<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>awareness - RiskInsight</title>
	<atom:link href="https://www.riskinsight-wavestone.com/en/tag/awareness/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.riskinsight-wavestone.com/en/tag/awareness/</link>
	<description>The cybersecurity &#38; digital trust blog by Wavestone&#039;s consultants</description>
	<lastBuildDate>Thu, 22 Jan 2026 13:27:26 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/Blogs-2024_RI-39x39.png</url>
	<title>awareness - RiskInsight</title>
	<link>https://www.riskinsight-wavestone.com/en/tag/awareness/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Are you ready to TAMAM your cybersecurity awareness?</title>
		<link>https://www.riskinsight-wavestone.com/en/2025/03/are-you-ready-to-tamam-your-cybersecurity-awareness/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2025/03/are-you-ready-to-tamam-your-cybersecurity-awareness/#respond</comments>
		
		<dc:creator><![CDATA[Noëmie Honoré]]></dc:creator>
		<pubDate>Fri, 14 Mar 2025 07:00:01 +0000</pubDate>
				<category><![CDATA[Cloud & Next-Gen IT Security]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[cybersecurity awareness]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[methodology]]></category>
		<category><![CDATA[risk management]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=25538</guid>

					<description><![CDATA[<p>This article was originally published on our corporate website wavestone.com on 26 January 2023.   Cybersecurity awareness is a journey to embed secure behaviours in people&#8217;s daily lives   To do so, you need to build a strong cyberawareness program, focus...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2025/03/are-you-ready-to-tamam-your-cybersecurity-awareness/">Are you ready to TAMAM your cybersecurity awareness?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p style="text-align: justify;"><em>This article was originally published on our corporate website <a href="https://www.wavestone.com/en/">wavestone.com</a> on 26 January 2023.</em></p>
<p style="text-align: justify;"> </p>
<h2 style="text-align: justify;">Cybersecurity awareness is a journey to embed secure behaviours in people&#8217;s daily lives</h2>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">To do so, you need to build <strong>a strong cyberawareness program</strong>, focus on your key cybersecurity themes, that engages your people and respects their uniqueness, with practical positive actions and diverse activities. In other words, a program that meets your ambitions and aims:</p>
<ul style="text-align: justify;">
<li>An <strong>effective behavioural change</strong></li>
<li>The development of a<strong> security culture</strong> in your organization</li>
</ul>
<p style="text-align: justify;">We developed our <strong>TAMAM framework</strong> to formalize our strong beliefs about how best to build a cyberawareness framework.</p>
<p style="text-align: justify;"><strong>TARGET</strong>: set concrete and measurable objectives</p>
<p style="text-align: justify;"><strong>AUDIENCE</strong>: adapt the approach according to the people concerned</p>
<p style="text-align: justify;"><strong>MESSAGE</strong>: choose a concise, positive message that calls for action</p>
<p style="text-align: justify;"><strong>ACTIONS</strong>: set up effective, concrete and various actions</p>
<p style="text-align: justify;"><strong>MEASURES</strong>: evaluate the program&#8217;s impact on behaviour</p>
<p style="text-align: justify;">This article explains the principles, the stakes and the role that TAMAM has to play to support you!</p>
<p style="text-align: justify;">But first, let’s put some contextual elements about cybersecurity awareness…</p>
<p> </p>
<h2 style="text-align: justify;">Why do they keep clicking on these phishing emails?!</h2>
<p> </p>
<ul style="text-align: justify;">
<li><strong>Our journey doing cybersecurity awareness started more than 15 years ago.</strong> And things looked quite different back then. It was the time of the new awareness programs, led by newly appointed cybersecurity managers, with little means and yet a key objective to tell people what they must do to protect the information systems. Nothing more, nothing less. It was the time of the Top 10 best practices; the Do’s and Don’ts; the mass training sessions; etc.</li>
</ul>
<ul style="text-align: justify;">
<li>Once said, these messages were considered to be common knowledge and applied by everyone; and just like that<strong> awareness was deprioritized</strong> and no longer a priority for the cybersecurity managers. It was the rough time of insufficiency and budget cuts.</li>
</ul>
<ul style="text-align: justify;">
<li>Then came the <strong>rising number of cyberattacks and the GDPR</strong>. With new risks came new appetite for awareness and education of users. Cybersecurity awareness was back in the agenda, yet with variable means and interests. Over the years it remained part of the cybersecurity topics but with great variability between the organizations when it came to effectiveness and efficiency.</li>
</ul>
<ul style="text-align: justify;">
<li>And here we are now: at the beginning of the year 2023 and the same questions remain: “I’ve tried everything but there are still some people who do not perceive the risks– what can I do?”; “I need to keep my people interested in the topic, what new things can you propose?”. Basically, what we notice is simply a <strong>lack of consideration of the effectiveness of the program</strong>: they seemed to be reaching a glass ceiling. Efforts were put, investments were made, but little change happened. That triggered our attention and led us to discussions and research until we finally came to the evidence: efforts and investment are vain if they don’t aim at <strong>effectively changing behaviours</strong> and ultimately <strong>establishing a culture of cybersecurity</strong>. But how do you do that? That’s the focus of this article.</li>
</ul>
<p> </p>
<h2 style="text-align: justify;">Are you getting everyone on board with cybersecurity?</h2>
<p> </p>
<p style="text-align: justify;">Based on these observations of the past years of cyberawareness, we developed <strong>a framework to build an effective cybersecurity awareness program</strong>. We wanted this model to be customizable so that it could be applied to every organization regardless of its size, maturity, budget, or current culture. Not a one-size-fits-all, but a backbone to be adapted to every organization.</p>
<p> </p>
<h3 style="text-align: justify;">Target</h3>
<p style="text-align: justify;">Just like with everything, you have to start with the “why”. This serves to define the <strong>objectives</strong>: a target to reach, <a href="https://www.linkedin.com/pulse/shall-we-start-your-secure-behaviours-corentin-decock/">a vision of where to go and a path to reach that place</a>.</p>
<p style="text-align: justify;">These objectives must be targeted to your priority battles, i.e., what change you want to see in your organization, <strong>precise behaviours that you expect from your people</strong>. They do not just represent good intentions – like “raising awareness among my employees” – but precise behaviours that you want to see every day. For instance, if phishing is one of your primary concerns, and it sure is: “How to educate my employees to report phishing attempts and incidents?”. Like this you see your target and the way to reach it.</p>
<p style="text-align: justify;">Precise objectives also enable <strong>measurable results</strong>. When you define them, you also define the KPIs and metrics that you will use to assess their success. As a rule of thumb: if you are unable to find a measure for your objective, that means it’s more illusional than achievable.</p>
<p style="text-align: justify;">Finally, you share these with your employees. Isn’t it plain fairness that to tell your people from the beginning what you expect from them? This way, you make them actively engaged in the change of behaviour that you expect from them. By giving them the rules of the game, you enable them to play by these rules and to win the game with you, because <strong>cybersecurity is a collective win</strong>.</p>
<p style="text-align: justify;">This first step is largely overviewed, and few are the organizations that take the necessary time to reflect on their true target when it comes to cyberawareness. However, it is the essential starting point of our journey. Just like with any journey: we can only reach a friend’s house if know their address.</p>
<p> </p>
<h3 style="text-align: justify;">Audience</h3>
<p style="text-align: justify;">And who do you want to reach exactly? That is your audience, your population, your <strong>people that need awareness, training, and education</strong>. A clear identification of these specific audiences will help you define an approach that is meant to reach them. To know these needs you will need to start by differentiating people in clusters – mostly based on their positions in the organization, their closeness to the topic, their expositions to the risks you want to prevent, their role figures, etc. These clusters can gather newcomers, external staff, local ambassadors, IT staff, etc.</p>
<p style="text-align: justify;">For each of these populations, you will want to <strong>assess their current level of mastery</strong> of the different targets defined. That is basically performing a skills gap to know what topics requires more attention for each population. This information will be essential to customize the program to the needs of these populations (because you understand what they do in life) and their current level of mastery (which you have assessed precisely).</p>
<p style="text-align: justify;"> </p>
<h3 style="text-align: justify;">Message</h3>
<p style="text-align: justify;">Off we go now with the messages you want to communicate to these people to reach these objectives; the moment where you find this catchy phrase that will be repeated oftentimes. The people with whom you will be communicating also receive numerous other communications for numerous other causes (name it: CSR, compliance, values, etc.). Hence the importance to select your messages wisely and to stay concise. The time and attention available are limited, this is why you will prefer to select <strong>a few messages that address key risks and meaningful objectives</strong>.</p>
<p style="text-align: justify;">Eventually, the tone used to communicate these messages is crucial as it must be adapted to the organizational culture: funny messages work in some environment while serious ones work better in others. Regardless of the tone used, the <strong>messages will need to be positive and call for action</strong>. Drop out the negative injunctions (“don’t”) and embrace the positive actions (“act”).</p>
<p style="text-align: justify;">With these first three steps in mind (Target, Audience and Message), you build up the framing of your cyberawareness program: you know what you want to tell, to whom, in order to reach the expected behaviours.</p>
<p style="text-align: justify;"> </p>
<h3 style="text-align: justify;">Actions</h3>
<p style="text-align: justify;">Now that you have tailored your messages for your specific audiences to reach the defined objectives, time has come to identify the actions that you will implement in this framing. Although you now open the catalogue of action, you must be focus and pragmatic. The principle when doing so is to think of the <strong>effectiveness of the chosen action in your journey to reach your objectives</strong>. <a href="https://www.riskinsight-wavestone.com/en/2023/01/cracking-the-recipe-making-employees-hungry-for-more-cyber-awareness-activities/">Creativity and innovation</a> are surely important to keep people motivated but is not the sole success factor. You want to make cybersecurity practical for people, to bring the topic closer to their life and to involve them in their learning (e.g., practical activities, application of the behaviour expected, etc.) on top of a more theoretical top-down approach.</p>
<p style="text-align: justify;"><strong>The way you implement these activities</strong> is also an essential success factor, with the right resources, people and planning to enforce the selected messages:</p>
<ul style="text-align: justify;">
<li>Who is the bearer of these messages? Internal or external?</li>
<li>How to repeat them in different ways (as different people will respond to different stimuli that can be practical, visual, spoken, etc.)</li>
<li>From what angles and with what activities should these issues be addressed in order to raise awareness among employees in the most appropriate way?</li>
</ul>
<p style="text-align: justify;">With few selected messages, you build different activities, at different moments, with different approaches, to embed these behaviours in your audiences’ daily lives.</p>
<p style="text-align: justify;"> </p>
<h3 style="text-align: justify;">Measures</h3>
<p style="text-align: justify;">Finally, <strong>this whole program needs to be evaluated</strong> in order to say if it actually allows to change behaviours – for the management that will ask to see the value delivered for its investment, or for the awareness team that will want to show tangible results from its efforts.</p>
<p style="text-align: justify;">In your quest to raise awareness, <strong>you must focus on the effectiveness of what you implement</strong>, beyond the implementation itself. All too frequently, organizations focus on numbers of activities or people addressed. But these figures seldom provide a real understanding of the change of behaviours happening.</p>
<p style="text-align: justify;">When building your evaluation plan, you need to include quantitative measures and qualitative feedback to obtain a comprehensive understanding of the achievement of your objectives. Perhaps this will require new ways to gather this information – like getting the helpdesk involved, or even obtaining fresh data from the SOC – but the outcome will bring terrific value to your program as it will allow you to review it and keep it continuously adapted to your objectives; which can also be subject to adaptations if the organizational context changes.</p>
<p style="text-align: justify;">Oh, and don’t forget one last thing if you want to create a positive trend in awareness: communicate your achievements and celebrate the victories with everyone. You deserve it.</p>
<p style="text-align: justify;"><img fetchpriority="high" decoding="async" class="aligncenter size-full wp-image-25545" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/03/Image1ENG.png" alt="TAMAM methodology relies on the following pillars: Target, Audience, Message, Actions and Measures" width="945" height="630" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/03/Image1ENG.png 945w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/03/Image1ENG-287x191.png 287w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/03/Image1ENG-59x39.png 59w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/03/Image1ENG-768x512.png 768w" sizes="(max-width: 945px) 100vw, 945px" /></p>
<p style="text-align: justify;">Take the first letter of these 5 principles and you obtain TAMAM. It is no coincidence if the world translates into “all right” in Turkish; this is what you want from your people: an adherence to your objectives and an agreement to onboard your journey to more secure behaviours.</p>
<p> </p>
<h2 style="text-align: justify;">Where to start?</h2>
<p> </p>
<p style="text-align: justify;">Now that you have a better understanding of the iterative journey to build a strong awareness program, you must find yourself in the middle on a strong questioning: where do I stand in that and how do I lean more towards what you’ve just said?</p>
<p style="text-align: justify;">A first action to take is probably to <strong>take a step back to look at your current maturity level in cyberawareness</strong>. You will need to have a clear and honest understanding of how your organization addresses this topic in order to define a path towards a greater maturity.</p>
<p style="text-align: justify;">The power of TAMAM resides notably in its ability to be used regardless of your maturity level, because its principles are adaptable and true to different situations.</p>
<p> </p>
<h3 style="text-align: justify;">Do you TAMAM?</h3>
<p style="text-align: justify;">When you <strong>TAMAM</strong>, you:</p>
<ul style="text-align: justify;">
<li>Visualize a clear and precise target – behaviours – that you want to reach</li>
<li>Tailor your approach around the need of your specific clusters of people</li>
<li>Define the few messages you want communicate to your audience on these objectives</li>
<li>Select the best manner to communicate your messages with activities that focus on effectiveness</li>
<li>Monitor and assess this effectiveness to adapt your approach and finetune your whole program</li>
</ul>
<p style="text-align: justify;">This article is only a glimpse of what TAMAM can bring to your cyberawareness program. Contact us for a full understanding of how our framework can help you step up your awareness!</p>
<p><a href="https://www.riskinsight-wavestone.com/en/contact-us/">Contact us</a></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2025/03/are-you-ready-to-tamam-your-cybersecurity-awareness/">Are you ready to TAMAM your cybersecurity awareness?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2025/03/are-you-ready-to-tamam-your-cybersecurity-awareness/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>2025 cybersecurity awareness solutions radar: how can I find the right solution for my needs?</title>
		<link>https://www.riskinsight-wavestone.com/en/2025/02/2025-cybersecurity-awareness-solutions-radar-how-can-i-find-the-right-solution-for-my-needs/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2025/02/2025-cybersecurity-awareness-solutions-radar-how-can-i-find-the-right-solution-for-my-needs/#respond</comments>
		
