:01explicitly trusts. Employees, sure, but also
- 5:04former employees, contractors, vendors, anyone
- 5:08inside that trust boundary. Okay. And the threat
- 5:11isn't always malicious intent, is it? You mentioned
- 5:14a key distinction. Right. Accidental versus intentional.
- 5:17That's crucial. It's not always someone plotting
- 5:19something nefarious. So what does an accidental
- 5:21threat look like? Well, look, even the best employee,
- 5:24the most careful person can make a mistake. It
- 5:26could be simple, like mistyping an email address
- 5:29and sending sensitive data, maybe a customer
- 5:31list out to a competitor by accident. Ouch. Yeah.
- 5:34Or, you know, they get a really convincing phishing
- 5:36email. It slips past their training and they
- 5:38click the link. Or even something physical, like
- 5:40not shredding sensitive documents properly. And
- 5:43curiosity. That's a big one. Finding a USB drive
- 5:46in the parking lot. Someone plugs it in just
- 5:48to see what's on it. Exactly. And an attacker
- 5:50might have left it there precisely for that reason.
- 5:53So these accidental things, you can't completely
- 5:56prevent them, maybe, but you can definitely mitigate
- 5:59the impact with the right procedures and awareness.
- 6:02Right. But then there are the intentional threats.
- 6:04Those seem scarier. What drives those? It really
- 6:08varies. Sometimes it's for personal gain, like
- 6:10maybe trying to advance their career by stealing
- 6:13intellectual property to take to a new job. Financial
- 6:16pressure is a big one. Or grievances, feeling
- 6:18underappreciated, passed over for promotion,
- 6:21unfairly treated. Personal motives, mostly. Often
- 6:23personal, yeah. Sometimes it's ego, wanting recognition.
- 6:27Occasionally it's even a misguided belief they're
- 6:29doing something noble, like whistleblowing inappropriately.
- 6:32It's complex human stuff, rarely simple. You
- 6:35mentioned a case in American Energy Tech Company.
- 6:37That sounded pretty severe. Oh, it was. A really
- 6:40stark example. This company lost over a billion
- 6:43dollars in shareholder equity. Nearly 700 jobs
- 6:46gone. A billion. Because their head of automation
- 6:49engineering secretly downloaded proprietary source
- 6:52code. Just hooked it. Then passed it to a foreign
- 6:54competitor. This was back in 2011. But the legal
- 6:57fight dragged on until 2018. Even when they got
- 7:00a court order for, I think it was $59 million.
- 7:03It sounds like a lot, but compared to the billion
- 7:05lost and the jobs, it's a hollow victory. Shows
- 7:09the devastation an intentional act can cause.
- 7:12Absolutely devastating. And then there was that
- 7:13other case, the water reclamation plant employee.
- 7:16That seemed driven by something else entirely.
- 7:18That's right. Very different motivation. In that
- 7:21case, the employee deliberately disabled critical
- 7:23systems, caused about $60 ,000 in damages. His
- 7:27motivation seemed to stem from financial problems
- 7:30mixed with unaddressed depression. And what's
- 7:34really key there is that apparently there was
- 7:35a pattern beforehand. Increased stress, some
- 7:38concerning behaviors. Warning signs were missed.
- 7:40Exactly. It just highlights how severe the consequences
- 7:43can be when those signs are missed and why organizations
- 7:45need ways to support people and address issues
- 7:47respectfully. Personal problems can be - become
- 7:50security risks. And it's not always just one
- 7:53person acting alone, right? You mentioned collusive
- 7:55threats. Yeah, that's another layer. Collusive
- 7:58threats are where insiders actively work with
- 8:00external attackers, often cyber criminals. For
- 8:04what purpose? Usually fraud or stealing intellectual
- 8:07property. These are tough to spot because the
- 8:10external folks are often good at covering tracks
- 8:12and the insider provides the crucial in. Makes
- 8:14sense. And then there are third -party threats.
- 8:16This involves your contractors, your vendors,
- 8:20anyone external you grant access to your systems.
- 8:23Okay. They might cause harm. directly, maybe
- 8:27if they're malicious, but more often it's indirect,
- 8:29like their systems get compromised, and that
- 8:31gives attackers a way into your network. The
- 8:33supply chain risk. Precisely. And those attacks
- 8:36are way up. Some reports show supply chain attacks
- 8:38jumped like 431 % between 2021 and 2023. It really
- 8:44hammers home that your security is only as strong
- 8:46as the weakest link in your whole extended network.
