<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Timoléon Tilmant, Auteur</title>
	<atom:link href="https://www.riskinsight-wavestone.com/en/author/timoleon-tilmant/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.riskinsight-wavestone.com/author/timoleon-tilmant/</link>
	<description>The cybersecurity &#38; digital trust blog by Wavestone&#039;s consultants</description>
	<lastBuildDate>Mon, 12 Jul 2021 08:54:30 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/Blogs-2024_RI-39x39.png</url>
	<title>Timoléon Tilmant, Auteur</title>
	<link>https://www.riskinsight-wavestone.com/author/timoleon-tilmant/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>The creation of Wavestone’s new internal awareness program (2/2)</title>
		<link>https://www.riskinsight-wavestone.com/en/2020/06/the-creation-of-wavestones-new-internal-awareness-program-2-2/</link>
		
		<dc:creator><![CDATA[Timoléon Tilmant]]></dc:creator>
		<pubDate>Fri, 26 Jun 2020 09:00:26 +0000</pubDate>
				<category><![CDATA[Cyberrisk Management & Strategy]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Sections]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[cyberawareness]]></category>
		<category><![CDATA[DSI]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=13299</guid>

					<description><![CDATA[<p>Find the entire story about the creation of TRUST in my first article. &#160; A campaign launch is all well, but how do you keep it going over time? The creation of TRUST was not an end in itself, but...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/06/the-creation-of-wavestones-new-internal-awareness-program-2-2/">The creation of Wavestone’s new internal awareness program (2/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Find the entire story about the creation of TRUST in my <a href="https://www.riskinsight-wavestone.com/en/2020/06/the-creation-of-wavestones-new-internal-awareness-program-1-2/">first article.</a></p>
<p>&nbsp;</p>
<h2>A campaign launch is all well, but how do you keep it going over time?</h2>
<p>The creation of TRUST was not an end in itself, but a stepping-stone for the future.</p>
<p>At the start of the project, we immediately envisaged the annual pace of our two awareness plans.</p>
<p>Two, because we had to keep in mind that we were raising awareness for two distinct populations: newcomers and existing employees.</p>
<p>For newcomers, the solution is simple: plan the launch of all existing TRUST resources over one year to space out messages.</p>
<p>&nbsp;</p>
<figure id="post-13290 media-13290" class="align-none"><img fetchpriority="high" decoding="async" class="size-full wp-image-13290 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-1-3.png" alt="" width="854" height="584" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-1-3.png 854w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-1-3-279x191.png 279w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-1-3-57x39.png 57w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-1-3-768x525.png 768w" sizes="(max-width: 854px) 100vw, 854px" /></figure>
<p>&nbsp;</p>
<p>For all other employees, it&#8217;s more complex. How to get the messages across again without giving a feeling of déjà vu, fatigue or even an overdose?</p>
<p>We have therefore organized our awareness plan with 3 major initiatives spaced out over time.</p>
<p>&nbsp;</p>
<h2>A new monthly meeting: The Trust minute</h2>
<p>&nbsp;</p>
<figure id="post-13292 media-13292" class="align-none"><img decoding="async" class="size-full wp-image-13292 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-2-2.png" alt="" width="800" height="450" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-2-2.png 800w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-2-2-340x191.png 340w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-2-2-69x39.png 69w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-2-2-768x432.png 768w" sizes="(max-width: 800px) 100vw, 800px" /></figure>
<p>&nbsp;</p>
<p>A one-minute film broadcasted on all our communication channels to present 5 different messages per month:</p>
<ol>
<li>An example of an anonymous user or client incident</li>
<li>A Trustee, our security tool presented in the previous article</li>
<li>A security indicator (e.g. the percentage of new recruits who have completed e-learning, the number of those leaving the firm detected downloading documents before they leave). Sharing these indicators helps raising awareness and demonstrates that controls have been lifted.</li>
<li>A daily tip given by our friend Sofia</li>
<li>A popularized cyber news story</li>
</ol>
<p><strong> </strong></p>
<figure id="post-13300 media-13300" class="align-none"><img decoding="async" class="size-full wp-image-13300 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-3-EN.png" alt="" width="1920" height="1080" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-3-EN.png 1920w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-3-EN-340x191.png 340w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-3-EN-69x39.png 69w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-3-EN-768x432.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-3-EN-1536x864.png 1536w" sizes="(max-width: 1920px) 100vw, 1920px" /></figure>
<p>&nbsp;</p>
<h2>A new campaign of cybercoffee quizzes because it gets results</h2>
<p>Of course, we must reinvent it, change the quizzes (but not necessarily the themes) and change the prize? All of this is easy and requires little preparation. Admittedly, this period of lockdown slightly challenged our initial plan. But it has been an opportunity to be creative and to release, in partnership with my colleagues in the Cybersecurity &amp; Digital Trust practice, the new <a href="https://youtu.be/YneNQ0nts98">#TotalCyberAwakening video </a>series about lockdown.</p>
<p>&nbsp;</p>
<h2>An annual global event in October during Cyber Security Month</h2>
<p>In 2019, we organized a firm-wide competition on the theme of protecting personal digital information.</p>
<p>Every week, all employees received a question by email which they could answer directly via option buttons <em>(sending a multiple-choice approval via Power Automate)</em>. Depending on their answer, they received a second email with the answer and the various tips associated to be used on a personal basis.</p>
<p>Answering a question and getting a correct answer would help contributing to a Euro prize fund. More than €2,100 was donated to the ISSA association, an association which Wavestone has partnered with to promote cybersecurity among schools and children.</p>
<p>This first game, based entirely on voluntary participation, enabled us to reach more than a third of Wavestone&#8217;s employees.</p>
<p>&nbsp;</p>
<figure id="post-13302 media-13302" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-13302 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-4-EN.png" alt="" width="781" height="1352" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-4-EN.png 781w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-4-EN-110x191.png 110w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-4-EN-23x39.png 23w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-4-EN-768x1329.png 768w" sizes="auto, (max-width: 781px) 100vw, 781px" /></figure>
<p>&nbsp;</p>
<p>We are already preparing for next October&#8217;s initiative and this time we will go further with videos, games, meetings, quizzes under a global theme inspired by a famous TV series. What if this time, the new threat of Wavestone was the return of the White Walkers?</p>
<p>&nbsp;</p>
<h2>6 key elements to keep in mind</h2>
<p>To sum up, the key elements for creating a successful awareness program are as follows:</p>
<ol>
<li>Set achievable goals</li>
<li>Define a common thread (a theme, a brand) that will allow users to easily associate your messages with security</li>
<li>Define a short list of messages to be communicated and stick to it</li>
<li>Diversify the media and channels (posters, films, emails, e-learning, games) but always keep at least one event to meet the users</li>
<li>First use the tools already at your disposal (PowerPoint, emails, PowerAutomate) before acquiring new interesting solutions if needed, but not necessarily a priority to get started</li>
<li>Be creative and use humor to get your messages across (however, culture differences may have an impact in case of an international group)</li>
</ol>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/06/the-creation-of-wavestones-new-internal-awareness-program-2-2/">The creation of Wavestone’s new internal awareness program (2/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Récit de la création du nouveau programme de sensibilisation interne de Wavestone (2/2)</title>
		<link>https://www.riskinsight-wavestone.com/en/2020/06/programme-sensibilisation-interne-wavestone-2-2/</link>
		
		<dc:creator><![CDATA[Timoléon Tilmant]]></dc:creator>
		<pubDate>Fri, 26 Jun 2020 09:00:07 +0000</pubDate>
				<category><![CDATA[Cyberrisk Management & Strategy]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[cyberawareness]]></category>
		<category><![CDATA[DSI]]></category>
		<category><![CDATA[sensibilisation]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=13288</guid>

					<description><![CDATA[<p>Retrouver toute l&#8217;histoire de la création de TRUST dans mon premier article. &#160; Un lancement de campagne c’est bien, mais comment tenir dans la durée ? La création de TRUST n’a pas été une finalité, mais un tremplin pour la...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/06/programme-sensibilisation-interne-wavestone-2-2/">Récit de la création du nouveau programme de sensibilisation interne de Wavestone (2/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Retrouver toute l&#8217;histoire de la création de TRUST dans mon <a href="https://www.riskinsight-wavestone.com/en/2020/06/the-creation-of-wavestones-new-internal-awareness-program-1-2/">premier article.</a></p>
<p>&nbsp;</p>
<h2>Un lancement de campagne c’est bien, mais comment tenir dans la durée ?</h2>
<p>La création de TRUST n’a pas été une finalité, mais un tremplin pour la suite.</p>
<p>Au démarrage du projet, nous avions tout de suite imaginé quel serait le rythme annuel de nos 2 plans de sensibilisation.</p>
<p>Nous devions avoir en tête de gérer la sensibilisation de 2 populations distinctes : les nouveaux et les anciens collaborateurs.</p>
<p>Pour les nouveaux, la solution est simple : planifier le lancement de tous les supports TRUST existants sur une année pour espacer les messages.</p>
<p>&nbsp;</p>
<figure id="post-13289 media-13289" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-13289 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-1-3.png" alt="" width="854" height="584" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-1-3.png 854w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-1-3-279x191.png 279w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-1-3-57x39.png 57w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-1-3-768x525.png 768w" sizes="auto, (max-width: 854px) 100vw, 854px" /></figure>
<p>&nbsp;</p>
<p>Pour tous les autres collaborateurs, c’est plus complexe. Comment faire à nouveau passer les messages sans donner un sentiment de déjà vu, de lassitude, voire d’overdose ?</p>
<p>Nous avons donc organisé notre plan de sensibilisation avec 3 grandes actions espacées temporellement.</p>
<p>&nbsp;</p>
<h2>Un nouveau rendez-vous mensuel : The Trust minute</h2>
<p>&nbsp;</p>
<figure id="post-13291 media-13291" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-13291 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-2-2.png" alt="" width="800" height="450" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-2-2.png 800w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-2-2-340x191.png 340w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-2-2-69x39.png 69w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-2-2-768x432.png 768w" sizes="auto, (max-width: 800px) 100vw, 800px" /></figure>
<p>&nbsp;</p>
<p>Un film d’une minute diffusé sur tous nos canaux de communications pour présenter 5 messages différents par mois :</p>
<ol>
<li>Un exemple anonymisé d’incident utilisateur ou avec un client</li>
<li>Un Trustee, nos outils de sécurité présentés dans l&#8217;article précédent</li>
<li>Un indicateur de sécurité (ex : le pourcentage de nouveaux ayant réalisé le e-learning, le nombre de démissionnaires détectés à télécharger des documents avant leur départ). Le fait de partager ces indicateurs permet de sensibiliser sur la problématique et de démontrer l’existence des contrôles.</li>
<li>Une astuce du quotidien donnée par notre amie Sofia</li>
<li>Une actualité cyber vulgarisée</li>
</ol>
<p>&nbsp;</p>
<figure id="post-13295 media-13295" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-13295 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-3-1.png" alt="" width="800" height="450" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-3-1.png 800w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-3-1-340x191.png 340w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-3-1-69x39.png 69w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-3-1-768x432.png 768w" sizes="auto, (max-width: 800px) 100vw, 800px" /></figure>
<p>&nbsp;</p>
<h2>Une nouvelle campagne de cybercoffee quizz car le résultat est au rendez-vous.</h2>
<p>Evidemment, il faut se renouveler, changer les questionnaires (mais pas forcément les thèmes), changer le goodie, mais tout cela est facile et demande peu de préparation. Certes, je vous l’avoue, cette période de confinement a légèrement remis en cause notre plan initial. Cependant, cela a été l’occasion d’être imaginatif et de sortir, en partenariat avec mes collègues de la practice Cybersécurité &amp; Digital Trust, la nouvelle série en <a href="https://youtu.be/YneNQ0nts98">vidéo TotalCyberAwakening</a> sur le confinement.</p>
<p>&nbsp;</p>
<h2>Un évènement global annuel en octobre lors du mois de la cybersécurité.</h2>
<p>En 2019, nous avions organisé un jeu concours à l’échelle du cabinet sur le thème de la protection de la vie numérique personnelle.</p>
<p>Chaque semaine, tous les collaborateurs recevaient une question par mail à laquelle ils pouvaient répondre directement via des boutons de choix <em>(envoi d’une approbation à choix multiples via Power Automate)</em>. En fonction de leur réponse, ils recevaient un second email leur annonçant la réponse et différents conseils associés à utiliser à titre personnel.</p>
<p>La participation à une question et une bonne réponse alimentaient une cagnotte en euros. Plus de 2100€ ont ainsi été reversés à l’association ISSA à laquelle Wavestone s’est associée pour promouvoir la cybersécurité auprès des écoles et des enfants.</p>
<p>Ce premier jeu sur base de volontariat nous a permis d’atteindre plus d’un tiers des collaborateurs de Wavestone.</p>
<p>&nbsp;</p>
<figure id="post-13293 media-13293" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-13293 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-4.png" alt="" width="781" height="1352" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-4.png 781w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-4-110x191.png 110w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-4-23x39.png 23w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-4-768x1329.png 768w" sizes="auto, (max-width: 781px) 100vw, 781px" /></figure>
<figure id="post-13289 media-13289" class="align-none"></figure>
<p>&nbsp;</p>
<p>Nous sommes déjà en train de préparer celui d’octobre prochain et cette fois-ci nous irons plus loin, avec des vidéos, des jeux, des rencontres, des quizz sous un thème global inspiré d’une célèbre série TV. Et si cette fois-ci la nouvelle menace de Wavestone était le retour des marcheurs blancs ?</p>
<p>&nbsp;</p>
<h2>6 éléments clés à retenir</h2>
<p>Pour résumer, les éléments clés de succès pour la création d’un programme de sensibilisation réussi sont les suivants :</p>
<ol>
<li>Se fixer des objectifs chiffrables et atteignables</li>
<li>Définir un fil rouge (un thème, une marque) qui va permettre aux utilisateurs d’associer facilement vos messages à la sécurité</li>
<li>Définir une courte liste de messages à faire passer et s’y tenir</li>
<li>Diversifier les supports et les canaux (affiches, films, mails, e-learning, jeux) mais toujours conserver au moins un évènement permettant d’aller à la rencontre des utilisateurs</li>
<li>Utiliser dans un premier temps les outils déjà à votre disposition (PowerPoint, mails, PowerAutomate) avant d’acquérir si besoin de nouvelles solutions intéressantes mais pas forcément prioritaires pour démarrer</li>
<li>Faire preuve de créativité et utiliser l’humour pour faire passer vos messages (attention toutefois à prendre en compte les différences de culture dans le cadre d&#8217;un groupe international)</li>
</ol>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/06/programme-sensibilisation-interne-wavestone-2-2/">Récit de la création du nouveau programme de sensibilisation interne de Wavestone (2/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The creation of Wavestone’s new internal awareness program (1/2)</title>
		<link>https://www.riskinsight-wavestone.com/en/2020/06/the-creation-of-wavestones-new-internal-awareness-program-1-2/</link>
		
		<dc:creator><![CDATA[Timoléon Tilmant]]></dc:creator>
		<pubDate>Tue, 23 Jun 2020 09:00:43 +0000</pubDate>
				<category><![CDATA[Cyberrisk Management & Strategy]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[data protection]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=13272</guid>

					<description><![CDATA[<p>&#160; A year ago, the idea of TRUST was born, the name of the new awareness program at Wavestone. My team and I spent a year thinking about and developing a whole new strategy to raise awareness among Wavestone employees....</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/06/the-creation-of-wavestones-new-internal-awareness-program-1-2/">The creation of Wavestone’s new internal awareness program (1/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<figure id="post-13245 media-13245" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-13245 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-1.jpg" alt="" width="1161" height="452" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-1.jpg 1161w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-1-437x170.jpg 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-1-71x28.jpg 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-1-768x299.jpg 768w" sizes="auto, (max-width: 1161px) 100vw, 1161px" /></figure>
<p>&nbsp;</p>
<p>A year ago, the idea of TRUST was born, the name of the new awareness program at Wavestone. My team and I spent a year thinking about and developing a whole new strategy to raise awareness among Wavestone employees. Wavestone has 3,500 employees in 8 countries, whose main job is consulting (but not only!), rather young (but not only!), who know about IT and cybersecurity (but not only!).</p>
<p>This anniversary was an opportunity to reflect on the results and think about what we are going to do next. In view of the very positive feedback that I have received from our employees, I consider this program to be a success in terms of our objectives and I would therefore like to share it with you to explain how it is possible to build a program and develop materials without necessarily having an enormous budget. In a nutshell, awareness-raising is within the reach of every company, even the smallest.</p>
<p>&nbsp;</p>
<h2>It all starts with a review and objectives</h2>
<p>The assessment at the beginning of 2019 was simple: for several years, I had already developed various awareness-raising tools: a virtual character (Sofia), an e-learning module, phishing campaigns, a very stylish user charter (but I am not fooled by its actual read rate), videos, an Intranet page, awareness-raising emails, security tools available to users&#8230; but then <strong>why did our users always continue to act as if they didn&#8217;t know?</strong></p>
<p>At the same time, within the framework of the <strong>Wavestone 2021 strategic plan</strong> and its aim to position the firm in the top 3 of its category in terms of CSR, we have set ourselves the objective of being a trusted partner with 100% of our employees being aware of data protection issues.</p>
<p><strong>100%!</strong> At the beginning of 2019, I only had a 70% participation rate of employees in e-learning safety.</p>
<p>&nbsp;</p>
<figure id="post-13247 media-13247" class="align-none"></figure>
<figure id="post-13277 media-13277" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-13277 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-2-EN.png" alt="" width="591" height="560" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-2-EN.png 591w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-2-EN-202x191.png 202w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-2-EN-41x39.png 41w" sizes="auto, (max-width: 591px) 100vw, 591px" /></figure>
<p>&nbsp;</p>
<h2>But then how? What more could I do?</h2>
<p>After several group sessions and one or two sleepless nights, the ideas were there:</p>
<p>Our various actions were too diverse, <strong>a common thread was missing: a brand!</strong></p>
<p>A digital format is a good thing, but there is no substitute for a verbal discussion (we forget the traditional 2 hour face-to-face mandatory training for all newcomers, which is very time consuming and has a limited impact due to the large number of messages addressed in the 2 hours. I have led so many of them as a consultant).</p>
<p>We always talk about risk and threat, but employees need more practical examples that are well adapted to their company&#8217;s situation. What mistakes can they make on a daily basis and what would be the actual impact for Wavestone?</p>
<p>&#8220;Humor! We need humor!&#8221; Yes, but not always! Humor is a great tool to grab the attention of your target audience, to lure them in, to make them receptive to you&#8230; but what you really need is <strong>pragmatism!</strong></p>
<p>It is difficult for the employee to ultimately know what to do with the many rules given. In the end, a large part of data protection remains the mission of IT management, by implementing protection tools, alerts and controls. For example: <strong>is it up to users to be more vigilant against phishing or malicious emails?</strong> For my part, I think it&#8217;s more up to the company:</p>
<ol>
<li>to implement a better messaging protection solution,</li>
<li>a better EDR that will block the action of the faulty part,</li>
<li>to have solutions to avoid the spread of ransomware or data backups,</li>
<li>to have a multi-factor solution that will greatly reduce the use of stolen logins and passwords via a fake password reset email.</li>
</ol>
<p>It is more important to work on limiting the impact of a malicious email that will always find a willing victim, rather than focusing energy on educating users on this topic.</p>
<p>Based on this observation, what are the messages I wanted to convey? <strong>What is really in the control of the Wavestone employee, and not IT management?</strong></p>
<p>They can be summed up in 5 messages:</p>
<ol>
<li><strong>Transfer documents from your client ONLY WITH authorization:</strong>When you are a consulting firm whose employees spend so much time on your clients&#8217; IS, the primary risk is a lack of awareness and the loss of a client because your employees have taken out sensitive documents to make it easier for them to work on their workstations, or with their project manager who does not have access to the client&#8217;s IS (at least not yet, which can often happen with long processes for providing access to client’s IS). This is not a security risk as such for Wavestone, but rather a risk of a client incident that is dealt with through data protection awareness.</li>
<li><strong>Respect the project confidentiality procedure</strong>: the fundamentals! Comply with the instructions for handling client data. On the other hand, for it to be effective, this procedure must be very simple&#8230; no more than 2 or 3 rules.</li>
<li><strong>Use security tools to protect data</strong>: as long as they are easy to use! We&#8217;ll talk about this later.</li>
<li><strong>Store personal data only if necessary and process only for the intended purpose</strong>: you have to put a little GDPR message in the formula&#8230;</li>
<li><strong>Think twice before opening an attachment, clicking on the web link, and working in transport </strong><strong>and public places</strong>: &#8220;but you just told us it was the role of IT management!&#8221; Yes, sure, you&#8217;re right, but it doesn&#8217;t cost anything to add it at the end. Anyway, we always forget the last piece of advice!</li>
</ol>
<p>5 messages. Perhaps the more visual among you have noticed&#8230; but the first letter of each line combines to form…</p>
<p>&nbsp;</p>
<figure id="post-13249 media-13249" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-13249 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-3.png" alt="" width="1163" height="565" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-3.png 1163w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-3-393x191.png 393w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-3-71x34.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-3-768x373.png 768w" sizes="auto, (max-width: 1163px) 100vw, 1163px" /></p>
<figure id="post-13249 media-13249" class="align-none"></figure>
</figure>
<p>&nbsp;</p>
<p>And here&#8217;s the TRUST brand that was born, with its logo, design, style guide and visuals.</p>
<p>&nbsp;</p>
<h2>We have the brand! Like any good marketing product, it must now be broken down into multiple promotional formats.</h2>
<p>Once we had our central theme in terms of messages and visuals, all that remained was to communicate it, but not in a single action, in a series of actions linked to each other to simultaneously increase formats, channels and messages to different categories of users.</p>
<h3>Production of the TRUST video. 5-minute film in 3 parts:</h3>
<ol>
<li>An introduction to set the scene with fictional press or radio articles presenting the consequences for Wavestone of a security incident (loss of clients, loss of turnover, stock market decline, etc.).</li>
<li>5 messages: 5 humorous sketches including a Wavestone employee and a different CISO. What better than CISOs to play their own role? I was lucky that the CISOs of 2 CAC40 companies, a large French public company and a large English bank agreed to play the game in a humorous way. Many thanks again to them! Each consequence of the scene is then explained by the managing director of Wavestone, Mr Patrick HIRIGOYEN. Small video excerpt <a href="https://youtu.be/I3dbj1SHvgw">here</a>.</li>
</ol>
<ol start="3">
<li>Finally, a conclusion with a message from Mr. Pascal IMBERT, Chairman and Chief Executive Officer of Wavestone, as a more serious reminder of the risks involved for the firm and the need for each employee to feel committed and to apply the proposed measures.</li>
</ol>
<p>We received a very good feedback from the employees on this humorous film, which was widely distributed through all the firm&#8217;s communication channels.</p>
<p>The TRUST brand was quickly identifiable. But this film was just for the launch, it needs more!</p>
<h3>Creation of cybercoffee quizzes</h3>
<p>The principle is simple: answer at least 3 security questions and get a free coffee and 1 goodies (a TRUST webcam cover for this year).</p>
<p>An excellent opportunity to meet employees at a time when they are open to discussion: during their coffee break.</p>
<p>For this, you need visuals: kakemonos, polo shirts, screens with the awareness film and 1 coffee machine with free coffee. You can’t miss us!</p>
<p>&nbsp;</p>
<figure id="post-13251 media-13251" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-13251 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-4.jpg" alt="" width="658" height="878" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-4.jpg 658w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-4-143x191.jpg 143w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-4-29x39.jpg 29w" sizes="auto, (max-width: 658px) 100vw, 658px" /></figure>
<p>&nbsp;</p>
<p>Every fortnight, my team would go to a different break room in our offices to introduce TRUST, get the staff playing and answer their questions. This initiative was greatly appreciated by the employees. Beyond the lure of winning, they were delighted that we took the time to explain to them individually things they didn&#8217;t know or didn&#8217;t know well and all the simple things that were available to them. <strong>&#8220;It&#8217;s not as complicated as it sounds!”</strong></p>
<p>These quizzes, in the form of presentations at management meetings or team meetings in our various offices, enabled us to meet with more than <strong>1,000</strong> employees in person in 9 months, i.e. around 1/3 of our staff. Although time-consuming, this action remains one of the most impactful in terms of making ourselves known and getting our messages across.</p>
<p><em>Technical tip:</em> it&#8217;s very easy to implement in practice:</p>
<ul>
<li>3-question form, for us, made on Microsoft Forms,</li>
<li>QR code displayed on a kakemono or a poster so that from its phone, the participant can easily access this form (just take out the camera, no application to install)</li>
<li>Finally, a simple workflow (via Power Automate) to save the result in a database and automatically send a summary email to the participant with key messages and links to videos.</li>
</ul>
<p>The score and corrections being displayed directly on the phone after confirmation, the facilitator can directly discuss with the participant to explain their mistakes and offer them their gift.</p>
<h3>What if the security tools were superheroes?</h3>
<p>&#8220;Encrypt your document&#8221;, &#8220;Protect your passwords&#8221;, &#8220;Encrypt your emails&#8221;&#8230; so many instructions given to users who, despite their good intentions, often find themselves saying &#8220;I want to, but how can I do it?”</p>
<p>We had a whole catalog of tools installed on the workstations and were available for employees, which were simply unknown to everyone. So, we had to bring them out of the shadows and into the spotlight to show their existence and their usefulness. That&#8217;s how our League of Trustees was born!</p>
<p>&nbsp;</p>
<figure id="post-13279 media-13279" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-13279 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-5-EN.png" alt="" width="1012" height="571" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-5-EN.png 1012w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-5-EN-339x191.png 339w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-5-EN-69x39.png 69w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-5-EN-768x433.png 768w" sizes="auto, (max-width: 1012px) 100vw, 1012px" /></figure>
<p>&nbsp;</p>
<p>Each tool has its own superhero whose duty is to show our employees what they are used for and how easy it is to use them in less than 1 minute:</p>
<p>&#8220;I want to send a secure document to my client&#8221;: Encrypt it with 7zip!</p>
<p>&#8220;I want to protect the documents on my USB flash drive&#8221;: Encrypt it with BitlockerToGo, it&#8217;s on your computer!</p>
<p>Posters and short demonstration videos were used to communicate on our different channels and to present them during our Cybercoffee quizzes.</p>
<p>I wouldn&#8217;t say that they are now used every time, but at least they are better known and therefore are used more than they were before.</p>
<p>&nbsp;</p>
<figure id="post-13281 media-13281" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-13281 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-6-EN.png" alt="" width="497" height="722" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-6-EN.png 497w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-6-EN-131x191.png 131w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-6-EN-27x39.png 27w" sizes="auto, (max-width: 497px) 100vw, 497px" /></figure>
<p>&nbsp;</p>
<p><em>Technical tip:</em> did you know that you don&#8217;t need professional software and a 5-year degree in audiovisuals to make short animated films?</p>
<p>There are tools such as Powtoon or Vyond that allow you to make awareness videos very easily with a whole series of characters or settings already proposed. In 1 to 2 days you can already make your first one-minute video. Quickly, you will only need half a day of editing. The most complex part is always the script writing, the duration of this step can be very varied depending on the message you want to convey, your context or requirements (it&#8217;s this last point that personally takes me a lot of time!).</p>
<p>For simpler films, including video clips and text, personally, my new video editing tool has become Microsoft PowerPoint! You all already know how to use it to put text, animations and transitions. All you have to do now is use the video insertion, screen recording and video export functions. 3 features that make your life easier because usually you always have to find third party tools to record your screen, cut them and convert videos.</p>
<p>You can even save your films in GIF format to integrate them directly into your awareness emails! No need to redirect your user to a video site!</p>
<p>The ultimate advantage is that you can have your videos edited by other people and modified afterwards by others without training because most of your employees know how to use PowerPoint. Creativity becomes your only limit.</p>
<p>&nbsp;</p>
<h2>3 new materials, that&#8217;s it?</h2>
<p>As soon as our new materials were ready, we took the opportunity to bring our old awareness tools back to TRUST&#8217;s colours:</p>
<p>The e-learning for all new employees has been revamped with TRUST visuals by integrating the videos presented previously and refocusing the questions on our 5 messages. This more entertaining aspect enabled us to achieve our goal of having 100% of our new employees completing this e-learning programme by 2019. It is also thanks to good follow-up efforts and perseverance that this objective has been achieved! It&#8217;s not that easy getting 100%&#8230;</p>
<p>The Intranet page has also undergone a makeover to centralize all these resources and highlight the messages.</p>
<p>The security alerts for employees have also been rebranded under the TRUST brand. It should not be forgotten, but these alerts can be a great tool for raising awareness. Between the automatic email saying &#8220;We saw you, it&#8217;s not right, you&#8217;re going to be punished&#8221; and the prevention email sent by the awareness character explaining the right way to do things, the message gets across differently. And I strongly believe that it is more effective&#8230; the proof is in the observed decrease of these alerts since their implementation.</p>
<p>&nbsp;</p>
<figure id="post-13275 media-13275" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-13275 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-7-EN-1.png" alt="" width="1244" height="513" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-7-EN-1.png 1244w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-7-EN-1-437x180.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-7-EN-1-71x29.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-7-EN-1-768x317.png 768w" sizes="auto, (max-width: 1244px) 100vw, 1244px" /></figure>
<p>&nbsp;</p>
<p><strong>End of the first article&#8230; how to keep it going and my conclusion soon to be published in part 2.</strong></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/06/the-creation-of-wavestones-new-internal-awareness-program-1-2/">The creation of Wavestone’s new internal awareness program (1/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