		<dc:creator><![CDATA[Laetitia Reverseau]]></dc:creator>
		<pubDate>Wed, 05 Feb 2025 10:19:20 +0000</pubDate>
				<category><![CDATA[Cyberrisk Management & Strategy]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[radar]]></category>
		<category><![CDATA[Wavestone]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=25316</guid>

					<description><![CDATA[<p>According to the 2024 Verizon report, the human factors is responsible for 68% of data breaches. Aware of this vulnerability, 90% of cyberattacks exploit human error, with phishing as the primary attack vector. In this context, it has become essential...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2025/02/2025-cybersecurity-awareness-solutions-radar-how-can-i-find-the-right-solution-for-my-needs/">2025 cybersecurity awareness solutions radar: how can I find the right solution for my needs?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p style="text-align: justify;">According to the 2024 Verizon report, the human factors is responsible for <strong>68% of data breaches</strong>. Aware of this vulnerability, <strong>90% of cyberattacks exploit human error</strong>, with phishing as the primary attack vector. In this context, it has become essential to raise awareness to cybersecurity risks in line with your organization&#8217;s needs.</p>
<p style="text-align: justify;">However, although <strong>companies recognize the importance of awareness content</strong>, <strong>very few manage to effectively deploy</strong> <strong>solutions</strong> adapted to their teams&#8217; specific needs. In fact, as much as awareness is a priority, choosing the most suitable tool remains a challenge. Companies are confronted to a diverse range of options, from standardized online training to interactive and personalized tools.</p>
<p> </p>
<h2 style="text-align: justify;"><strong>A radar of +100 cybersecurity awareness solutions</strong></h2>
<p style="text-align: justify;">In an environment where cybersecurity awareness is becoming a priority, the <strong>awareness solutions radar proves to be a strategic ally for companies</strong>. This tool provides a <strong>clear and structured view of available solutions</strong>, helping organizations <strong>identify the ones best suited to their needs.</strong></p>
<p><img decoding="async" class="aligncenter wp-image-28865 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/02/Image-2.png" alt="" width="837" height="561" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/02/Image-2.png 837w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/02/Image-2-285x191.png 285w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/02/Image-2-58x39.png 58w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/02/Image-2-768x515.png 768w" sizes="(max-width: 837px) 100vw, 837px" /></p>
<p> </p>
<h3 style="text-align: justify;"><strong>A decision-making tool</strong></h3>
<p><strong>The radar provides a comprehensive overview of options available and helps assess the size of the market. </strong>Thanks to the radar, companies can <strong>quickly identify high-performing</strong> <strong>and innovative</strong> <strong>solutions</strong>, while also distinguishing <strong>essential ones</strong>. To achieve this, the solutions have been grouped into 7 categories:</p>
<ol>
<li><strong>Maturity Assessment</strong>: Solutions offering robust cybersecurity maturity and human risk evaluation tools, going beyond reports or questionnaires</li>
<li><strong>E-learning</strong>: Solutions providing a variety of structured learning modules</li>
<li><strong>Technical Training</strong>: Solutions specifically designed for technical audiences (cybersecurity teams, IT, developers, etc.)</li>
<li><strong>AI</strong>: Solutions based on artificial intelligence tools</li>
<li><strong>Chatbot</strong>: Solutions integrating an interactive conversational agent</li>
<li><strong>Phishing</strong>: Solutions specialized in phishing attack simulations, distinct from e-learning modules covering the topic.</li>
<li><strong>Games</strong>: Solutions focused on gamification, offering engaging cybersecurity awareness activities.</li>
</ol>
<p>This <strong>radar aims to provide a condensed view of our benchmark and is not a ranking</strong>. It is a <strong>curated selection based on several criteria</strong>, including company size, market presence (primarily in France), and our expert evaluation. We have <strong>intentionally limited the number of solutions presented to ensure a clear and strategic overview.</strong></p>
<p>The selection favors French solutions, in line with our client base, while also including a few relevant international players. Additionally, <strong>only solutions whose core offer is product-oriented</strong>, rather than consulting services, have been included, to ensure a <strong>product-focused approach</strong>.</p>
<h3> </h3>
<h3 style="text-align: justify;"><strong>A benchmark for a tailored solution</strong></h3>
<p style="text-align: justify;"><strong>The radar is based on a benchmark of over +100 solutions available on the market</strong>, providing a <strong>comprehensive overview of the cybersecurity awareness solutions’ ecosystem</strong>.</p>
<p style="text-align: justify;">The <strong>benchmark is designed to guide your selection</strong> towards the <strong>most suitable solution</strong>. Companies <strong>fill in their criteria</strong> to <strong>generate a refined list of options: types of content </strong>(phishing, passwords, social engineering, etc.), <strong>types of formats </strong>(quizzes, videos, chatbot, e-learning, etc.),<strong> availability and flexibility of the solution</strong>,<strong> target population</strong>, <strong>price</strong>,<strong> languages</strong>, etc. This process helps <strong>avoid arbitrary choices</strong> and ensures the selection of a <strong>solution that is truly aligned with awareness challenges and objectives.</strong></p>
<p style="text-align: justify;">Thus, without trying to be exhaustive, the radar <strong>offers a wide range of options to best meet</strong> <strong>your</strong> <strong>organization&#8217;s needs.</strong></p>
<p> </p>
<h3 style="text-align: justify;"><strong>Integration process into the benchmark</strong></h3>
<p style="text-align: justify;">The process of integrating a solution into the benchmark is intended to be straightforward. Once a solution is identified, it is <strong>analyzed and sorted based on specific criteria</strong>, along with <strong>feedbacks from our Wavestone consultants.</strong> In addition, <strong>meetings with solution providers </strong>allow us to <strong>refine our analysis </strong>through demonstrations and the collection of additional information.</p>
<p style="text-align: justify;">As such, a solution with a <strong>clear and intuitive interface</strong>, offering <strong>transcriptions in multiple languages, </strong>and covering a <strong>wide range of topics</strong> (phishing, cloud, chatbot, etc.) in an <strong>innovative way</strong> will be particularly relevant. If it also receives positive feedback from our consultants, it will have a strong chance of being included in the radar.</p>
<p style="text-align: justify;">The benchmark and its radar also come with <strong>detailed presentations of certain solutions</strong>. Thanks to our <strong>expertise and strong convictions regarding awareness</strong>, some <strong>solutions deemed relevant have detailed profiles that include a more precise overview of the interface</strong> and <strong>expert opinions</strong>, enriched by discussions with vendors. These presentations not only help <strong>select the most suitable tool but also highlight often more effective yet lesser-known alternatives.</strong></p>
<p> </p>
<p style="text-align: justify;"><img decoding="async" class="aligncenter size-full wp-image-25318" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/02/Process-EN-v2-1.png" alt="" width="1344" height="370" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/02/Process-EN-v2-1.png 1344w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/02/Process-EN-v2-1-437x120.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/02/Process-EN-v2-1-71x20.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/02/Process-EN-v2-1-768x211.png 768w" sizes="(max-width: 1344px) 100vw, 1344px" /></p>
<p style="text-align: center;"><em style="font-size: revert; color: initial;">Integration process of a solution into the benchmark and radar</em></p>
<h4> </h4>
<h4><strong>Disclaimer</strong></h4>
<p>Please note that this radar is a reduced view of the associated benchmark. If you notice that a cyber awareness player you know is missing from this radar, contact us so we can evaluate and add them.</p>
<p> </p>
<h4 style="text-align: left;"><strong>Acknowledgements</strong></h4>
<p style="text-align: left;">We would like to thank Guillaume MASSEBOEUF for his contribution to this radar.</p>
<p> </p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2025/02/2025-cybersecurity-awareness-solutions-radar-how-can-i-find-the-right-solution-for-my-needs/">2025 cybersecurity awareness solutions radar: how can I find the right solution for my needs?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2025/02/2025-cybersecurity-awareness-solutions-radar-how-can-i-find-the-right-solution-for-my-needs/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>How to activate gamification for an impactful Cyber Month</title>
		<link>https://www.riskinsight-wavestone.com/en/2023/09/how-to-activate-gamification-for-an-impactful-cyber-month/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2023/09/how-to-activate-gamification-for-an-impactful-cyber-month/#respond</comments>
		
		<dc:creator><![CDATA[Noëmie Honoré]]></dc:creator>
		<pubDate>Fri, 22 Sep 2023 15:00:00 +0000</pubDate>
				<category><![CDATA[Cyberrisk Management & Strategy]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[gamification]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=21390</guid>