- 8:49Okay, so given all these risks, Accidental clicks,
- 8:52sophisticated phishing, intentional insiders,
- 8:55compromised vendors, it feels significant. What
- 8:59does this actually mean for strengthening security?
- 9:01It sounds like that cybersecurity awareness training
- 9:04isn't just a nice -to -have IT thing anymore.
- 9:07It feels like a core business necessity, more
- 9:10than just checking a box for compliance. Absolutely.
- 9:12It's fundamental. It's really about shifting
- 9:14the mindset, transforming your team from, you
- 9:18know, potential liabilities into your actual
- 9:20strongest line of defense. And effective training,
- 9:22it's got to go way beyond just don't click bad
- 9:25links. It's about building security habits into
- 9:27the daily routine, empowering people. Right.
- 9:30So if an organization is looking to build out
- 9:32or improve their training, what are the really
- 9:34key areas sources point to? Well, obviously,
- 9:37phishing and email security is foundational.
- 9:38Teaching people how to spot those scams, the
- 9:40suspicious links. the social engineering tactics.
- 9:43But then there's password management. And the
- 9:45insight here isn't just use a strong password
- 9:47because people hate that. Yeah, the complex ones
- 9:51you forget instantly. Exactly. It's more about
- 9:53enabling strong security. So encouraging things
- 9:56like good password managers and pushing multi
- 9:59-factor authentication, MFA. These tools actually
- 10:02reduce the friction for users while boosting
- 10:04security. Makes it easier to be secure. Okay,
- 10:07makes sense. What about just... everyday web
- 10:10surfing and devices that's safe internet usage
- 10:12and device security so guidance on avoiding risky
- 10:15websites being careful with unsecured wi -fi
- 10:18huge when people work remotely or travel and
- 10:21securing all devices not just the work laptop
- 10:24but personal phones if they access work stuff
- 10:26strong passcodes encryption also keeping software
- 10:30updated those patches often fix critical security
- 10:33holes right the updates we always click Remind
- 10:36me later on. Ah, yeah, those ones. Then there's
- 10:38data protection itself. This isn't just reciting
- 10:40regulations like GDPR. It's teaching practical
- 10:43steps, how to handle sensitive data, how to classify
- 10:46it, maybe understanding the real world impact
- 10:49if it leaks, instilling that sense of responsibility
- 10:51for the data. Got it. And physical stuff, too.
- 10:53You mentioned USBs earlier. Yep. Removable media
- 10:56security. highlighting the very real risks of
- 10:59plugging in unknown USBs, even those promotional
- 11:02giveaways you get at conferences. Good training
- 11:04often includes practical demos showing just how
- 11:07easily a system can be compromised by one of
- 11:09those. Makes it stick. So it's blending the digital
- 11:12and physical environment awareness. Precisely.
- 11:15Which leads to things like a modern clean desk
- 11:17policy. Not the old rigid rules, but adapted
- 11:21for today's workplaces, home offices, open seating.
- 11:25It's about making secure habits routine, like
- 11:27securing sensitive papers quickly, maybe using
- 11:30subtle nudges or reminders, not just rules. In
- 11:33minutes, not hours, as one source put it. Yeah,
- 11:35exactly. And finally, environmental security.
- 11:38Just being aware of those low -tech physical
- 11:40threats right there in the office. Things like
- 11:42tailgating someone slipping in the door behind
- 11:45you without badging in. Or shoulder surfing someone
- 11:47literally looking over your shoulder at your
- 11:49screen or keyboard. Simple but effective if people
- 11:52aren't vigilant. Okay, so there's a lot to cover.
- 11:54But it's not just what you train on. It's how,
- 11:56isn't it? I imagine those generic hour -long
- 11:59once -a -year videos don't really cut it. Oh,
- 12:01they really don't. The delivery is absolutely
- 12:03key to making it effective. It has to be personalized.
- 12:07It has to be engaging. Think about that mandatory
- 12:10training, boring video, tedious quiz. People
- 12:14just click through. The results are forgettable.
- 12:17The best approaches, the best platforms, they
- 12:19adapt. They look at the employee's role, their
- 12:22current skill level, how they learn best. Keeps
- 12:24everyone challenged but not overwhelmed or bored.
- 12:27That personalization is vital because people
- 12:29have different tech skills, different priorities
- 12:32day to day. It needs to feel relevant to their
- 12:34job. Exactly. And that's where we get into behavioral
- 12:37science, isn't it? Right. This isn't just about
- 12:39knowing stuff. It's about changing what people
- 12:42actually do. Habits. Precisely. And that's the
- 12:45real aha moment for a lot of organizations. Security
- 12:48isn't just knowledge, it's ingrained habits.
