Within today’s modern organisations, security education is an absolute need since technical measures cannot, on their own, prevent breaches that are caused by human. This chapter examines why traditional training methods often fail, citing rote learning, compliance-driven approaches, and security fatigue as key culprits. Instead, research has shown that strategies that are dynamic and rich in context, such as emotional involvement, scenario-based learning, and spaced repetition, are effective in improving memory retention and situational awareness. When it comes to the formation of secure habits, cognitive and behavioural theories emphasise the significance of problem-solving, peer role models, and positive reinforcement. By using BJ Fogg’s Behaviour Model and incorporating habit formation into everyday routines, organisations have the ability to construct a security culture that is both resilient and proactive, allowing them to adapt to the ever-changing nature of security risks.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Security Education

  • Tymur Suslov

摘要

Within today’s modern organisations, security education is an absolute need since technical measures cannot, on their own, prevent breaches that are caused by human. This chapter examines why traditional training methods often fail, citing rote learning, compliance-driven approaches, and security fatigue as key culprits. Instead, research has shown that strategies that are dynamic and rich in context, such as emotional involvement, scenario-based learning, and spaced repetition, are effective in improving memory retention and situational awareness. When it comes to the formation of secure habits, cognitive and behavioural theories emphasise the significance of problem-solving, peer role models, and positive reinforcement. By using BJ Fogg’s Behaviour Model and incorporating habit formation into everyday routines, organisations have the ability to construct a security culture that is both resilient and proactive, allowing them to adapt to the ever-changing nature of security risks.