As we begin to think about training and awareness, we need to compile the methods we intend on using to conduct outreach:
- Include specific phishing training as part of your yearly information security training:
- If you don't conduct yearly training, start
- Develop a cycle for communicating with your entire user base through an email newsletter:
- Develop a plan where a certain number of these newsletters are used to deliver targeted phishing awareness training
- Conduct phishing exercises:
- Utilize automated tools that allow you to test your user base for their awareness of phishing threats. These tools should allow you to:
- Import your user population from your user directory instead of manually ...