					<description><![CDATA[<p>Cyber Month is to cybersecurity awareness what the Olympics are to sports: the time to shine, with all eyes on you. Given that human-risk remains significant, with human error accounting for 82% of data breaches according to the 2022 Verizon...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2023/09/how-to-activate-gamification-for-an-impactful-cyber-month/">How to activate gamification for an impactful Cyber Month</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p style="text-align: justify;">Cyber Month is to cybersecurity awareness what the Olympics are to sports: the time to shine, with all eyes on you.</p>
<p style="text-align: justify;">Given that human-risk remains significant, with human error accounting for 82% of data breaches according to the <a href="https://www.verizon.com/business/resources/T1ed/reports/dbir/2022-data-breach-investigations-report-dbir.pdf">2022 Verizon Data Breach Investigations Report</a>, no wonder CISOs across European organizations are aiming for the most innovative and ground-breaking activities during this crucial time of the year.</p>
<p style="text-align: justify;">Once key risks have been identified, it&#8217;s go-time: spread priority secure behaviors throughout your organization using the ultimate medium: gamification.</p>
<h2> </h2>
<h2 style="text-align: justify;"><strong>Fail to play, fail the Cyber Month game</strong></h2>
<p style="text-align: justify;">From football matches to Monopoly fights, there is a game for everyone, and whichever your preference goes to, the chosen one will always elicit enthusiasm.</p>
<p style="text-align: justify;">It is then only logical that when meeting an opportunity to learn secure behaviors, employees will favor a game rather than an e-learning that they will have to &#8211; let&#8217;s face it &#8211; painfully sit through.</p>
<p style="text-align: justify;">Gamification is a winner, and although there are many reasons behind this fact, we have selected seven striking pieces of rationale that will shed a light on the benefits that gamification presents in a learning environment.</p>
<h6 style="text-align: justify;"><span style="color: #503078;"><strong>Gamification increases engagement dramatically</strong></span></h6>
<p style="text-align: justify;">To feel involved in an activity, and therefore reach the holy grail component of attention, <strong>interactivity</strong> is key.</p>
<p style="text-align: justify;">Games require action from the participant, which transforms the latter into a moving cog of their own learning process.</p>
<p style="text-align: justify;">Additionally, the element of <strong>competition</strong>, whether between teams or against a fictitious villain, present in games serves as a powerful motivator, further promoting engagement.</p>
<h6 style="text-align: justify;"><span style="color: #503078;"><strong>Practice beats theory in a learning context</strong></span></h6>
<p style="text-align: justify;">Practice accounts for <strong>70% of the learning process</strong>. Why so? Because practice allows to make the materials tangible and embed them into real-life situations, that employees can directly link to their everyday practices.</p>
<h6 style="text-align: justify;"><span style="color: #503078;"><strong>Feedback and rewards stimulate positive behaviors</strong></span></h6>
<p style="text-align: justify;">Games imply prizes and rewards to be earned. Not only does it contribute to foster motivation, but it also allows employees to access <strong>direct positive feedback</strong> about their actions and decisions, which comes with a sense of accomplishment and progress, further embedding the targeted secure behavior.</p>
<h6 style="text-align: justify;"><span style="color: #503078;"><strong>Games revamp the image of your cyber team</strong></span></h6>
<p style="text-align: justify;">Cyberawareness games have the power to shift the perception that staff hold of your cyber team. Indeed, cybersecurity may seem like an obscure and complex area for many employees.</p>
<p style="text-align: justify;">Offering games helps to make security concepts more<strong> tangible, accessible, and applicable into everyday life</strong>.</p>
<p style="text-align: justify;">Further, if they are held in-person, they allow your cyber team to gain <strong>visibility</strong> with end-users and bring a sense of <strong>recognition and trust</strong>, which in turn will boost the impact of future awareness actions.</p>
<h6 style="text-align: justify;"><span style="color: #503078;"><strong>Learning together increases team cohesion</strong></span></h6>
<p style="text-align: justify;">As if learning more effectively wasn&#8217;t enough, gamification also offers the valuable benefit of boosting <strong>team spirit</strong>.</p>
<p style="text-align: justify;">Many awareness games provide the opportunity to work collaboratively to attain success. This way, employees leave with fond memories and appreciation on top of precious security tips.</p>
<h6 style="text-align: justify;"><span style="color: #503078;"><strong>Games allow repetition of security messages in novel and fun ways</strong></span></h6>
<p style="text-align: justify;">When aiming to embed secure behaviors across an organization, repetition is crucial to ensure integration and implementation.</p>
<p style="text-align: justify;">However, repeating awareness communications through the same channels may decrease the attention that employees pay to them.</p>
<p style="text-align: justify;">Games constitute an innovative and enjoyable experience to<strong> reinforce security messages</strong>, making them <strong>stick over time</strong>.</p>
<h6 style="text-align: justify;"><span style="color: #503078;"><strong>Bonus: You collect valuable feedback and inputs from end-users</strong></span></h6>
<p style="text-align: justify;">By interacting with staff through awareness games, your cyber team gets the unique opportunity to collect information on the most urgent security questions that employees ask themselves and uncover which are their biggest challenges in terms of security in their daily activities. This feedback is then useful to <strong>prioritise future awareness messages</strong> and <strong>review or implement processes to facilitate employees&#8217; work life</strong>. For example, if staff repeatedly bring up the fact that they may see suspicious-looking emails but don&#8217;t know how to report them, this may lead to a special awareness campaign meant to remind employees of the way to report phishing emails, and the implementation of a phishing report button to facilitate the reporting process.</p>
<h2> </h2>
<h2 style="text-align: justify;"><strong>L</strong><strong>everaging gamification: The musts for organizing successful awareness games</strong></h2>
<p style="text-align: justify;">Prior to establishing the success factors of an awareness game, let&#8217;s pinpoint what makes a fruitful one.</p>
<p style="text-align: justify;">In order to prove truly effective, an awareness game should see its participants leave the activity with a clear idea of the security behaviors that they will change in their own office life.</p>
<p style="text-align: justify;">To achieve this goal, we have identified a set of <strong>five key criteria</strong>:</p>
<p style="text-align: justify;"><img loading="lazy" decoding="async" class="aligncenter wp-image-21392 " src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Image-article-gamification.png" alt="" width="492" height="350" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Image-article-gamification.png 2144w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Image-article-gamification-269x191.png 269w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Image-article-gamification-55x39.png 55w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Image-article-gamification-768x546.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Image-article-gamification-1536x1091.png 1536w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Image-article-gamification-2048x1455.png 2048w" sizes="auto, (max-width: 492px) 100vw, 492px" /></p>
<p style="text-align: justify;">A solid game will cover a<strong> priority awareness topic</strong>, based on the risks identified for the organization and ranked accordingly.</p>
<p style="text-align: justify;">Then, the right <strong>level of complexity</strong> must be found, based on the level of knowledge of your staff.</p>
<p style="text-align: justify;">Staff who already have a high level of maturity in terms of security behaviors will &#8211; at best &#8211; not learn anything new during an easy game, and &#8211; at worst &#8211; be bored or resentful towards the security awareness team for taking away some of their working time to cover elements they already know.</p>
<p style="text-align: justify;">The reverse scenario would also be problematic: confronting beginner staff with a difficult game would only leave them confused.</p>
<p style="text-align: justify;">Having an<strong> understanding of the level of security maturity of your target audience</strong> is therefore key to adapt the game for optimal results.</p>
<p style="text-align: justify;">Thirdly, the game must have at its center a <strong>compelling story</strong>. The scenario must be intriguing and should unfold seamlessly. Additionally, it should be adapted to the context of the organization so participants relate to the events happening in the game.</p>
<p style="text-align: justify;">To truly catch, and most importantly, retain employees&#8217; attention, the game will have a <strong>strong focus on interactivity</strong>. Interactions can happen between the game master(s) and the players, but also between players themselves when collaborating in the context of the activity.</p>
<p style="text-align: justify;">To further exploit this concept, the game may stimulate the 5 senses to render it even more engaging and immersive.</p>
<p style="text-align: justify;">The final key element to an effective game resides in providing a<strong> good incentive</strong>. Again, there are multiple ways to achieve this: you can for example establish a scoring system to foster playful competition between teams, and implement rewards. Rewards may come in the form of goodies, prizes such as individual or team experiences, or even donations to the charitable organization of the participants&#8217; choice. A solid incentive will boost voluntary participation to the activity, and a decision to participate that comes from the genuine willingness of staff will also be synonymous with higher motivation and involvement in the game for better retention of the shared secure behaviors.</p>
<h2> </h2>
<h2 style="text-align: justify;"><strong>Which awareness game is made for you?</strong></h2>
<p style="text-align: justify;">To make your Cyber Month gamification dreams come true, let&#8217;s jump from theory to practice!</p>
<p style="text-align: justify;">Take the quiz below to find out which cyberawareness game is tailored to your needs and objectives for <strong>maximal impact</strong>.</p>
<p style="text-align: justify;"><a href="https://take.quiz-maker.com/QCMG79JZ3" data-quiz="QCMG79JZ3" data-type="4">Loading&#8230;</a><script>(function(i,s,o,g,r,a,m){var ql=document.querySelectorAll('A[quiz],DIV[quiz],A[data-quiz],DIV[data-quiz]'); if(ql){if(ql.length){for(var k=0;k<ql.length;k++){ql[k].id='quiz-embed-'+k;ql[k].href="javascript:var i=document.getElementById('quiz-embed-"+k+"');try{qz.startQuiz(i)}catch(e){i.start=1;i.style.cursor='wait';i.style.opacity='0.5'};void(0);"}}};i['QP']=r;i[r]=i[r]||function(){(i[r].q=i[r].q||[]).push(arguments)},i[r].l=1*new Date();a=s.createElement(o),m=s.getElementsByTagName(o)[0];a.async=1;a.src=g;m.parentNode.insertBefore(a,m)})(window,document,'script','https://take.quiz-maker.com/3012/CDN/quiz-embed-v1.js','qp');</script></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2023/09/how-to-activate-gamification-for-an-impactful-cyber-month/">How to activate gamification for an impactful Cyber Month</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2023/09/how-to-activate-gamification-for-an-impactful-cyber-month/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Cracking the recipe: making employees hungry for more cyber awareness activities</title>
		<link>https://www.riskinsight-wavestone.com/en/2023/01/cracking-the-recipe-making-employees-hungry-for-more-cyber-awareness-activities/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2023/01/cracking-the-recipe-making-employees-hungry-for-more-cyber-awareness-activities/#respond</comments>
		
		<dc:creator><![CDATA[Thomas Vo-Dinh]]></dc:creator>
		<pubDate>Mon, 23 Jan 2023 09:00:00 +0000</pubDate>
				<category><![CDATA[Cyberrisk Management & Strategy]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[EscapeGame]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=19509</guid>

					<description><![CDATA[<p>Who would have known that locking your employees in a room for 15 minutes could become their new favorite way to learn about cybersecurity?  In a never-ending quest to find innovative ways to raise awareness on cybersecurity topics, the Wavestone team...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2023/01/cracking-the-recipe-making-employees-hungry-for-more-cyber-awareness-activities/">Cracking the recipe: making employees hungry for more cyber awareness activities</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="reader-text-block__paragraph" style="text-align: justify;">Who would have known that locking your employees in a room for 15 minutes could become their new favorite way to learn about cybersecurity? </p>
<p class="reader-text-block__paragraph" style="text-align: justify;">In a never-ending quest to find innovative ways to raise awareness on cybersecurity topics, the Wavestone team might have very well unearthed the new golden nugget.</p>
<p class="reader-text-block__paragraph" style="text-align: justify;">Tested and approved by hundreds of our clients&#8217; employees, <strong>read on to find out the secret recipe that makes cybersecurity best practices so easy to digest. </strong></p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-24559 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/image-1-1.png" alt="Cyber escape game as a secret recipe for maximizing awareness-raising efforts" width="1002" height="318" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/image-1-1.png 1002w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/image-1-1-437x139.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/image-1-1-71x23.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/image-1-1-768x244.png 768w" sizes="auto, (max-width: 1002px) 100vw, 1002px" /></p>
<div class="reader-image-block reader-image-block--full-width" style="text-align: justify;">
<figure class="reader-image-block__figure">
<div class="ivm-image-view-model   ">
<div class="ivm-view-attr__img-wrapper ivm-view-attr__img-wrapper--use-img-tag display-flex
    
    "> </div>
<div> </div>
<div class="ivm-view-attr__img-wrapper ivm-view-attr__img-wrapper--use-img-tag display-flex
    
    "><span style="font-size: revert; color: initial;">The concept, inspired by a beloved leisure activity, is </span><strong style="font-size: revert; color: initial;">simple, yet mightily potent. </strong></div>
</div>
</figure>
</div>
<p class="reader-text-block__paragraph" style="text-align: justify;">Employees are assembled into teams of four or five participants. </p>
<p class="reader-text-block__paragraph" style="text-align: justify;">The mission starts with a 10-minute briefing where they receive a lightning-fast training to become agents, and step into the shoes of hackers to perform their mission &#8211; should they accept it. </p>
<p class="reader-text-block__paragraph" style="text-align: justify;">They are then given 15 minutes to uncover as many confidential documents as they will find in their fictional target&#8217;s office. The game elaborately weaves in clues of varying difficulty level related to key security topics, including <strong>passwords, physical security, and social engineering</strong> to name a few. </p>
<p class="reader-text-block__paragraph" style="text-align: justify;">Finally, participants come out of their adventure eyes bright and laughing, enthusiastic to move on to a 15-minute debriefing, where best cybersecurity practices are explained. </p>
<p class="reader-text-block__paragraph" style="text-align: justify;">In the end, <strong>the activity mobilizes employees for a mere 40 minutes, which pass by in a flash, and leaves them motivated to implement concrete actions to protect their organization</strong>.</p>
<p><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-24561" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/image-2.png" alt="What sets the cyber game apart?" width="966" height="325" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/image-2.png 966w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/image-2-437x147.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/image-2-71x24.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/image-2-768x258.png 768w" sizes="auto, (max-width: 966px) 100vw, 966px" /></p>
<div class="reader-image-block reader-image-block--full-width" style="text-align: justify;">
<figure class="reader-image-block__figure">
<div class="ivm-image-view-model   ">
<h2 class="ivm-view-attr__img-wrapper ivm-view-attr__img-wrapper--use-img-tag display-flex
    
    "> </h2>
</div>
</figure>
</div>
<h2 class="reader-text-block__heading2" style="text-align: justify;">Gamification never disappoints  </h2>
<p class="reader-text-block__paragraph" style="text-align: justify;">Quite a few years might have passed since you and the members of your organization ran around your school&#8217;s playground, but one thing remains the same: <strong>games are still a unanimously popular way to learn. </strong></p>
<p class="reader-text-block__paragraph" style="text-align: justify;">Through gamification, <strong>people become actors, instead of spectators</strong>, of the learning process and embody the principles that you aim to instill in them. Keeping in mind that <strong>practice makes up 70% of the learning process</strong>, that is an opportunity that is hard to pass by.</p>
<p class="reader-text-block__paragraph" style="text-align: justify;">When adopting an active posture, participants get immersed in the activity, and they do not even realize that they are <strong>acquiring precious skills that will serve them and their organization&#8217;s security well for years to come. </strong></p>
<h2 class="reader-text-block__heading2" style="text-align: justify;">Spice it up with competition </h2>
<p class="reader-text-block__paragraph" style="text-align: justify;">What do football, chess, and Monopoly have in common? Besides the fact that they are all games, they also include an element of competition. </p>
<p class="reader-text-block__paragraph" style="text-align: justify;">In the context of a challenge, <strong>competition acts as a strong motivator and a driver to perform</strong>. Add a fun and safe environment to the mix, and you have yourself a perfect combination to tremendously boost engagement. </p>
<p class="reader-text-block__paragraph" style="text-align: justify;">Our cyber escape game includes a <strong>smart scoring system</strong>, so teams feel driven to reach the highest score, and you can gather information on overall performance. That&#8217;s what we call a win-win. </p>
<figure id="attachment_19496" aria-describedby="caption-attachment-19496" style="width: 872px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-19496" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Article-Escape-Game-Photo-1.png" alt="Example of scoring sheet for the cybersecurity escape game" width="872" height="637" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Article-Escape-Game-Photo-1.png 872w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Article-Escape-Game-Photo-1-261x191.png 261w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Article-Escape-Game-Photo-1-53x39.png 53w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Article-Escape-Game-Photo-1-768x561.png 768w" sizes="auto, (max-width: 872px) 100vw, 872px" /><figcaption id="caption-attachment-19496" class="wp-caption-text"><em>Example of scoring sheet</em></figcaption></figure>
<div class="reader-image-block reader-image-block--resize" style="text-align: center;">
<figure class="reader-image-block__figure">
<div class="ivm-image-view-model   ">
<div class="ivm-view-attr__img-wrapper ivm-view-attr__img-wrapper--use-img-tag display-flex
    
