Security Awareness Training: a reference model
Netgroup illustrates a deeply structured Security Awareness & Training model with continuous improvement and a risk-based approach
The Challenge
Guarantee of security and defense
Netgroup’s offering for Security Awareness & Training services is aimed at reducing the risk of human factor attacks (HUMINT, Social Engineering, Phishing, SMIShing and Spear Phishing, etc.) thus improving the overall security posture of corporate clients.
Since each organization is unique and, as such, exposed to peculiar threats, Security Awareness & Training services are adapted to the needs of each specific reality through a contextualization process based on two main factors: the systematic risk, identified through a preliminary Risk Assessment & Analysis activity conducted with respect to the organization’s mission, its activities and the context in which it operates, and the specific risk, which is identified through ‘overt’ or ‘covert’ assessment activities, targeting those groups of people identified as being at higher risk by function or role held, and conducted through simulations of Phishing, Spear Phishing or Social Engineering attacks.
For further study:
- Social engineering campaign targeting high-risk figures within the organization, particularly technical and support figures, in order to verify the presence and robustness of appropriate organizational measures aimed at containing the risk from hostile social engineering practices.
- Spear phishing campaign targeting key or otherwise high-risk figures within the organization. These campaigns employ more sophisticated phishing techniques.
- Massive Phishing Campaign, which through the use of a special platform, can produce simulations of massive phishing campaigns to measure the permeability of the entire company or specific departments and organizational units to phishing attacks.
The Proposal
A structured approach to go deep
Luigi calabrese and Pietro De Angelis, experts in Cybersecurity at Netgroup, expose the method applied for obtaining a solid enterprise security posture.
For its Security Awareness & Training services, Netgroup proposes a structured delivery model divided into phases, inspired by the principle of continuous improvement according to the PDCA paradigm (or Deming Cycle) and based, as required by the latest industry regulations, on a risk-based approach.
The approach to be taken is expressed in the following phases of which service delivery is composed:
INHERENT AND SYSTEMATIC RISK ASSESSMENT
is aimed at reducing the risk of human factor attacks thus improving the overall security posture of companies.
It will take the form of highly specialized advisory work, employing established risk management methodologies such as ISO 31000, ISO/IEC 27005, SEI/CMU OCTAVE, ISACA Risk IT, ANSSI EBIOS RM
SPECIFIC RISK ASSESSMENT
also aimed at the human factor is, unlike systematic risk, aimed at functions, roles and conduct through the simulation of generalized or targeted attacks by employing massive Phishing, Spear Phishing and Social Engineering campaigns in order to assess the permeability of the organization
CONTEXTUALIZED DESIGN
and subsequent deployment of Awareness (thematic newsletters, knowledge pills via videos or infographics, etc.) and Training (with live training sessions, for full interactivity) campaigns aimed at managing the risk identified in the first two assessment phases.
RE-ASSESSMENT OF HUMAN RISK
through additional Phishing, Spear phishing or Social Engineering campaigns subsequent to Awareness and Training activities designed to measure their relative effectiveness rate.
ANALYSIS, REPORTING AND FOLLOW-UP
of the campaign conducted, aimed at identifying areas for improvement and defining the possible, consequent provision of additional training sessions (training and training activities at the company’s in-house Academy that provides professional development pathways, which have as their focus the findings gathered from the Assessment of the above-mentioned approach).
The Benefits
CONTINUOUS MONITORING AND SURVEILLANCE
REDUCTION OF ATTACKS
TAILOR MADE PROTECTION
CONSTANT VERIFICATION OF THE METHODS USED
DELIVERY OF TRAINING SESSIONS
The Results
Risk Re-assessment and Follow-up
With the aim of verifying the increase in risk awareness downstream of awareness and training activities, reports are produced to be able to objectively measure the improvement in the security posture of the entire organization with respect to human-driven vulnerabilities.
This report will be the starting point for the design of follow-up and re-assessment activities, an innovative method aimed at using the results obtained, with the aim of improving the entire system and offering increasingly high-performing services.
Turn to our specialists
Luigi Calabrese and Pietro De Angelis
B.U. Cybersecurity
Netgroup S.p.A Italy
