METHODOLOGY · CYBER AWARENESS

Awareness on its own does not build cyber readiness.

Most cybersecurity awareness training solutions concentrate on raising awareness, without answering the question that follows: so what do we do now? RiskSight’s methodology is built around actionable outcomes that answer this question. Training produces a risk posture for every user, every unit and the organisation as a whole, with specific follow-up guidelines.

01

Measure

Each cyber hygiene training task is mapped to risk categories and vectors, providing clear oversight of human cyber risk behaviour.

02

Interpret

The training platform provides a detailed risk analysis breakdown through tiered variables, allowing for sorting, filtering and cross-analysing all human cyber risk behaviour.

03

Act

Each user, unit and organisation receives a risk profile, which establishes the baseline for organisation-level follow-up actions.

Cyber awareness training methodology
Cyber awareness training in progress
Cyber awareness training results
CHALLENGES AND APPROACH

Cyber Awareness Training Methodology

THE CHALLENGE
RISKSIGHT’S APPROACH
01

Annual campaigns

The most commonly delivered annual campaign-form cyber awareness courses lack speed for threat adequacy and the general principles of knowledge acquisition. 

Persistence

Cyber readiness training must be consistent and reflect the changing risk picture, while taking into account the well-known knowledge acquisition approach. Trainings should be frequent and delivered as digestible pieces, preferably weekly, depending on the organisation’s risk assessment.

02

Generic materials

In general, most cyber awareness learning materials are unengaging or repetitive. This reduces the participants’ interest in enhancing cyber readiness.

 

Engagement

Utilising gamification elements and psychological techniques, it is possible to increase the effectiveness of knowledge transfer in ensuring cyber readiness of the end users.

03

Outdated and universal content

Often, the cyber awareness training materials are outdated or distant. The threat landscape changes rapidly, rules and the legal environment make their own adjustments, and organisations differ. Universal and static cyber awareness training materials are very difficult to use in different contexts.

Relevance

Artificial intelligence makes it possible to create cyber awareness training content, which is dynamic and takes into account the changing threat landscape, the user’s specifics and risks, as well as applicable policies and procedures.

04

Learner individuality

Each learner is unique, with their own weaknesses and strengths, interests and skills.

Responsiveness

An AI-based model delivers content to the learner according to their knowledge and weaknesses and constantly adapts it over time. The additional layer of gamification creates an engaging yet transparent learning journey.

05

Extensive course duration

Taking courses that are too extensive for the attention span can lead to “phantom learners” where the material is simply “clicked through” while actually not learning much.

Modularity

Modularity – the ability to present complex topics in small chunks, but consistently – significantly increases the likelihood of acquiring the material.

06

No actionable outcome

Training that reports only completion leaves supervisory staff with nothing to act on once the course is over.

Tangibility

Cyber readiness trainings must provide clear and actionable outcomes, allowing supervisory staff to implement post-training improvements such as technical measures, operational procedures or additional training to further reduce the possible impact of the human risk behaviour.

07

A reactive approach

Cyber readiness requires constant vigilance and adaptability to the threat landscape. Significant time, personnel and financial resources are required to stay up-to-date.

 

Pre-emptiveness

RiskSight, with AI-infused capabilities, pre-emptively provides customers with the necessary topics and threats to prepare against.

THE PROCESS

Cyber Awareness Training Lifecycle

FIVE-STEP CYCLE
01

Context & Customisation

Elements such as sector, size, IT systems and services and languages are configured for the tenant to ensure proper relevance.

02

Content Delivery

RiskSight delivers cybersecurity awareness training content according to the customer-specific training cycle.

03

Content Validation

Content is approved, edited or rejected according to customer preferences.

04

Task Completion

Users complete the designated tasks according to the training cycle.

05

Tangible Outcomes

User, unit and whole-structure analytics provide a detailed breakdown of risks and next steps to ensure human cyber risk mitigation and readiness.

GET STARTED

Begin cyber training

Discover how RiskSight’s cyber resilience trainings increase user cyber awareness and executive cyber preparedness.