    "> </div>
</div>
<figcaption class="display-block mt2 full-width text-body-small-open t-sans text-align-center t-black--light"></figcaption>
</figure>
</div>
<h2 class="reader-text-block__heading2" style="text-align: justify;">The more the merrier </h2>
<p class="reader-text-block__paragraph" style="text-align: justify;">When faced with a puzzle to solve, who would be against a little bit of help? </p>
<p class="reader-text-block__paragraph" style="text-align: justify;">Indeed, completing an exercise on one&#8217;s own can be daunting, if not just plain lonely.  </p>
<p class="reader-text-block__paragraph" style="text-align: justify;">As part of a cyber escape game, people are encouraged to collaborate to solve clues. <strong>Teamwork then makes the challenge even more fun</strong> as creative ideas to break codes burst and are implemented, rendering their success all the more rewarding. </p>
<figure id="attachment_19498" aria-describedby="caption-attachment-19498" style="width: 1024px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-19498" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Article-Escape-Game-Photo-2.jpg" alt="Briefing session in Krakow" width="1024" height="768" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Article-Escape-Game-Photo-2.jpg 1024w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Article-Escape-Game-Photo-2-255x191.jpg 255w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Article-Escape-Game-Photo-2-52x39.jpg 52w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Article-Escape-Game-Photo-2-768x576.jpg 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Article-Escape-Game-Photo-2-600x450.jpg 600w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption id="caption-attachment-19498" class="wp-caption-text"><em>Briefing before the escape game</em></figcaption></figure>
<div class="reader-image-block reader-image-block--resize" style="text-align: center;">
<figure class="reader-image-block__figure">
<div class="ivm-image-view-model   ">
<div class="ivm-view-attr__img-wrapper ivm-view-attr__img-wrapper--use-img-tag display-flex
    
    "> </div>
</div>
<figcaption class="display-block mt2 full-width text-body-small-open t-sans text-align-center t-black--light"></figcaption>
</figure>
</div>
<h2 class="reader-text-block__heading2" style="text-align: justify;">Bring the human touch to learning experiences </h2>
<p class="reader-text-block__paragraph" style="text-align: justify;">To complement online training initiatives, providing staff with a way to <strong>engage in-person with cybersecurity experts</strong> allows to go the extra mile in accompanying them on their learning journey. </p>
<p class="reader-text-block__paragraph" style="text-align: justify;">Indeed, this format promotes live discussions and gives people the opportunity to receive personalized answers to their specific questions related to security.</p>
<p class="reader-text-block__paragraph" style="text-align: justify;">The result? Employees coming out of the activity with <strong>advice that precisely solves their pain points</strong>. </p>
<figure id="attachment_19500" aria-describedby="caption-attachment-19500" style="width: 1395px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-19500" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Article-Escape-Game-Photo-3.png" alt="Positive feedback from the cybersecurity escape game" width="1395" height="919" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Article-Escape-Game-Photo-3.png 1395w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Article-Escape-Game-Photo-3-290x191.png 290w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Article-Escape-Game-Photo-3-59x39.png 59w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Article-Escape-Game-Photo-3-768x506.png 768w" sizes="auto, (max-width: 1395px) 100vw, 1395px" /><figcaption id="caption-attachment-19500" class="wp-caption-text"><em>Feedback from participants of our latest session</em></figcaption></figure>
<div class="reader-image-block reader-image-block--resize" style="text-align: center;">
<figure class="reader-image-block__figure">
<div class="ivm-image-view-model   ">
<div class="ivm-view-attr__img-wrapper ivm-view-attr__img-wrapper--use-img-tag display-flex
    
    "> </div>
</div>
<figcaption class="display-block mt2 full-width text-body-small-open t-sans text-align-center t-black--light"><em><br /><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-24563" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/image-3.png" alt="Make it happen" width="1004" height="320" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/image-3.png 1004w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/image-3-437x139.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/image-3-71x23.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/image-3-768x245.png 768w" sizes="auto, (max-width: 1004px) 100vw, 1004px" /></em></figcaption>
</figure>
</div>
<p class="reader-text-block__paragraph" style="text-align: justify;">Not only is the format of the cyber escape game particularly appreciated by employees, it also presents multiple advantages for your organization in terms of implementation. </p>
<p class="reader-text-block__paragraph" style="text-align: justify;">Take it from the Wavestone team !</p>
<p class="reader-text-block__paragraph" style="text-align: justify;">Over the course of the month of October 2022, <a href="https://www.linkedin.com/company/wavestone/" data-entity-hovercard-id="urn:li:fs_miniCompany:10133" data-entity-type="MINI_COMPANY">Wavestone</a> Belgium carried out +100 cyber escape games sessions with +400 players across 6 countries.  </p>
<p class="reader-text-block__paragraph" style="text-align: justify;">As training sessions last 40 minutes each,<strong> up to 45 collaborators can be trained in one day</strong>, maximizing time-efficiency. </p>
<p class="reader-text-block__paragraph" style="text-align: justify;">Further, <strong>customization </strong>is at the core of our approach, with a debriefing that exposes concrete ways to <strong>apply the best security practices that are most crucial to your organization</strong>.</p>
<p class="reader-text-block__paragraph" style="text-align: justify;">Although we could keep on enumerating the benefits that a cyber escape game can bring to an entity&#8217;s security, a game is still worth a thousand words.</p>
<p class="reader-text-block__paragraph" style="text-align: justify;">Curious to understand how the cyber escape game leaves employees asking for another serving of awareness activities? <strong>Get in touch with our expert </strong><a href="https://www.linkedin.com/in/thomasvodinh?miniProfileUrn=urn%3Ali%3Afs_miniProfile%3AACoAABXDa2gB3uuIfNKDhMbmEedA2haY2hHz1UA" data-entity-hovercard-id="urn:li:fs_miniProfile:ACoAABXDa2gB3uuIfNKDhMbmEedA2haY2hHz1UA" data-entity-type="MINI_PROFILE">Thomas Vo Dinh</a><strong> to organize a free session.</strong></p>
<p class="reader-text-block__paragraph" style="text-align: justify;">See you on the other side, agent <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2023/01/cracking-the-recipe-making-employees-hungry-for-more-cyber-awareness-activities/">Cracking the recipe: making employees hungry for more cyber awareness activities</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2023/01/cracking-the-recipe-making-employees-hungry-for-more-cyber-awareness-activities/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Fake President Fraud: almost caught me out!</title>
		<link>https://www.riskinsight-wavestone.com/en/2022/01/fake-president-fraud-almost-caught-me-out/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2022/01/fake-president-fraud-almost-caught-me-out/#respond</comments>
		
		<dc:creator><![CDATA[Noëmie Honoré]]></dc:creator>
		<pubDate>Mon, 24 Jan 2022 09:00:00 +0000</pubDate>
				<category><![CDATA[Cyberrisk Management & Strategy]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[scam]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=17534</guid>

					<description><![CDATA[<p>I often talk about cybersecurity awareness: I share concepts and best practices, but today I&#8217;m writing from another point of view: that of the person who has been made aware! Yes, experts are not exempt from awareness initiatives&#8230; let me...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2022/01/fake-president-fraud-almost-caught-me-out/">Fake President Fraud: almost caught me out!</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p style="text-align: justify;">I often talk about cybersecurity awareness: I share concepts and best practices, but today I&#8217;m writing from another point of view: that of the person who has been made aware!</p>
<p style="text-align: justify;">Yes, experts are not exempt from awareness initiatives&#8230; let me tell you a story, I’m hoping that it will help you to get the message across to your organization.</p>
<p style="text-align: justify;">It all started on a Tuesday at 3:34 pm. I received a WhatsApp from my CEO (or that&#8217;s what I think at the time!). The message read:</p>
<blockquote>
<p style="text-align: justify;">&#8220;Hi Noémie, are you available? I need to talk with you about a confidential acquisition in Belgium. Pascal&#8221;.</p>
</blockquote>
<p style="text-align: justify;">I picked up the message 10 minutes later and replied that I could free up my time and have that call. In my head, I asked myself a few questions: an acquisition, but who could it be? at what stage of the discussions are they? our priority areas are the US and UK, so it would be a bigger firm?&#8230; In short, the stress level was rising but I wanted to know more. At this stage, nothing indicated the slightest hint of a fraud or scam and I didn’t see any particular risk. I was more intrigued by the opportunity&#8230;</p>
<p style="text-align: justify;"> 2 minutes after my message, the following answer appeared:</p>
<blockquote>
<p style="text-align: justify;">&#8220;No need, but I will need you to prepare a transfer quickly, I will send you the bank information in a few minutes. Thanks”</p>
</blockquote>
<p style="text-align: justify;">At that moment, it all clicked into place. One thing was clear: it was a trap! It was urgent that I did nothing <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
<p style="text-align: justify;">I then decided to investigate because something wasn’t right in this situation:</p>
<ul style="text-align: justify;">
<li>The phone number of the WhatsApp contact was not the one I have in my phonebook</li>
<li>The photo is indeed Pascal&#8217;s but it&#8217;s a common photo, so easy to get</li>
</ul>
<p style="text-align: justify;">I then sent 2 messages in parallel:</p>
<ul style="text-align: justify;">
<li>The first one to my CEO, to the number registered in my directory. I took a screenshot of the WhatsApp discussion and asked him &#8220;Hello Pascal, obviously it&#8217;s not you! Can you confirm?&#8221;</li>
<li>The second was to the mystery sender on WhatsApp: &#8220;Are you testing me?&#8221;</li>
</ul>
<p style="text-align: justify;">The response on WhatsApp soon arrived, &#8220;Well done!&#8221;, and a more comprehensive message then followed which clarified:</p>
<ul style="text-align: justify;">
<li>This was a campaign to raise awareness about Fake President Fraud.</li>
<li>That the cases are unfortunately frequent and that several attackers have tried to impersonate a member of the executive management, by SMS, social networks or email by simply changing a photo or name</li>
<li>What Fake President Fraud is and the objective of the attackers: to make you believe that they have a priority and confidential matter for you to deal with, such as an acquisition, which requires an urgent payment out of the normal processes.</li>
<li>Rules to follow in case of an attack, clues to thwart attacks, and the security contact to alert.</li>
</ul>
<p style="text-align: justify;">As you can see, this story has a happy ending. In the cold light of day, you might think that it is quite simple to thwart the attack, but unfortunately that is not always the case.   </p>
<p style="text-align: justify;">Beyond the example, it is the management of emotions that I want to emphasise. This exercise was well done and very credible; it first gave me confidence with an important request but without asking me to take any risky or suspicious actions. The importance of the request generated questions and a little stress &#8211; emotions I needed to master in order to keep my decisions and actions logical and reasonable. I am personally familiar with this subject; I know the theory, but I assure you that the real-life situation was very different! I now know that a flood of emotions appears (although they won&#8217;t be so new next time!), but I am reassured that my common sense allowed me to keep a level head and investigate without rushing. I thanked my CISO after the exercise &#8211; I understand the benefits of practice and this experience was a good test, especially for those experts who may feel safe as they know what to do (to be clear: I don’t put myself in that category!). It tested in a very realistic way whether they would know how to put the theory into practice and recognise the messages for what they were: a scam.</p>
<p style="text-align: justify;">Training your people, even the experts, allows them to be better, to be ready (although not necessarily to be perfect!), because the situation will no longer be new, and the emotions will not be unknown&#8230; To shine on the big day, preparation is an essential ingredient, and this is true for everyone!</p>
<p style="text-align: justify;"> </p>
<h1 style="text-align: justify;"><strong>Summary</strong></h1>
<p style="text-align: justify;">Some key elements of Fake President Fraud:</p>
<ul>
<li style="text-align: justify;">Confidence building (photo, tone of voice, choice of words, etc.) by the attacker or climate of authority</li>
<li style="text-align: justify;">Urgency, stress: emotions that create pressure and disturb lucidity</li>
<li style="text-align: justify;">Demand for unusual, abnormal actions to be carried out within a short period of time</li>
</ul>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2022/01/fake-president-fraud-almost-caught-me-out/">Fake President Fraud: almost caught me out!</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2022/01/fake-president-fraud-almost-caught-me-out/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Organise a cyber crisis exercise in a large company</title>
		<link>https://www.riskinsight-wavestone.com/en/2021/07/organise-a-cyber-crisis-exercise-in-a-large-company/</link>
		
		<dc:creator><![CDATA[Matthieu Garin]]></dc:creator>
		<pubDate>Thu, 08 Jul 2021 12:00:18 +0000</pubDate>
				<category><![CDATA[Cyberrisk Management & Strategy]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[COMEX]]></category>
		<category><![CDATA[crisis]]></category>
		<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[cyberawareness]]></category>
		<category><![CDATA[exercice]]></category>
		<category><![CDATA[management]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=13884</guid>

					<description><![CDATA[<p>Organising a cyber crisis exercise is not an easy task.&#160;From&#160;the preparation to the D-Day, a lot of&#160;unforeseen&#160;events&#160;can&#160;occur&#160;and the preparation&#160;teams&#160;need to remain a step ahead of the players. This article will break down the steps to a successful cyber crisis exercise...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2021/07/organise-a-cyber-crisis-exercise-in-a-large-company/">Organise a cyber crisis exercise in a large company</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p style="text-align: justify;"><i><span data-contrast="auto">Organising a cyber crisis exercise is not an easy task.&nbsp;From&nbsp;the preparation to the D-Day, a lot of&nbsp;unforeseen&nbsp;events&nbsp;can&nbsp;occur&nbsp;and the preparation&nbsp;teams&nbsp;need to remain a step ahead of the players. This article will break down the steps to a successful cyber crisis exercise in a large company.</span></i><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:120,&quot;335559740&quot;:264}">&nbsp;</span></p>
<h2></h2>
<h2 style="text-align: justify;"><strong>ORGANISING&nbsp;A CYBER CRISIS EXERCISE IN A LARGE COMPANY&nbsp;</strong></h2>
<p style="text-align: justify;"><span data-contrast="auto">There are many reasons to organise a Cyber crisis exercise: evaluating the integration of Cyber security in the crisis management system, improving interactions between the different teams, and testing the capacity of the security division to make itself understood by top management.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:120,&quot;335559740&quot;:240}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-contrast="auto">From a simple table-top process test to SOC/CERT training to a large-scale exercise involving dozens of crisis&nbsp;teams&nbsp;and months of preparation, the resources&nbsp;</span><span data-contrast="auto">allocated to a crisis simulation vary greatly</span><span data-contrast="auto">.&nbsp;This article focuses on&nbsp;the&nbsp;last category.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:120,&quot;335559740&quot;:240}">&nbsp;</span></p>
<h2></h2>
<h2><strong>WHAT’S A TYPICAL CRISIS EXERCISE?&nbsp;</strong></h2>
<p style="text-align: justify;"><span data-contrast="auto">Looking at the figures, some of the largest crisis exercises in France have consisted of one day of activity, 150 people mobilised, 10-12 crisis teams in several countries, 30 facilitators, 20 observers and more than 300 stimuli. Being able to make a success of such an event requires both a high level of preparation and a very solid facilitation team on the D-day.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:120,&quot;335559740&quot;:240}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-contrast="auto">One of the key issues found in these types of exercises is that there is only one take. It is therefore essential that ALL the actors take part in the game, and that the scenario involves all the participants. Preparation and facilitation are key in such exercises to make sure the time spent on the simulation is worthwhile. </span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:120,&quot;335559740&quot;:240}">&nbsp;</span></p>
<h2 aria-level="2"></h2>
<h2 style="text-align: justify;" aria-level="2"><strong>SIX MONTHS TO PREPARE</strong><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:80,&quot;335559739&quot;:0,&quot;335559740&quot;:240}">&nbsp;</span></h2>
<h4 aria-level="2"></h4>
<h3 style="text-align: justify;" aria-level="3"><strong>1/&nbsp;Selecting&nbsp;the attack scenario&nbsp;</strong></h3>
<p style="text-align: justify;"><span data-contrast="auto">The first months of work are always devoted to the attack scenario. Ransomware, targeted fraud, attacking suppliers… the choice of weapons is large. In ambitious exercises, it is not rare to combine several attacks in one crisis: smoke screen launched by the attackers, identification of a second group during the investigation, etc. Whatever the scenario chosen, the key is to be as precise as possible:</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:120,&quot;335559740&quot;:240}">&nbsp;</span></p>
<ul style="text-align: justify;">
<li data-leveltext="" data-font="Symbol" data-listid="2" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">What are the attackers’ motives?</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:120,&quot;335559740&quot;:240}">&nbsp;</span></li>
<li data-leveltext="" data-font="Symbol" data-listid="2" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">What path of attack did they take?</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:120,&quot;335559740&quot;:240}">&nbsp;</span></li>
<li data-leveltext="" data-font="Symbol" data-listid="2" aria-setsize="-1" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">When was the first intrusion?</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:120,&quot;335559740&quot;:240}">&nbsp;</span></li>
</ul>
<p style="text-align: justify;"><span data-contrast="auto">The exercise is long and preparation beforehand is needed, especially when 150 players investigate an attack for several hours. Spear-phishing, water holing, code compromise, privilege escalation: the vulnerabilities used by the fictitious attacker are not real, but they must be plausible and “validated” by technical accomplices throughout the preparation. Similarly, for business impacts, they should be reviewed with business specialists: the level of fraud at which the situation becomes critical, critical activities to be targeted as a priority, most sensitive customers, etc. The choice and involvement of accomplices are essential and they should be integrated into the coordination team on D-day. </span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:120,&quot;335559740&quot;:240}">&nbsp;</span></p>
<h3 style="text-align: justify;" aria-level="3"><strong>2/ Building&nbsp;the script of the exercise&nbsp;</strong></h3>
<p style="text-align: justify;"><span data-contrast="auto">The&nbsp;script consists in defining minute by minute the information that will be communicated to the players. The calibration of the exercise rhythm is a complex point.&nbsp;The temptation to impose&nbsp;a strict&nbsp;rhythm is great to “master” the scenario&nbsp;but&nbsp;attention needs to be&nbsp;given&nbsp;to leave enough space&nbsp;for reflection.&nbsp;</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:120,&quot;335559740&quot;:240}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-contrast="auto">The start of the exercise is another complex point: should&nbsp;the scenario&nbsp;start directly&nbsp;in&nbsp;a crisis situation&nbsp;or on&nbsp;an&nbsp;alert that will test the general mobilization process?&nbsp;Most often than not, the&nbsp;second option is chosen.&nbsp;That way, the&nbsp;technical teams (CERT, SOC, IT…)&nbsp;&nbsp;can be mobilised&nbsp;for the entire duration of the exercise.&nbsp;ExCom&nbsp;members should have their diary freed up during that day&nbsp;as well.&nbsp;</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:120,&quot;335559740&quot;:240}">&nbsp;</span></p>
<h3 style="text-align: justify;" aria-level="3"><strong>3/ Preparation of&nbsp;the stimuli&nbsp;</strong></h3>
<p style="text-align: justify;"><span data-contrast="auto">Technical reports, fake tweets, messages from worried customers, these are all useful stimuli for the players.&nbsp;</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:120,&quot;335559740&quot;:240}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-contrast="auto">Videos are often used to&nbsp;captivate.&nbsp;Indeed, nothing is more striking than a fake&nbsp;BBC&nbsp;report relaying the current attack (logo, board, etc.&nbsp;the more realistic the better).&nbsp;For more realism, videos&nbsp;of people “known” in the company (message from the CEO, interview of a factory boss,&nbsp;etc)&nbsp;can be used.&nbsp;</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:120,&quot;335559740&quot;:240}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-contrast="auto">The same goes for the technical side: the duration of the exercises often does not allow the players to carry out the technical investigations themselves, but they will ask a lot of the facilitators.&nbsp;Everything must be ready to avoid panic:&nbsp;Malware analysis reports, application log extracts, IP address lists, etc.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:120,&quot;335559740&quot;:240}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-contrast="auto">As mentioned in the introduction, the most ambitious exercises may require the creation of 300 stimuli to get through the day and remain credible&nbsp;–&nbsp;is represents a&nbsp;lot of work.</span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:120,&quot;335559740&quot;:240}">&nbsp;</span></p>
<h2 style="text-align: justify;" aria-level="2"><strong>D-DAY&nbsp;</strong></h2>
<p style="text-align: justify;"><span data-contrast="auto">On D-Day, early morning, a meeting is organised&nbsp;with all the animation team and observers for&nbsp;the&nbsp;final adjustments. A few hours later, the observers&nbsp;will&nbsp;go to their crisis cells and start the players’ briefing.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:120,&quot;335559740&quot;:240}">&nbsp;</span></p>
<h3 style="text-align: justify;" aria-level="3"><strong>1/ Starting on a good basis&nbsp;</strong></h3>
<p style="text-align: justify;"><span data-contrast="auto">For&nbsp;many players, this may be their first exercise. The briefing is&nbsp;therefore&nbsp;essential to avoid&nbsp;confusion between fictional and real-life events:&nbsp;</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:120,&quot;335559740&quot;:240}">&nbsp;</span></p>
<ul style="text-align: justify; list-style-type: circle;">
<li data-leveltext="%1." data-font="Times New Roman" data-listid="3" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Players call the police in the middle of the exercise</span></li>
</ul>
<ul style="text-align: justify; list-style-type: circle;">
<li data-leveltext="%1." data-font="Times New Roman" data-listid="3" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">The players contact a mailing list of 400 people without specifying that it is an exercise</span></li>
</ul>
<ul style="text-align: justify; list-style-type: circle;">
<li data-leveltext="%1." data-font="Times New Roman" data-listid="3" aria-setsize="-1" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Real customers be called to be reassured</span></li>
</ul>
<ul style="text-align: justify; list-style-type: circle;">
<li data-leveltext="%1." data-font="Times New Roman" data-listid="3" aria-setsize="-1" data-aria-posinset="4" data-aria-level="1"><span data-contrast="auto">A production site is neutralized “by prevention”</span></li>
</ul>
<p style="text-align: justify;"><span data-contrast="auto">To avoid such situations, it is essential to iron out the rules of the game during the briefing: the players must communicate with each other, but they must go through the facilitation unit to contact external stakeholders. Throughout the day, the facilitators and accomplices in each team find themselves in the shoes of a client, a technical expert, a CEO, or a regulator, according to the players’ requests. </span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:120,&quot;335559740&quot;:240}">&nbsp;</span></p>
<h3 style="text-align: justify;" aria-level="3"><strong>2/ Rely on an efficient facilitation team&nbsp;</strong></h3>
<p style="text-align: justify;"><span data-contrast="auto">The sequence of events depends on the efficiency of the animation cell. A successful exercise includes a lot of improvisation on the day. Stimuli may have to be readjusted according to the reactions of the players, the score is never fixed and the facilitation cell will be put to the test on the day of the exercise. The largest crisis exercises have particularly professional crisis management teams, including the head of the facilitators, PMO, technical manager, business manager, call management centre, etc. </span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:120,&quot;335559740&quot;:240}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-contrast="auto">We suggest not to take any risks on D-Day and to recreate teams that are used to working together and know each other. Doing so is the best way to gain time that will prevent the organisation team from going into crisis itself.</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:120,&quot;335559740&quot;:240}">&nbsp;</span></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2021/07/organise-a-cyber-crisis-exercise-in-a-large-company/">Organise a cyber crisis exercise in a large company</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Comment concevoir la sensibilisation du futur ?</title>
		<link>https://www.riskinsight-wavestone.com/en/2020/10/comment-concevoir-la-sensibilisation-du-futur/</link>
		
		<dc:creator><![CDATA[Margaux Nedelec]]></dc:creator>
		<pubDate>Tue, 27 Oct 2020 06:30:37 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[escape game]]></category>
		<category><![CDATA[formation en distanciel]]></category>
		<category><![CDATA[futur]]></category>
		<category><![CDATA[Outils]]></category>
		<category><![CDATA[sensibilisation]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=14394</guid>

					<description><![CDATA[<p>Après de nombreux rebondissements en cette année 2020, une chose est sûre : le futur n’attend pas. Aujourd’hui, l’enjeu majeur de la cybersécurité réside essentiellement dans la formation des collaborateurs. L’erreur humaine est impliquée dans plus de 90 % des incidents...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/10/comment-concevoir-la-sensibilisation-du-futur/">Comment concevoir la sensibilisation du futur ?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Après de nombreux rebondissements en cette année 2020, une chose est sûre : <strong>le futur n’attend pas</strong>.</p>
<p>Aujourd’hui, l’enjeu majeur de la <strong>cybersécurité</strong> réside essentiellement dans la <strong>formation</strong> des collaborateurs. <strong>L’erreur humaine est impliquée dans plus de 90 % des incidents de sécurité</strong> (clic sur un lien de phishing, consultation d’un site Web suspect, activation de virus ou autres menaces persistantes avancées).</p>
<p>Il devient urgent de trouver des moyens efficaces afin de former chaque collaborateur. Pour ce faire, le numérique reste le format idéal pour parvenir à sensibiliser rapidement le maximum de personnes au sein des entreprises.</p>
<p>Dès lors,<strong> quels outils</strong> <strong>peuvent être mis en place </strong>afin d’impliquer <strong>différents publics</strong>, dans cette période où la <strong>transformation</strong> <strong>digitale</strong> bouleverse les codes ?</p>
<p>&nbsp;</p>
<h2>Le rapport au distanciel</h2>
<p>Jusqu’à aujourd’hui, il était habituel de faire des actions de sensibilisation au travers d’interventions physiques. Mais au vu de la situation sanitaire, il devient <strong>très compliqué d’organiser des sessions en présentiel</strong>.</p>
<p>Les actions et jeux de sensibilisation utilisant des cartes ou des plateaux sont difficiles à virtualiser. En revanche, les <strong>Escape Games sont plutôt simples à développer sous format digital</strong>. Des outils comme <strong>Genially</strong> ou <strong>Bfast</strong> accélèrent la création de jeux en ligne grâce à leur facilité de prise en main. En quelques dizaines de jour, il devient possible de <strong>créer un jeu sur mesure</strong> en fonction des besoins de sensibilisation.</p>
<p>L’avantage du format numérique se trouve dans la <strong>simplicité à adapter/changer/mettre à jour</strong> les outils. Ainsi, les outils développés sous format numérique seront toujours à l’ordre du jour et même <strong>spécialement adaptés</strong> pour une occasion particulière.</p>
<p>&nbsp;</p>
<h2>Adapter les outils au public</h2>
<p>La clé pour plaire à tout le monde c’est de <strong>s’adapter à tout le monde.</strong></p>
<p>Il n’est pas possible de créer 1 seul outil qui conviendra à toutes les populations visées par votre campagne de sensibilisation. Le but est d’avoir <strong>plusieurs outils différents</strong> ou bien de pouvoir adapter facilement l’outil à chaque nouvelle population cible.</p>
<p>Si l’on reprend l’exemple de l’Escape Game, le format numérique permet de créer plusieurs jeux de <strong>différents niveaux</strong>. En gardant le même scénario, il est possible de modifier le nombre d’énigmes, d’ajouter des indices ou encore de rallonger le temps de jeu afin de <strong>l’adapter au degré de connaissance des joueurs</strong>. Le tout en quelques clics.</p>
<p>&nbsp;</p>
<h2>Le format numérique: une sensibilisation à moindre coût</h2>
<p>Les <strong>budgets affectés à la cybersécurité</strong> et à la sensibilisation des collaborateurs sont souvent <strong>trop faibles par rapport aux besoins</strong> des entreprises. Malgré tout, il existe des <strong>moyens de sensibiliser</strong> les collaborateurs à <strong>faible coût</strong>.</p>
<p>La <strong>transformation digitale</strong> s’opère aussi dans <strong>l’éducation</strong>. De nombreux sites et plateformes en ligne permettent de <strong>créer des présentations et jeux ludiques rapidement</strong>. Genially, une plateforme de création de contenu interactif, est un bon moyen de créer ce genre d’outil. Très <strong>facile</strong> à prendre en main, son utilisation <strong>ne nécessite aucun savoir-faire particulier</strong>.</p>
<p>Aujourd’hui, la <strong>création d’un escape game en ligne</strong> est réalisable en <strong>30 jours</strong> par <strong>un seul développeur</strong>. Ces 30 jours comprennent la phase de réflexion autour du scénario, le développement du jeu ainsi que les phases de test.</p>
<p>Un dernier avantage, et non des moindres, se trouve dans l’efficacité du jeu digital. Grâce à la version numérique de l’escape game, plus besoin d’animateur et de créneau pour chaque session. L’accès au jeu se fait par un lien, disponible à tout moment. Ainsi, former 1 ou 1000 collaborateurs revient au même prix.</p>
<p>&nbsp;</p>
<p>La <strong>sensibilisation du futur</strong> se joue essentiellement sur l’<strong>approche numérique</strong>. Avec un <strong>développement rapide</strong>, à <strong>faible</strong> <strong>coût</strong>, <strong>adaptable à tous les niveaux</strong> et <strong>faisable à</strong> <strong>distance</strong>, <strong>l’Escape Game digital</strong> sera bientôt le <strong>nouvel outil phare</strong> des campagnes de sensibilisation.</p>
<p>&nbsp;</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/10/comment-concevoir-la-sensibilisation-du-futur/">Comment concevoir la sensibilisation du futur ?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>How to design the awareness of the future?</title>
		<link>https://www.riskinsight-wavestone.com/en/2020/10/how-to-design-the-awareness-of-the-future/</link>
		
		<dc:creator><![CDATA[Margaux Nedelec]]></dc:creator>
		<pubDate>Tue, 27 Oct 2020 06:30:32 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[escape game]]></category>
		<category><![CDATA[future]]></category>
		<category><![CDATA[tools]]></category>
		<category><![CDATA[training]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=14404</guid>

					<description><![CDATA[<p>After many twists and turns in the year 2020, one thing is certain: the future does not wait. Today, the major challenge of cybersecurity lies essentially in the training of employees. Human error is involved in more than 90% of...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/10/how-to-design-the-awareness-of-the-future/">How to design the awareness of the future?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>After many twists and turns in the year 2020, one thing is certain: the <strong>future does not wait</strong>.</p>
<p>Today, the major challenge of <strong>cybersecurity</strong> lies essentially in the <strong>training</strong> of employees. <strong>Human error is involved in more than 90% of security incidents</strong> (clicking on a phishing link, visiting a suspicious website, activating viruses or other advanced persistent threats).</p>
<p>There is an urgent need to find effective ways to train every employee. To this end, digital remains the ideal format to quickly reach the maximum number of people within companies.</p>
<p>So <strong>what tools can be put in place</strong> to involve <strong>different audiences</strong> in this period when the <strong>digital transformation</strong> is shaking up codes?</p>
<p>&nbsp;</p>
<h2>The relationship to distance</h2>
<p>Until today, it was usual to raise awareness through physical interventions. But given the health situation, it is becoming <strong>very complicated to organise face-to-face sessions</strong>.</p>
<p>Awareness-raising actions and games using cards or boards are difficult to virtualise. On the other hand, <strong>Escape Games are rather simple to develop in digital format</strong>. Tools such as <strong>Genially</strong> or <strong>Bfast</strong> speed up the creation of online games thanks to their ease of use. In just a few dozen days, it becomes possible to <strong>create a game tailored to the needs of awareness</strong>.</p>
<p>The advantage of the digital format lies in the simplicity of adapting/changing/updating the tools. Thus, the tools developed in digital format will always be on the agenda and even specially adapted for a particular occasion.</p>
<p>&nbsp;</p>
<h2>Adapting the tools to the public</h2>
<p>The key to appealing to everyone is to <strong>adapt to everyone</strong>.</p>
<p>It is not possible to create 1 single tool that will suit all the populations targeted by your awareness campaign. The goal is to have <strong>several different tools</strong> or to be able to easily adapt the tool to each new target population.</p>
<p>If we take the example of the Escape Game, the digital format makes it possible to create several games at <strong>different levels</strong>. By keeping the same scenario, it is possible to modify the number of riddles, add clues or even extend the game time to <strong>adapt it to the level of knowledge of the players</strong>. All in just a few clicks.</p>
<p>&nbsp;</p>
<h2>The digital format: raising awareness at lower cost</h2>
<p><strong>Budgets allocated to cyber security</strong> and employee awareness are often <strong>too small in relation to the needs of companies</strong>. Nevertheless, there are <strong>ways to raise employee awareness at low cost</strong>.</p>
<p>The <strong>digital transformation</strong> is also taking place in <strong>education</strong>. Numerous websites and online platforms make it possible to <strong>create fun presentations and games quickly</strong>. Genially, an interactive content creation platform, is a good way to create this kind of tool. It is very <strong>easy</strong> to use and <strong>does not require any special know-how</strong>.</p>
<p>Today, the <strong>creation of an online escape game</strong> can be done in <strong>30 days</strong> by a <strong>single developer</strong>. These 30 days include the reflection phase around the scenario, the development of the game as well as the test phases.</p>
<p>Last but not least, a last but not least advantage is the efficiency of the digital game. Thanks to the digital version of the escape game, there is no need for a facilitator and a time slot for each session. Access to the game is via a link, available at all times. Thus, training 1 or 1000 employees costs the same.</p>
<p>&nbsp;</p>
<p>Raising <strong>awareness of the future</strong> is essentially based on the <strong>digital approach</strong>. With <strong>rapid development</strong>, <strong>low cost</strong>, <strong>adaptable to all levels</strong> and <strong>remotely feasible</strong>, the digital Escape Game will soon be the <strong>new flagship tool</strong> for awareness campaigns.</p>
<p>&nbsp;</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/10/how-to-design-the-awareness-of-the-future/">How to design the awareness of the future?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Creating a relationship of trust with the EXCOM: first step, raising awareness!</title>
		<link>https://www.riskinsight-wavestone.com/en/2020/07/creating-a-relationship-of-trust-with-the-excom-first-step-raising-awareness/</link>
		
		<dc:creator><![CDATA[Gérôme Billois]]></dc:creator>
		<pubDate>Fri, 17 Jul 2020 12:00:11 +0000</pubDate>
				<category><![CDATA[Cyberrisk Management & Strategy]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Sections]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[EXCOM]]></category>
		<category><![CDATA[How-to]]></category>
		<category><![CDATA[Maturity]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[Strategy]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=13916</guid>

					<description><![CDATA[<p>The cybersecurity topic requires involvement at all levels of the company, but also and above all with the executive committee! Obviously, management must be an example, but it will also decide on major investments and will know how to unlock...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/07/creating-a-relationship-of-trust-with-the-excom-first-step-raising-awareness/">Creating a relationship of trust with the EXCOM: first step, raising awareness!</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>The cybersecurity topic requires involvement at all levels of the company, but also and above all with the executive committee! Obviously, management must be an example, but it will also decide on major investments and will know how to unlock the most complex situations in the company. It is therefore a key issue for all cybersecurity managers to create a lasting relationship of trust with their EXCOM. But it is also a high-risk exercise, which requires a gradual approach and consistency in commitments.</p>
<p>After having made several dozen speeches to executive committees, audit committees and boards of directors, I wanted to share with you the essential steps for advancing the relationship over the long term. The first phase of this trip should make it possible to create an initial contact and raise the EXCOM&#8217;s awareness on cybersecurity issues. First step, awareness! The objective for these sessions is often to manage to attract attention so as to be able to trigger further reflection within the organization. Later on, we will see the following steps: presenting a balance sheet, obtaining a budget, monitoring the progress on the security level&#8230;</p>
<p>&nbsp;</p>
<h2>An essential prerequisite, knowing where you are starting from and who you are going to deal with</h2>
<p>This may seem like a cliché, but it is certainly the most important element before going to meet an executive committee or a board of directors. Thanks to its wide media coverage, cybersecurity is often already present in executives&#8217; minds. But their degree of digital literacy and their level of appetite for the topic can completely change the way the topic is raised. Will it be necessary to be very didactic (going so far as to re-explain the principle of data, applications, if any) or will it be necessary to immediately address complex points such as the latest attacks observed and their methodologies? You would be surprised to see the diversity of levels between companies, but also within the same EXCOM. And it is necessary to interest each of the stakeholders, at the cost of having comments that are not very helpful during the intervention.</p>
<p>It is therefore important to prepare this first meeting by talking with other members of the ECOM their deputies or with people familiar with this forum to determine the tone to be adopted and the level of the speech to be given. Obviously, the operating rules will also have to be known: is it common for questions to be asked as they arise? Can a member be questioned? Should subjects relating to the company be raised from the outset? Plan to clear the ground upstream! And even if there is no perfect recipe, I will give you below the elements I use most often to make these meetings useful and effective.</p>
<p>&nbsp;</p>
<h2>To start, draw the attention by revealing the behind-the-scenes of an attack&#8230;</h2>
<p>The topics quickly follow one another during the EXCOM. The directors think very, very quickly, so it is necessary to be concrete and to give food for thought and experience. The element that I find most effective consists in presenting a recent attack, published in the press or having affected the sector, and deciphering the stakes and the background: what is the timeframe? what motivation for the attackers? what weaknesses in the company? what is the reaction internally? publicly? with the authorities? This will have the effect of mentally projecting the directors concerned into their role as if they were going through the same thing. <a href="https://www.wavestone.com/app/uploads/2019/10/2019-Security-incident-response-benchmark-Wavestone.pdf">We at Wavestone are fortunate enough to frequently manage major cyber crises</a> and we use these elements, both as a benchmark but also by anonymizing them or in agreement with the victims, to give a very concrete meaning to our feedback.</p>
<p>&nbsp;</p>
<h2>Follow-up with a generalization about cybercrime</h2>
<p>An case is good to understand, but it doesn&#8217;t explain everything! After zooming in on a case, it is a question of generalizing it by explaining what are the mainsprings cybercriminality ways of proceeding. We then analyze the motivations of criminal groups, their organizations, but also and perhaps above all how they make money!</p>
<p>&nbsp;</p>
<figure id="post-13920 media-13920" class="align-none"><img loading="lazy" decoding="async" class="wp-image-13920 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/0-1-1.jpg" alt="" width="569" height="332" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/0-1-1.jpg 390w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/0-1-1-327x191.jpg 327w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/0-1-1-67x39.jpg 67w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/0-1-1-120x70.jpg 120w" sizes="auto, (max-width: 569px) 100vw, 569px" /></figure>
<p>&nbsp;</p>
<p>For an EXCOM to know that it is a DDoS attack or ransomware that has done damage is of little interest, it is especially important to show them that cybercriminal activities are profitable, even very profitable. We have calculated the ROI of several types of attacks and I can tell you that when you explain a 600% profitable attack like a ransomware, the eyes of the directors are wide open. We then highlight very concretely why their structure could be attacked and especially how much money the criminals would make. This often puts an end to the question &#8220;but why would we be targeted by an attack? We&#8217;re not known/we&#8217;re small/we don&#8217;t do anything strategic&#8221;.</p>
<p>&nbsp;</p>
<h2>Explain the company&#8217;s current situation in concrete terms</h2>
<p>This is the right time to present the company&#8217;s IT posture and its current organization in terms of security. It is then a question of presenting it simply, with clear and meaningful images: are you rather in an old-fashioned &#8220;fortress&#8221; model? Or have you already opened your doors as a result of the digital transformation and have you adopted a porch model where security is reinforced the further you go towards critical systems? This will help to make the situation more concrete.</p>
<p>After this phase of mobilization and explanation, comes naturally the phase of questioning by the members of the executive committee. &#8220;But then, where are we now, or are we facing this risk of a cyberattack? ». Faced with this question, either you are lucky enough <a href="https://www.riskinsight-wavestone.com/en/2020/06/how-to-effectively-evaluate-your-cybersecurity/">to have a detailed maturity assessment</a> and you can present it immediately, or you can bring in initial qualitative or even partial quantitative elements and explain that today you need to have more visibility. The elements that speak for themselves are the latest audit reports, the latest incidents, budgetary elements.</p>
<p>&nbsp;</p>
<figure id="post-13917 media-13917" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-13917 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/0-3.jpg" alt="" width="598" height="461" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/0-3.jpg 598w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/0-3-248x191.jpg 248w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/0-3-51x39.jpg 51w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/0-3-156x121.jpg 156w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/0-3-155x120.jpg 155w" sizes="auto, (max-width: 598px) 100vw, 598px" /></figure>
<p>&nbsp;</p>
<p>If it is difficult at the beginning of the process to talk about the budget and to compare oneself because of a lack of data, it is possible to use a simple and effective indicator, that of your staff dedicated to cybersecurity. We have a database on this point and we can quickly show a EXCOM where it is just by mobilizing its HR. It&#8217;s simple and effective to convince them!</p>
<p>&nbsp;</p>
<h2>Don&#8217;t leave emprty-handed</h2>
<p>The major risk of this awareness is that everything goes well but nothing moves. Indeed, you may have a positive message, &#8220;thank you and see you in a year for an update&#8221;, you will be happy but you will not have helped cybersecurity situation moving forward. It is then necessary to prepare the next step by indicating from this presentation the main points of weakness or strength felt and how you would like to evaluate them more precisely.</p>
<p>Indeed, the second step is often the realization of a dedicated maturity assessment in order to know how to position yourself! If at this point the meeting has taken place, the EXCOM, intrigued and interested in the topic, will want to know more and will give an agreement in principle. Beware that this may not be a budget directly, it will certainly refer you to the CIO or the Risk Director to get it, but with their agreement you will have a great lever to move on to the next step! See you on the next episode.</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/07/creating-a-relationship-of-trust-with-the-excom-first-step-raising-awareness/">Creating a relationship of trust with the EXCOM: first step, raising awareness!</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Is cybersecurity escape game the best way to raise awareness?</title>
		<link>https://www.riskinsight-wavestone.com/en/2020/07/is-cybersecurity-escape-game-the-best-way-to-raise-awareness/</link>
		
