
Most common mistakes in training staff for cybersecurity
- – Training with unrealistic simulations.
- I see this all the time! Companies “dumb” down their training to avoid complaints. This causes a better sense of employees doing well in the trainings but captures unrealistic metrics for what your companies true security posture looks like.
- Lack of hands on training.
- Unfortunately due to most business need a lot of companies will shy away from these types of trainings due to time constraints or not wanting to “disrupt” things. This is an immediate gratification that is filled in the time but will hurt you in the long run. You must have real hands on approaches that your staff are able to replicate when an attack occurs.
- Not tailoring training
- This could be number 1 honestly! This is something I think every org is guilty of at some point. They have to meet compliance or get their training out to the staff so they push a generic training that is for the whole company. This does not inherently mean the training is bad but is it something that some of those staff will ever actually encounter? For instance, If you sent out a whole training about how to look out for suspicious people in your offices , inherently that’s good training. Now what if you then went and looked where your security staff work and realize they are in a locked room where only 5 or 6 people have access. Does that training really value their time? No not really since it would be almost impossible for them to not notice someone out of place in their environment.
- Not showing consequences
- This is very common where someone may actually “click” a phishing email, fail a training, or even pass a training and yet never know the impact of what training they are actually doing. Many just play the training and tune out. This breeds an environment where in a real instances of attack people will just “tune out”. Make sure everyone understands the full consequences of actions and play the whole scenario out!
- Poorly communicated policies
- Many companies purchase third party training. This is typically good training but the issue usually lies with how does that companies policies align with the training and does the staff know where to actually find these policies and align them? This is a common mistake and something that should be avoided!





