Skip to main content

Cyber Security Training for Employees

Manager and employee looking at computer while discussing training at desk.

A large number of information security incidents can be directly attributable to inadequate security awareness training. Empowering employees to recognize common cyber threats and initiate appropriate notification and containment procedures can have a large impact on an organization’s computer security posture. Security awareness training teaches employees to understand system vulnerabilities and threats to business operations and their own responsibilities and accountabilities when using a computer or accessing the business network. A strong information security program includes training information technology (IT) users on security policy, procedures and techniques, as well as the management, operational and technical controls necessary to keep IT resources secure. 

Mandatory new hire training and regularly scheduled refresher training courses should be established to help instill a data security culture of your organization. Require new employees to complete the training within a specified timeframe (e.g., 30 days) and document the dates the employees have completed the new hire training and refresher courses. Employee training can include:  

Responsibility for company data security

Employers can continually emphasize the critical nature of data security and the responsibility of each employee or contractor to protect company data, including confidential customer data and the company’s intellectual property through cyber security training. It can also outline and highlight any legal and regulatory obligations the company and the employee may have to respect and protect the privacy of information and its integrity and confidentiality.

Employees should understand that they should use their computers only for company-authorized purposes. Employees are in the best position to help ensure their actions do not create a legal or security exposure for the company.  

Document management

Employees should be educated on your records management policy. The training can provide guidance on naming conventions, where the files should be stored, when files need to be backed up and your final retention and disposal guidelines.  

Incident response procedures

Employees should be aware of your incident response procedures. Educate employees how to recognize suspected or actual cyber-attacks and how to immediately report and contain the incident so your IT team can be promptly engaged to mitigate and investigate the threat.  

Passwords

Educate employees on password management and how to select strong passwords.

Unauthorized software

Employees should be made aware that they are not allowed to install unauthorized software on any company computer. Doing so could make the company susceptible to malicious software downloads that can attack and corrupt company data. Company hardware should allow only those personnel with appropriate admin credentials to install software.

Internet usage

Your company policies and procedures should establish safe browsing rules and limits on employee internet usage in the workplace. Employees should have clear knowledge of the guidelines and types of sites that are deemed acceptable or unacceptable under your policy.

Email usage

Responsible email usage can be the best defense for preventing data theft and protecting against downloading malicious software. Training on how scams can occur and appropriate responses to suspicious e-mails can help avoid introducing malicious software to your company’s systems. A policy for handling e-mail can include only accepting and opening attachments from email that:  

  • Comes from someone they know.
  • Comes from someone they have received email from before.
  • Is something they were expecting.
  • Does not look odd with unusual spellings or characters.  

Employees should be aware of scams and not respond to email from sources they do not recognize.

Social engineering and phishing 

Train employees to recognize and protect against common cybercrime and information security risks including social engineering, online fraud, phishing, web-browsing risks, and other common threats including physical threats.  

Social media policy

Educate your employees on the company social media policy and your restrictions on the use of company email addresses to register, post or receive social media.  

Mobile devices

Communicate your mobile device policy to employees for company-owned and personally owned devices used during the course of business.

Protecting IT equipment and resources

Educate employees about their responsibilities for protecting the IT equipment and resources in their possession. Some steps to help protect IT equipment and stored data include:  

  • Safeguarding their computers from theft by locking them or keeping them in a secure place.
  • Backing up critical information routinely and storing backup copies in company approved secure location(s).
  • Encrypting sensitive information kept in storage or transmitted to others.
  • All employees are responsible for accepting antivirus protection and software patches or updates within the company established timeframes.
  • Employees are not allowed to disable or bypass antivirus or other security protections.  

Related resources

Cyber Risk Management - Getting Started - Establishing a Security Baseline

This article discusses the importance of management commitment as one strategy in a cyber security program to help prevent unauthorized access or damage to your information, networks or computer systems and equipment.

Related resources

Cyber Risk and Your Company Website

This bulletin discusses the importance of network security as one strategy in a cyber security program to help prevent unauthorized access or damage to your information, networks or computer systems and equipment.

Related resources

Information Technology (IT) Incident Response Plan

Every business should plan for the unexpected. This bulletin discusses how having an incident response plan can assist with protecting the integrity of company and customer data in your business.