Create a security user awareness campaign

2022-12-07 | Martina Grom

Holiday season is a good time to train your users about common security risks they may fall into it. Let me describe how to create a security awareness campaign and how to let users know their score.

In Microsoft’s latest Digital Defense Report 2022 there are some very good conclusions and suggestions how to improve security in the digital space. In an environment where a lot of false information is publishes, phishing gets better and better. And people still need to be aware about security in their digital environment. The numbers, Microsoft can provide, are impressive:

We just cannot rely on Microsoft alone when it comes to protection against threats. We also need to onboard our users and keep them trained and aware about security. An excellent approach to that is a security awareness campaign and what could be the best time to do that during holiday season!

bit_unicorn

Create your own security awareness campaign

Within the security center you can create your very own security awareness campaign. In the left navigation you can launch the Attack simulation training, With those trainings you are able to run realistic attack scenarios in your organization. These simulated attacks can help you to improve security awareness in your organization.

cyber3

From here you can start a couple of simulations. The easiest way to learn how it works is with an assisted simulation which can be targeted against a couple of users first. This simulation is looking for credentials and very easy to create.

cyber4


If you are ready for your own simulation you can create and chose among a couple of simulations:

For the simulation to be as realistic as possible think about something reliable within your organization and include that to the message. If you start with credential harvest you can create user trainings afterwards that supports users to pay more attention to those types of attacks. The assistant will drive you through the necessary steps to create a successful campaign. What is really useful that you can assign simulations in different languages and you can also assign trainings to the users if they fail the simulation. After the simulation was finished you will get a summary report how the campaign went. This is especially useful when you repeat those types of simulations after a while.

cyber6

Learn more: Get started using Attack simulation training - Office 365 | Microsoft Learn


98% basic security hygiene still protects against 98% of attacks

Be aware that basic security hygiene can help you to prevent threats in your organization. Multifactor authentication is the easiest to use and still a big struggle for organizations. To prevent against MFA fatigue, Microsoft will change MFA authentication to Authenticator number matching.

cyber7

The Cyber resilience bell curve infographic shows basic security hygiene practices to implement to protect against 98% of attacks:

cyber2

The attack simulation is a great way to improve user awareness!

Categories: Azure, English, Microsoft365, Security, cybersecurity

Source: https://blog.atwork.at/post/FestiveSecurityAwareness