Offer tailored cyber security training to your employees - ITSAP.10.093

One of the top 10 IT security actions from the Cyber Centre is to provide cyber security Cyber securityThe protection of digital information, as well as the integrity of the infrastructure housing and transmitting digital information. More specifically, cyber security includes the body of technologies, processes, practices and response and mitigation measures designed to protect networks, computers, programs and data from attack, damage or unauthorized access so as to ensure confidentiality, integrity and availability. training that is tailored to your organization's business needs and security requirements. By providing tailored training to all personnel, including employees, contractors, managers and executives, you can increase awareness of the cyber security issues that your organization faces. When your employees have a greater awareness of cyber security, your organization can reduce its risks. Training creates a positive cyber security culture where personnel feel supported and equipped with the right tools to carry out their job functions.

On this page

Types of training

Cyber security training should cover various topics and can be delivered in different formats. For example:

  • basic cyber security training for new and existing personnel to review policies, procedures and current threats
  • computer-based training that personnel can take from their desks to refresh their understanding of key cyber security topics
  • role-based training for specific job functions, such as system administrators or developers

For all types of training, consider incorporating practical exercises, such as learning to spot phishing PhishingAn attempt by a third party to solicit confidential information from an individual, group, or organization by mimicking or spoofing a specific, usually well-known brand, usually for financial gain. Phishers attempt to trick users into disclosing personal data, such as credit card numbers, online banking credentials, and other sensitive information, which they may then use to commit fraudulent acts. emails or reviewing incident response processes.

 

Training topics

At a minimum, training should include the following topics:

  • identifying and handling phishing attempts
  • strengthening passwords
  • updating and patching systems
  • securing IT assets and sensitive information
  • reporting incidents

Including case studies or examples of publicly known cyber security incidents in training material can help demonstrate vulnerabilities, threat actor techniques and mitigation measures.

Depending on the nature of your organization, specific job requirements and industry standards, you may need to provide more specialized training. For example, critical infrastructure Critical infrastructureProcesses, systems, facilities, technologies, networks, assets, and services essential to the health, safety, security, or economic well-being of Canadians and the effective functioning of government. Critical infrastructure can be stand-alone or interconnected and interdependent within and across provinces, territories, and national borders. Disruptions of critical infrastructure could result in catastrophic loss of life, adverse economic effects, and significant harm to public confidence. sectors will need to provide training related to the cyber security elements of operational technology and industrial control systems.

Your organization may also want to provide awareness training on topics such as misinformation, disinformation and artificial intelligence Artificial intelligenceA subfield of computer science that develops intelligent computer programs to behave in a way that would be considered intelligent if observed in a human (e.g. solve problems, learn from experience, understand language, interpret visual scenes). technologies.

 

In-house training

If you have the resources and expertise, make in house training opportunities available to all personnel. Coordinate training activities with your IT and security teams to ensure topics are covered appropriately.

 

External training

You may need to look at third-party training providers if your organization does not have the resources to provide in-house training.

The Cyber Centre Learning Hub offers in class and online learning programs for various audiences, as well as customized programs. These activities and programs are offered primarily to the Government of Canada (GC) and our domestic partners. However, other government organizations and industry partners who work with GC departments may also participate.

Our Certifications in the field of cyber security publication outlines globally recognized certification training bodies that offer a variety of training options at different levels.

 

Learn more

 
Date modified: