
Plan, design, and execute a security and awareness program to protect assets, data, sensitive information from hacking and unauthorized access. Apply persona-based and technical insights to drive prevention and recovery.
Meet Mohammad Chelsea, a certified big data, business intelligence, DevOps, and cybersecurity engineer with over ten years of experience, who mentors aspiring architects across domains.
Define training and awareness and explain their roles in driving behavior change to reduce security incidents. Use phishing and malware statistics to justify programs and boost compliance and trust.
Explore how people, processes, and technology drive the NIST framework’s five functions—identify, protect, detect, respond, and recover—through asset management, access control, training, and proactive incident planning.
Define vpn, end point, credentials, and two-factor and multi-factor authentication; explain password managers, router, firewall, attack vectors, defense in depth, security information and event management (siem), and apt.
Define basic risk terminologies by distinguishing vulnerability, threat, and risk, explain how a weakness may be exploited, leading to data loss, damages, and decisions to fix or accept risk.
Define law, regulation, policy, standard, and guideline, detailing government enforcement, contractual obligations, internal rules, best practices, and secure practices like encryption and strong passwords.
Define attacks and social engineering terminologies, including MITM, brute force, credential harvesting, phishing, smishing, spear phishing, and whaling. Explain malware, ransomware, malvertising, drive-by downloads, USB drops, tailgating, and email compromise.
Assess current state of security awareness training and employee engagement, noting gaps between awareness and caring or between knowing and doing, and the imperative to boost engagement before behavior change.
Examine bias, distraction, apathy, and fatigue through the Dunning-Kruger effect and learned helplessness, and analyze how attention spans and seven second bumper ads drive security behavior and brand awareness.
Leverage human attention spans, hooks, and storytelling to design effective security awareness training. Understand how the first 30 seconds and storytelling biology: cortisol, oxytocin, and dopamine drive engagement.
Define the marketing persona and the sales funnel for security awareness training, and connect branding, marcom, and content marketing to reach and educate target audiences.
Explore marketing tactics, automation, and integrated campaigns for training and awareness, including emails, guerrilla, outdoor, video, ambient, and content marketing, with analytics via Pardot and HubSpot.
Define the target market, unique value, and problem to solve to craft a clear brand statement, taglines, colors, and positioning, reflecting the brand voice.
Design and plan a security and awareness program tailored to the organization’s risk appetite, culture, and resources, aligned with HIPAA, GLBA, GDPR, ISO 27001, and 22301.
Explore learning science and behavior design for security awareness, using Fogg’s motivation-ability-prompt and Gardner’s seven learning styles. Emphasize customized, teachable moments and corrections to boost retention.
Deliver precise security training by tailoring the message to the right person at the right time, using clear speech and audience-specific topics like phishing, malware, and data privacy.
Launch phishing simulations to educate users and test awareness, incorporating anti-phishing reporting tools and redirection scenarios. Establish a transparent training plan with reminders, measurable baselines, and interactive channels for feedback.
Explore carrot versus stick approaches to deter repeat offenders and reinforce security culture. Integrate VPN, firewalls, policies, guidelines, reporting, escalation, three strikes, and role-aligned job descriptions for stronger awareness.
Not all training and awareness programs are alike.
Building a robust security awareness program is important, but it can be in vain in your employees don't buy into what you're selling and actually change their security behavior.
Go “beyond compliance” to learn about sales and marketing techniques that can take a training and awareness program to the next level: engagement and behavior change.
This course also includes security basics for soft-skilled professionals new to the security field, as well as how to leverage brain chemistry to be more effective.
This learning path is designed for established security practitioners with existing security expertise who are new to the practice of security training and awareness and people with existing marketing and communications experience who are entering the field of security training and awareness.
Any hacker will tell you that the easiest target isn’t a system or a technology; it’s people. In this learning path, you’ll learn how to engage your audience and create “pull” for your training and awareness.
You’ll learn how to assess the security culture of your organization and map out a plan to improve it.
You’ll learn how align your program to your organization’s goals and get executive support.
You’ll learn how people learn, and how they consume media.
You’ll learn how to create marketing personas and how to get the right message to the right person at the right time, increasing the likelihood of behavioral change.
You’ll also learn about: the awareness maturity model, measuring impact and engagement, integrating existing technology with your training and awareness program, and evaluating human risk.