An organization's security metrics reveal that high-risk departments, such as finance and human resources, continue to exhibit elevated click-through rates on sophisticated spear-phishing simulations despite completing the mandatory annual security awareness course. The CISO wants to update the awareness program to effectively reduce human risk in these departments while maintaining a supportive security culture. Which of the following strategies is the most effective approach to achieve this objective?
- AMandate generic quarterly security training courses for the entire enterprise to ensure uniform compliance across all departments.
- Deliver tailored, role-based micro-learning and targeted phishing simulations designed specifically for high-risk job functions.Answer
- CEnforce immediate account suspension and mandatory HR escalation whenever an employee clicks any simulated link.
- DImplement network-level web filtering to restrict all external email access exclusively for non-technical staff.
Answer
Deliver tailored, role-based micro-learning and targeted phishing simulations designed specifically for high-risk job functions.
Role-based security awareness tailors educational content and simulated phishing scenarios to the specific threats, data access levels, and workflows of vulnerable job functions (such as financial wire transfers or HR credential targeting). Providing frequent micro-learning modules keeps threat awareness top of mind without causing training fatigue, fostering a constructive security culture.
Step-by-Step Solution
Key Concept
Role-Based Security Awareness and Human Risk Management