One Size Does Not Fit All: Toward Contextualized Security Awareness Training Through User-Centred Design
B.C.P. Zuurbier (TU Delft - Technology, Policy and Management)
S.E. Parkin – Mentor (TU Delft - Technology, Policy and Management)
M.J.G. van Eeten – Graduation committee member (TU Delft - Technology, Policy and Management)
K.L.L. van Nunen – Graduation committee member (TU Delft - Technology, Policy and Management)
More Info
expand_more
Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons.
Abstract
As cybercrimes rise, companies increasingly invest in security awareness training to protect themselves, but the effectiveness of the training is being called into question by researchers. Vendors sell one-size-fits-all training, yet these programmes fail to take the routines and needs of employees into account. This results in low engagement, wasted resources and, most importantly, little change in actual behaviour. Research has explored the relation between training and behaviour, identifying several factors that influence behaviour change. The resulting advice however often remains highly abstract. As such, this research explores how security awareness training can be made more effective by involving employees and designing or modifying it to align with their primary work tasks. It offers a structured approach and practical examples for practitioners to learn from.
The research was conducted as a case study in a large engineering company spread across Europe, focussing on the offices in the Netherlands. The pseudonym IECC was given to the company, as it was an International Engineering and Consultancy Company. Qualitative research methods were used, which included semi-structured interviews with employees from three departments and external experts, brainstorming sessions with employees and an expert validation session with IECC's CISO and change manager. The main research question was: "How can security awareness training be designed or modified to align with employees’ existing work routines and needs?".
Co-design was used to answer this research question, as each step in the approach used employee input. First, employees were involved in defining their needs and routines from their primary work tasks to answer SQ1, the first sub-question. Three departments of IECC participated in the research, which included the finance department, the Business Unit Living Environment (BULE) and the fieldworkers from Field Lab Consultancy (FLC). The next step in the approach was to evaluate the current training for SQ2, in which employees were also involved. This helped determine which parts of training aligned with their needs and routines and which parts did not. For the last step, employee and expert input was combined to address the misalignments found, thus answering SQ3. This led to practical and example supported advice, targeting the factors that influence the effectiveness of security awareness training on secure behaviour.
The findings outline an approach to better align training with the needs and routines of employees. The first step in the process is to gather employee input on their primary tasks, needs and routines. The next step is to evaluate the current training in order to determine how well it aligns with the needs and routines found, identifying what needs to be changed and what is already working. The third and final step is to modify or design training using the identified building blocks, to promote actual behaviour change. By involving employees early on in the process, organisations not only gather the input needed to make targeted training, but also build concordance with them, meaning people are committed, which is needed for lasting behaviour change.