Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

2/28/2020
07:00 AM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

Educating Educators: Microsoft's Tips for Security Awareness Training

Microsoft's director of security education and awareness shares his approach to helping train employees in defensive practices.

RSA Conference 2020 - San Francisco - The process of developing and implementing a cybersecurity awareness program is tricky. How do you enforce regular trainings? How do you convince employees to change their behaviors? How do you teach best security practices when the people in your organization are using more applications and services on a daily basis?

"We're asked to do a lot of things; we're pulled in many directions," said Ken Sexsmith, who heads up security education and awareness at Microsoft, in a session at this week's RSA Conference. "We're using the same technology, but we're busy doing multiple things. We have to find ways to get people interested and motivated to do things differently than they've done."

It's no small task for a company with 250,000 employees and vendors, and 441,000 Intune-managed devices hitting the network. Microsoft handles 630 billion authentication requests each month and hosts 1.04 million monthly Teams meetings, in addition to 1.23 million monthly Teams calls. It generates a terabyte of supply chain Internet of Things (IoT) data in a day and processes 128,000 Helpdesk chats.

"Ultimately what we're trying to do is protect our data," Sexsmith explained. "It's no different from any other company."

Microsoft started with a "digital security strategy" to give a sense of how education affected the organization. "Employees want to know how their work relates to the broader strategy," he said. The approach covers assurance, identity management, device health, data and telemetry, information protection, and risk management, where education and awareness come into play.

"Humans are the firewall – the last line of defense for what we're doing," he added. Today's attacks have shifted to the individual, with a stronger focus on credential phishing and identity-based threats. The adversaries' level of sophistication has evolved, said Sexsmith, and the days of receiving emails with poor spelling and grammatical errors are over. "The attackers are getting smart just as we're increasing our technology and becoming smarter," he noted. 

Sexsmith took a deep dive into three aspects of Microsoft's education and awareness program: role-based security and compliance training, awareness campaigns, and information platforms where best practices, education, information, and protection are shared via company intranets.

Employees across the business are required to take three internal training courses: Standards of Business Conduct, Security Foundations, and Privacy 101. Some trainings are role-dependent; for example, engineers are required to take a technical security training course called Strike.

Motivation Is Key
The key challenge is creating an engaging, relatable training course that effectively teaches employees the concepts they need to know, Sexsmith said.

Sexsmith pointed to a few tricks he uses in his programs. One of these is the "Social Proof Theory," a social and psychological concept that describes how people copy other people's behavior – if your colleagues are doing a training, you'll do it, too. Gamification also helps: "People want to learn; people want to master skills, but there's also a competitive nature around that," he said. Some trainings use videos that make security concepts more accessible.

One problem, he said, is lessons that aren't reinforced aren't retained. Humans forget half of new information learned within an hour and 70% of new information within a day. "By lunchtime, you're going to forget 50% of the stuff I'm up here saying," he joked to his morning audience.

To fight this, Microsoft uses a training reinforcement platform called Elephants Don't Forget to help employees build muscle memory around new concepts. During the gap between trainings, the program sends participants two daily emails with a link to questions tailored to the course. They have 60 seconds to respond to each question; if they get it wrong, they're given more information on the topic. A customized dashboard shows their scores and progress over time.

"It's all about the engagement and staying with that until you master it, and that's when you become the most efficient," said Sexsmith.

Then there is the application of concepts, which is done through phishing simulations. "This is where the rubber meets the road," he added. Fake emails, designed to appear as though they come from Microsoft, give employees a chance to apply their new knowledge. They could click on an email and still have a chance to report it, or follow through and share their credentials.

In these test campaigns, Sexsmith blends personal and professional by creating themed awareness campaigns around Tax Day, spring cleaning, cybersecurity awareness month, and Black Friday. Cybercriminals do the same, and this helps employees gain a sense of different types of phishing emails they might see.

Related Content:

Check out The Edge, Dark Reading's new section for features, threat data, and in-depth perspectives. Today's featured story: "Tense Talk About Supply Chain Risk Yields Few Answers."

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
2/28/2020 | 3:10:34 PM
Client vs Server Side Attack Shift
I like the line "Humans are a firewall". The exposure of the human element has been a large reason as to why between the 90's and early 2000's attacks transitioned from server side to client side much more heavily.
COVID-19: Latest Security News & Commentary
Dark Reading Staff 5/22/2020
How an Industry Consortium Can Reinvent Security Solution Testing
Henry Harrison, Co-founder & Chief Technology Officer, Garrison,  5/21/2020
10 iOS Security Tips to Lock Down Your iPhone
Kelly Sheridan, Staff Editor, Dark Reading,  5/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-13458
PUBLISHED: 2020-05-25
An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There are CSRF issues with the log-clear controller action.
CVE-2020-13459
PUBLISHED: 2020-05-25
An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There is stored XSS in the Bulk Resize action.
CVE-2020-13442
PUBLISHED: 2020-05-25
A Remote code execution vulnerability exists in DEXT5Upload in DEXT5 through 2.7.1402870. An attacker can upload a PHP file via dext5handler.jsp handler because the uploaded file is stored under dext5uploadeddata/.
CVE-2020-5537
PUBLISHED: 2020-05-25
Cybozu Desktop for Windows 2.0.23 to 2.2.40 allows remote code execution via unspecified vectors.
CVE-2020-13438
PUBLISHED: 2020-05-24
ffjpeg through 2020-02-24 has an invalid read in jfif_encode in jfif.c.