- 12:51So using behavioral science techniques, that's
- 12:53changing the game. Things like immediate feedback
- 12:56loops and training simulations, gamification
- 12:58elements making it a bit competitive or fun,
- 13:01and micro -learning, breaking down big topics
- 13:03into small, practical, digestible chunks. Easier
- 13:06to remember. Yeah, it helps fight that forgetting
- 13:08curve, you know, where we naturally forget most
- 13:10of what we learned shortly after learning it.
- 13:12So training... needs to be concise, continuous,
- 13:15maybe integrated into the workflow somehow, not
- 13:18just a big annual dump of information. That's
- 13:21how you get real lasting behavior change. And
- 13:24leadership has to buy in, right? It can't just
- 13:26be an I .T. initiative push from the side. Absolutely
- 13:29essential. Leadership has to champion this stuff.
- 13:32They need to set the expectation. Cybersecurity
- 13:35is everyone's job. From the top down. Walk the
- 13:38walk. Exactly. Model the behavior and crucially,
- 13:41find ways to acknowledge and maybe even reward
- 13:44good security practices and compliance, not just
- 13:47punish mistakes. That positive reinforcement
- 13:49can massively boost motivation and morale. It
- 13:52builds a culture where people feel safer reporting
- 13:54things, even their own mistakes, without fear.
- 13:57Okay, that makes sense. Fostering a positive
- 13:59security culture. Now, technology can help too,
- 14:02right? We hear about tools like user activity
- 14:04monitoring, data loss prevention. They definitely
- 14:06play a supporting role. Yeah. Tools like user
- 14:09activity monitoring, UAM that helps flag unusual
- 14:13employee behavior that might signal. a threat,
- 14:15internal or external. And data loss prevention,
- 14:19DLP, those tools are designed to stop sensitive
- 14:22data leaving the company through unauthorized
- 14:24routes. They can absolutely help detect anomalies,
- 14:27but, and this is the critical point, they only
- 14:30enhance human capabilities. They don't replace
- 14:32them. They need people to interpret the alerts.
- 14:34Exactly. You need skilled analysts to look at
- 14:37the data, understand the context, decide if it's
- 14:40a real threat or false alarm, and figure out
- 14:42how to respond. And these tools work. work best
- 14:45when employees know they're there and importantly,
- 14:47understand why they're there for collective protection,
- 14:50not just Big Brother watching. So they supplement
- 14:52human judgment. They don't substitute for it.
- 14:54Perfectly put. They supplement. They don't replace
- 14:56human vigilance. Human judgment remain key. So.
- 15:01Just to summarize, really, while the threats
- 15:03keep evolving, getting more sophisticated hackers,
- 15:05insiders, AI phishing, all of it, the human element,
- 15:09it's still absolutely central to your security
- 15:11posture. By investing in smart, engaging, continuous
- 15:14training, you really can transform your employees.
- 15:16Turn them from that potential weak link into
- 15:19your most resilient, most adaptable defense.
- 15:21It's a holistic approach. Prevention, protection,
- 15:24mitigation. Yeah, and that really shifts the
- 15:26perspective, doesn't it? It's not just about
- 15:28ticking that compliance box anymore. truly embedding
- 15:31security into the culture, into the fabric of
- 15:33the organization, building a place where everyone
- 15:35understands their role, their responsibility
- 15:38in protecting critical assets takes ownership.
- 15:41Precisely. And the goal isn't about assigning
- 15:43blame when something goes wrong. It's about empowerment,
- 15:47empowering every single person to spot potential
- 15:50threats, to report them, fostering that safe,
- 15:53secure environment. And also understanding, you
- 15:55know, that journey from trusted insider to potential
- 15:57threat. It's often a process that might be observable
- 15:59signs, behavioral patterns. If those are recognized
- 16:02early, maybe intervention is possible before
- 16:05a breach happens. Right. Prevention over reaction.
- 16:07Now is the goal. So as we wrap up this Tech Talks
- 16:10with Kinsoff. discussion, maybe here's something
- 16:12to think about. If, let's say, 95 % of breaches
- 16:16involve human error and attackers are getting
- 16:19better and better at exploiting our psychology
- 16:21using AI, consider this. What seemingly innocent
- 16:24or just routine digital habit are you, or maybe
- 16:27the people around you, doing every single day?
- 16:29Could that be the next subtle yet significant
- 16:31gateway for a cyber attack? That's definitely
- 16:34something to ponder until next time on Tech Talks
- 16:36with Kinsoft.