		<dc:creator><![CDATA[Sylvain Werdefroy]]></dc:creator>
		<pubDate>Wed, 15 Jul 2020 09:00:00 +0000</pubDate>
				<category><![CDATA[Cyberrisk Management & Strategy]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[escape game]]></category>
		<category><![CDATA[game]]></category>
		<category><![CDATA[users]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=13892</guid>

					<description><![CDATA[<p>Phishing, data leak, laptop or smartphone thefts, fake President… end-users are key actors in securing information systems. However, it is a difficult exercise to raise their awareness to security risk and to teach them good practices. Headache for CISOs, lack...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/07/is-cybersecurity-escape-game-the-best-way-to-raise-awareness/">Is cybersecurity escape game the best way to raise awareness?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Phishing, data leak, laptop or smartphone thefts, fake President… <strong>end-users are key actors in securing information systems.</strong></p>
<p>However, <strong>it is a difficult exercise to raise their awareness to security risk and to teach them good practices</strong>. Headache for CISOs, lack of interest or even state of tension from end-users interpreting security measures as restrictions. Ways to raise awareness on information security must evolve continuously.</p>
<p>Is an escape game the way to bring end-users and cybersecurity back together?</p>
<p>&nbsp;</p>
<h2>A fun approach to raise awareness among end-users</h2>
<p>Like any classic escape game, the game master welcomes players and introduces the game’s context and rules. They get into the game’s room where they have to reach their goals in a limited time.</p>
<p>During the game, the game master follows remotely the team progress and gives clues if the players encounter difficulties.</p>
<p>At the end, the game master performs a debriefing. He goes through the different bad security practices used by the team during the game and remind them the good security practices.</p>
<p>&nbsp;</p>
<figure id="post-13893 media-13893" class="align-none">
<figure id="post-13895 media-13895" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-13895 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-1-5.png" alt="" width="946" height="444" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-1-5.png 946w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-1-5-407x191.png 407w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-1-5-71x33.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-1-5-768x360.png 768w" sizes="auto, (max-width: 946px) 100vw, 946px" /></figure>
</figure>
<p>&nbsp;</p>
<p><strong> Goals to be reached during the game depends on the scenario</strong>. It can be:</p>
<ul>
<li>Someone pretending to apply for a job that will search the desk of the R&amp;D director of a competitor company to steal the design and technical details of a new product.</li>
<li>A hacker forcing people to steal classified documents and to do bank payments within their own company by threatening them to reveal private sensitive information.</li>
<li>Someone using the opportunity of an invitation at their CEO’s home to steal evidence of their involvement in misappropriation of funds.</li>
</ul>
<p>&nbsp;</p>
<h2>Which awareness areas are raised?</h2>
<p>An escape game enables<strong> to raise awareness</strong> on different topics:</p>
<p>&nbsp;</p>
<figure id="post-13897 media-13897" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-13897 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-2-5.png" alt="" width="950" height="481" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-2-5.png 950w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-2-5-377x191.png 377w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-2-5-71x36.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Image-2-5-768x389.png 768w" sizes="auto, (max-width: 950px) 100vw, 950px" /></figure>
<p>&nbsp;</p>
<p>Let us take as example the &#8220;Password&#8221; area. The game will expose players to bad practices they will have to leverage to reach their goals:</p>
<ul>
<li>Straightforward password based on personal information (first name, last name, birthdate…),</li>
<li>Passwords saved in Web browsers,</li>
<li>Same passwords used for personal and professional life,</li>
<li>Passwords written on a post-it.</li>
</ul>
<p>Players will <strong>exploit themselves vulnerabilities</strong> set-up in the game and will get a <strong>better understanding of associated risks than if they had to read a policy.</strong></p>
<p>Furthermore, the escape game will help them <strong>understand the part they have to play to avoid being unintentionally accomplice of a cyberattack.</strong> It means to have a cautious behavior like being discreet on social media, being careful when talking to someone new, having reflexes to identify phishing e-mail, shredding confidential papers, etc.</p>
<p>&nbsp;</p>
<h2 id="tw-target-text" class="tw-data-text tw-text-large XcVN5d tw-ta" dir="ltr" data-placeholder="Translation"><span lang="en">How to successfully build a cybersecurity escape game?</span></h2>
<p>First, define the <strong>overall scenario</strong>: goals to be reached, roles taken by players and location of the game.</p>
<p>Then, <strong>design secondary objectives and the series of actions</strong> that will allow the players to reach the main goals. Let us take an example: to reach the goal “steal the confidential document of a product’s design”, players will have to:</p>
<ul>
<li>Rebuild a document torn apart manually from the trash,</li>
<li>Use this document to find the answer of a secret question to reset a user password,</li>
<li>Leverage the account hacked to connect to a SharePoint to fetch the confidential document.</li>
</ul>
<p>A classic escape game is using clues / objects in unexpected hiding places. On the contrary, <strong>the idea of a cybersecurity escape game is to recreate real life circumstances that players will be able to reflect on their own working life.</strong></p>
<p>It is important <strong>to adjust the difficulty level according to the people targeted.</strong> Clues must be comprehensible to people with no IT expertise if the escape game is targeting a large group of coworkers. On the contrary, clues must be more complex if the target is IT people. Like, having them do easy SQL injections on an application to access confidential data. The approach to use the SQL injection can be provided through a Web app thanks to a bookmark saved in a Web browser.</p>
<p>Finally, once everything is designed and ready, test sessions are required to refine the game and adjust when the game master needs to give clues. It is important that players <strong>reach all goals to ensure they see all security awareness topics expected.</strong></p>
<p>&nbsp;</p>
<h2>A very effecient tool to be included in a global awareness strategy</h2>
<p>Role-playing provided by escape game enable <strong>great awareness and ensure a good assimilation of messages</strong>. Players spontaneously create links between life experience and ones encountered during the game which allows rich debriefings: multiple discussions and players are engaged in depth in the topic approached.</p>
<p>Escape game does not replace <strong>other methods of awareness campaigns</strong>. It must be part of a global strategy which alternate actions with strong impact (but costly) and other cheaper actions (but with less impact) to allow continuous awareness with a controlled budget.</p>
<p>Finally, <strong>cybersecurity escape game is also an excellent teambuilding tool!</strong></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/07/is-cybersecurity-escape-game-the-best-way-to-raise-awareness/">Is cybersecurity escape game the best way to raise awareness?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The creation of Wavestone’s new internal awareness program (2/2)</title>
		<link>https://www.riskinsight-wavestone.com/en/2020/06/the-creation-of-wavestones-new-internal-awareness-program-2-2/</link>
		
		<dc:creator><![CDATA[Timoléon Tilmant]]></dc:creator>
		<pubDate>Fri, 26 Jun 2020 09:00:26 +0000</pubDate>
				<category><![CDATA[Cyberrisk Management & Strategy]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Sections]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[cyberawareness]]></category>
		<category><![CDATA[DSI]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=13299</guid>

					<description><![CDATA[<p>Find the entire story about the creation of TRUST in my first article. &#160; A campaign launch is all well, but how do you keep it going over time? The creation of TRUST was not an end in itself, but...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/06/the-creation-of-wavestones-new-internal-awareness-program-2-2/">The creation of Wavestone’s new internal awareness program (2/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Find the entire story about the creation of TRUST in my <a href="https://www.riskinsight-wavestone.com/en/2020/06/the-creation-of-wavestones-new-internal-awareness-program-1-2/">first article.</a></p>
<p>&nbsp;</p>
<h2>A campaign launch is all well, but how do you keep it going over time?</h2>
<p>The creation of TRUST was not an end in itself, but a stepping-stone for the future.</p>
<p>At the start of the project, we immediately envisaged the annual pace of our two awareness plans.</p>
<p>Two, because we had to keep in mind that we were raising awareness for two distinct populations: newcomers and existing employees.</p>
<p>For newcomers, the solution is simple: plan the launch of all existing TRUST resources over one year to space out messages.</p>
<p>&nbsp;</p>
<figure id="post-13290 media-13290" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-13290 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-1-3.png" alt="" width="854" height="584" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-1-3.png 854w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-1-3-279x191.png 279w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-1-3-57x39.png 57w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-1-3-768x525.png 768w" sizes="auto, (max-width: 854px) 100vw, 854px" /></figure>
<p>&nbsp;</p>
<p>For all other employees, it&#8217;s more complex. How to get the messages across again without giving a feeling of déjà vu, fatigue or even an overdose?</p>
<p>We have therefore organized our awareness plan with 3 major initiatives spaced out over time.</p>
<p>&nbsp;</p>
<h2>A new monthly meeting: The Trust minute</h2>
<p>&nbsp;</p>
<figure id="post-13292 media-13292" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-13292 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-2-2.png" alt="" width="800" height="450" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-2-2.png 800w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-2-2-340x191.png 340w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-2-2-69x39.png 69w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-2-2-768x432.png 768w" sizes="auto, (max-width: 800px) 100vw, 800px" /></figure>
<p>&nbsp;</p>
<p>A one-minute film broadcasted on all our communication channels to present 5 different messages per month:</p>
<ol>
<li>An example of an anonymous user or client incident</li>
<li>A Trustee, our security tool presented in the previous article</li>
<li>A security indicator (e.g. the percentage of new recruits who have completed e-learning, the number of those leaving the firm detected downloading documents before they leave). Sharing these indicators helps raising awareness and demonstrates that controls have been lifted.</li>
<li>A daily tip given by our friend Sofia</li>
<li>A popularized cyber news story</li>
</ol>
<p><strong> </strong></p>
<figure id="post-13300 media-13300" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-13300 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-3-EN.png" alt="" width="1920" height="1080" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-3-EN.png 1920w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-3-EN-340x191.png 340w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-3-EN-69x39.png 69w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-3-EN-768x432.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-3-EN-1536x864.png 1536w" sizes="auto, (max-width: 1920px) 100vw, 1920px" /></figure>
<p>&nbsp;</p>
<h2>A new campaign of cybercoffee quizzes because it gets results</h2>
<p>Of course, we must reinvent it, change the quizzes (but not necessarily the themes) and change the prize? All of this is easy and requires little preparation. Admittedly, this period of lockdown slightly challenged our initial plan. But it has been an opportunity to be creative and to release, in partnership with my colleagues in the Cybersecurity &amp; Digital Trust practice, the new <a href="https://youtu.be/YneNQ0nts98">#TotalCyberAwakening video </a>series about lockdown.</p>
<p>&nbsp;</p>
<h2>An annual global event in October during Cyber Security Month</h2>
<p>In 2019, we organized a firm-wide competition on the theme of protecting personal digital information.</p>
<p>Every week, all employees received a question by email which they could answer directly via option buttons <em>(sending a multiple-choice approval via Power Automate)</em>. Depending on their answer, they received a second email with the answer and the various tips associated to be used on a personal basis.</p>
<p>Answering a question and getting a correct answer would help contributing to a Euro prize fund. More than €2,100 was donated to the ISSA association, an association which Wavestone has partnered with to promote cybersecurity among schools and children.</p>
<p>This first game, based entirely on voluntary participation, enabled us to reach more than a third of Wavestone&#8217;s employees.</p>
<p>&nbsp;</p>
<figure id="post-13302 media-13302" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-13302 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-4-EN.png" alt="" width="781" height="1352" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-4-EN.png 781w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-4-EN-110x191.png 110w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-4-EN-23x39.png 23w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-4-EN-768x1329.png 768w" sizes="auto, (max-width: 781px) 100vw, 781px" /></figure>
<p>&nbsp;</p>
<p>We are already preparing for next October&#8217;s initiative and this time we will go further with videos, games, meetings, quizzes under a global theme inspired by a famous TV series. What if this time, the new threat of Wavestone was the return of the White Walkers?</p>
<p>&nbsp;</p>
<h2>6 key elements to keep in mind</h2>
<p>To sum up, the key elements for creating a successful awareness program are as follows:</p>
<ol>
<li>Set achievable goals</li>
<li>Define a common thread (a theme, a brand) that will allow users to easily associate your messages with security</li>
<li>Define a short list of messages to be communicated and stick to it</li>
<li>Diversify the media and channels (posters, films, emails, e-learning, games) but always keep at least one event to meet the users</li>
<li>First use the tools already at your disposal (PowerPoint, emails, PowerAutomate) before acquiring new interesting solutions if needed, but not necessarily a priority to get started</li>
<li>Be creative and use humor to get your messages across (however, culture differences may have an impact in case of an international group)</li>
</ol>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/06/the-creation-of-wavestones-new-internal-awareness-program-2-2/">The creation of Wavestone’s new internal awareness program (2/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Récit de la création du nouveau programme de sensibilisation interne de Wavestone (2/2)</title>
		<link>https://www.riskinsight-wavestone.com/en/2020/06/programme-sensibilisation-interne-wavestone-2-2/</link>
		
		<dc:creator><![CDATA[Timoléon Tilmant]]></dc:creator>
		<pubDate>Fri, 26 Jun 2020 09:00:07 +0000</pubDate>
				<category><![CDATA[Cyberrisk Management & Strategy]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[cyberawareness]]></category>
		<category><![CDATA[DSI]]></category>
		<category><![CDATA[sensibilisation]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=13288</guid>

					<description><![CDATA[<p>Retrouver toute l&#8217;histoire de la création de TRUST dans mon premier article. &#160; Un lancement de campagne c’est bien, mais comment tenir dans la durée ? La création de TRUST n’a pas été une finalité, mais un tremplin pour la...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/06/programme-sensibilisation-interne-wavestone-2-2/">Récit de la création du nouveau programme de sensibilisation interne de Wavestone (2/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Retrouver toute l&#8217;histoire de la création de TRUST dans mon <a href="https://www.riskinsight-wavestone.com/en/2020/06/the-creation-of-wavestones-new-internal-awareness-program-1-2/">premier article.</a></p>
<p>&nbsp;</p>
<h2>Un lancement de campagne c’est bien, mais comment tenir dans la durée ?</h2>
<p>La création de TRUST n’a pas été une finalité, mais un tremplin pour la suite.</p>
<p>Au démarrage du projet, nous avions tout de suite imaginé quel serait le rythme annuel de nos 2 plans de sensibilisation.</p>
<p>Nous devions avoir en tête de gérer la sensibilisation de 2 populations distinctes : les nouveaux et les anciens collaborateurs.</p>
<p>Pour les nouveaux, la solution est simple : planifier le lancement de tous les supports TRUST existants sur une année pour espacer les messages.</p>
<p>&nbsp;</p>
<figure id="post-13289 media-13289" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-13289 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-1-3.png" alt="" width="854" height="584" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-1-3.png 854w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-1-3-279x191.png 279w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-1-3-57x39.png 57w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-1-3-768x525.png 768w" sizes="auto, (max-width: 854px) 100vw, 854px" /></figure>
<p>&nbsp;</p>
<p>Pour tous les autres collaborateurs, c’est plus complexe. Comment faire à nouveau passer les messages sans donner un sentiment de déjà vu, de lassitude, voire d’overdose ?</p>
<p>Nous avons donc organisé notre plan de sensibilisation avec 3 grandes actions espacées temporellement.</p>
<p>&nbsp;</p>
<h2>Un nouveau rendez-vous mensuel : The Trust minute</h2>
<p>&nbsp;</p>
<figure id="post-13291 media-13291" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-13291 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-2-2.png" alt="" width="800" height="450" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-2-2.png 800w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-2-2-340x191.png 340w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-2-2-69x39.png 69w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-2-2-768x432.png 768w" sizes="auto, (max-width: 800px) 100vw, 800px" /></figure>
<p>&nbsp;</p>
<p>Un film d’une minute diffusé sur tous nos canaux de communications pour présenter 5 messages différents par mois :</p>
<ol>
<li>Un exemple anonymisé d’incident utilisateur ou avec un client</li>
<li>Un Trustee, nos outils de sécurité présentés dans l&#8217;article précédent</li>
<li>Un indicateur de sécurité (ex : le pourcentage de nouveaux ayant réalisé le e-learning, le nombre de démissionnaires détectés à télécharger des documents avant leur départ). Le fait de partager ces indicateurs permet de sensibiliser sur la problématique et de démontrer l’existence des contrôles.</li>
<li>Une astuce du quotidien donnée par notre amie Sofia</li>
<li>Une actualité cyber vulgarisée</li>
</ol>
<p>&nbsp;</p>
<figure id="post-13295 media-13295" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-13295 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-3-1.png" alt="" width="800" height="450" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-3-1.png 800w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-3-1-340x191.png 340w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-3-1-69x39.png 69w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-3-1-768x432.png 768w" sizes="auto, (max-width: 800px) 100vw, 800px" /></figure>
<p>&nbsp;</p>
<h2>Une nouvelle campagne de cybercoffee quizz car le résultat est au rendez-vous.</h2>
<p>Evidemment, il faut se renouveler, changer les questionnaires (mais pas forcément les thèmes), changer le goodie, mais tout cela est facile et demande peu de préparation. Certes, je vous l’avoue, cette période de confinement a légèrement remis en cause notre plan initial. Cependant, cela a été l’occasion d’être imaginatif et de sortir, en partenariat avec mes collègues de la practice Cybersécurité &amp; Digital Trust, la nouvelle série en <a href="https://youtu.be/YneNQ0nts98">vidéo TotalCyberAwakening</a> sur le confinement.</p>
<p>&nbsp;</p>
<h2>Un évènement global annuel en octobre lors du mois de la cybersécurité.</h2>
<p>En 2019, nous avions organisé un jeu concours à l’échelle du cabinet sur le thème de la protection de la vie numérique personnelle.</p>
<p>Chaque semaine, tous les collaborateurs recevaient une question par mail à laquelle ils pouvaient répondre directement via des boutons de choix <em>(envoi d’une approbation à choix multiples via Power Automate)</em>. En fonction de leur réponse, ils recevaient un second email leur annonçant la réponse et différents conseils associés à utiliser à titre personnel.</p>
<p>La participation à une question et une bonne réponse alimentaient une cagnotte en euros. Plus de 2100€ ont ainsi été reversés à l’association ISSA à laquelle Wavestone s’est associée pour promouvoir la cybersécurité auprès des écoles et des enfants.</p>
<p>Ce premier jeu sur base de volontariat nous a permis d’atteindre plus d’un tiers des collaborateurs de Wavestone.</p>
<p>&nbsp;</p>
<figure id="post-13293 media-13293" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-13293 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-4.png" alt="" width="781" height="1352" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-4.png 781w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-4-110x191.png 110w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-4-23x39.png 23w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-4-768x1329.png 768w" sizes="auto, (max-width: 781px) 100vw, 781px" /></figure>
<figure id="post-13289 media-13289" class="align-none"></figure>
<p>&nbsp;</p>
<p>Nous sommes déjà en train de préparer celui d’octobre prochain et cette fois-ci nous irons plus loin, avec des vidéos, des jeux, des rencontres, des quizz sous un thème global inspiré d’une célèbre série TV. Et si cette fois-ci la nouvelle menace de Wavestone était le retour des marcheurs blancs ?</p>
<p>&nbsp;</p>
<h2>6 éléments clés à retenir</h2>
<p>Pour résumer, les éléments clés de succès pour la création d’un programme de sensibilisation réussi sont les suivants :</p>
<ol>
<li>Se fixer des objectifs chiffrables et atteignables</li>
<li>Définir un fil rouge (un thème, une marque) qui va permettre aux utilisateurs d’associer facilement vos messages à la sécurité</li>
<li>Définir une courte liste de messages à faire passer et s’y tenir</li>
<li>Diversifier les supports et les canaux (affiches, films, mails, e-learning, jeux) mais toujours conserver au moins un évènement permettant d’aller à la rencontre des utilisateurs</li>
<li>Utiliser dans un premier temps les outils déjà à votre disposition (PowerPoint, mails, PowerAutomate) avant d’acquérir si besoin de nouvelles solutions intéressantes mais pas forcément prioritaires pour démarrer</li>
<li>Faire preuve de créativité et utiliser l’humour pour faire passer vos messages (attention toutefois à prendre en compte les différences de culture dans le cadre d&#8217;un groupe international)</li>
</ol>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/06/programme-sensibilisation-interne-wavestone-2-2/">Récit de la création du nouveau programme de sensibilisation interne de Wavestone (2/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The creation of Wavestone’s new internal awareness program (1/2)</title>
		<link>https://www.riskinsight-wavestone.com/en/2020/06/the-creation-of-wavestones-new-internal-awareness-program-1-2/</link>
		
		<dc:creator><![CDATA[Timoléon Tilmant]]></dc:creator>
		<pubDate>Tue, 23 Jun 2020 09:00:43 +0000</pubDate>
				<category><![CDATA[Cyberrisk Management & Strategy]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[data protection]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=13272</guid>

					<description><![CDATA[<p>&#160; A year ago, the idea of TRUST was born, the name of the new awareness program at Wavestone. My team and I spent a year thinking about and developing a whole new strategy to raise awareness among Wavestone employees....</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/06/the-creation-of-wavestones-new-internal-awareness-program-1-2/">The creation of Wavestone’s new internal awareness program (1/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<figure id="post-13245 media-13245" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-13245 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-1.jpg" alt="" width="1161" height="452" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-1.jpg 1161w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-1-437x170.jpg 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-1-71x28.jpg 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-1-768x299.jpg 768w" sizes="auto, (max-width: 1161px) 100vw, 1161px" /></figure>
<p>&nbsp;</p>
<p>A year ago, the idea of TRUST was born, the name of the new awareness program at Wavestone. My team and I spent a year thinking about and developing a whole new strategy to raise awareness among Wavestone employees. Wavestone has 3,500 employees in 8 countries, whose main job is consulting (but not only!), rather young (but not only!), who know about IT and cybersecurity (but not only!).</p>
<p>This anniversary was an opportunity to reflect on the results and think about what we are going to do next. In view of the very positive feedback that I have received from our employees, I consider this program to be a success in terms of our objectives and I would therefore like to share it with you to explain how it is possible to build a program and develop materials without necessarily having an enormous budget. In a nutshell, awareness-raising is within the reach of every company, even the smallest.</p>
<p>&nbsp;</p>
<h2>It all starts with a review and objectives</h2>
<p>The assessment at the beginning of 2019 was simple: for several years, I had already developed various awareness-raising tools: a virtual character (Sofia), an e-learning module, phishing campaigns, a very stylish user charter (but I am not fooled by its actual read rate), videos, an Intranet page, awareness-raising emails, security tools available to users&#8230; but then <strong>why did our users always continue to act as if they didn&#8217;t know?</strong></p>
<p>At the same time, within the framework of the <strong>Wavestone 2021 strategic plan</strong> and its aim to position the firm in the top 3 of its category in terms of CSR, we have set ourselves the objective of being a trusted partner with 100% of our employees being aware of data protection issues.</p>
<p><strong>100%!</strong> At the beginning of 2019, I only had a 70% participation rate of employees in e-learning safety.</p>
<p>&nbsp;</p>
<figure id="post-13247 media-13247" class="align-none"></figure>
<figure id="post-13277 media-13277" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-13277 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-2-EN.png" alt="" width="591" height="560" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-2-EN.png 591w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-2-EN-202x191.png 202w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-2-EN-41x39.png 41w" sizes="auto, (max-width: 591px) 100vw, 591px" /></figure>
<p>&nbsp;</p>
<h2>But then how? What more could I do?</h2>
<p>After several group sessions and one or two sleepless nights, the ideas were there:</p>
<p>Our various actions were too diverse, <strong>a common thread was missing: a brand!</strong></p>
<p>A digital format is a good thing, but there is no substitute for a verbal discussion (we forget the traditional 2 hour face-to-face mandatory training for all newcomers, which is very time consuming and has a limited impact due to the large number of messages addressed in the 2 hours. I have led so many of them as a consultant).</p>
<p>We always talk about risk and threat, but employees need more practical examples that are well adapted to their company&#8217;s situation. What mistakes can they make on a daily basis and what would be the actual impact for Wavestone?</p>
<p>&#8220;Humor! We need humor!&#8221; Yes, but not always! Humor is a great tool to grab the attention of your target audience, to lure them in, to make them receptive to you&#8230; but what you really need is <strong>pragmatism!</strong></p>
<p>It is difficult for the employee to ultimately know what to do with the many rules given. In the end, a large part of data protection remains the mission of IT management, by implementing protection tools, alerts and controls. For example: <strong>is it up to users to be more vigilant against phishing or malicious emails?</strong> For my part, I think it&#8217;s more up to the company:</p>
<ol>
<li>to implement a better messaging protection solution,</li>
<li>a better EDR that will block the action of the faulty part,</li>
<li>to have solutions to avoid the spread of ransomware or data backups,</li>
<li>to have a multi-factor solution that will greatly reduce the use of stolen logins and passwords via a fake password reset email.</li>
</ol>
<p>It is more important to work on limiting the impact of a malicious email that will always find a willing victim, rather than focusing energy on educating users on this topic.</p>
<p>Based on this observation, what are the messages I wanted to convey? <strong>What is really in the control of the Wavestone employee, and not IT management?</strong></p>
<p>They can be summed up in 5 messages:</p>
<ol>
<li><strong>Transfer documents from your client ONLY WITH authorization:</strong>When you are a consulting firm whose employees spend so much time on your clients&#8217; IS, the primary risk is a lack of awareness and the loss of a client because your employees have taken out sensitive documents to make it easier for them to work on their workstations, or with their project manager who does not have access to the client&#8217;s IS (at least not yet, which can often happen with long processes for providing access to client’s IS). This is not a security risk as such for Wavestone, but rather a risk of a client incident that is dealt with through data protection awareness.</li>
<li><strong>Respect the project confidentiality procedure</strong>: the fundamentals! Comply with the instructions for handling client data. On the other hand, for it to be effective, this procedure must be very simple&#8230; no more than 2 or 3 rules.</li>
<li><strong>Use security tools to protect data</strong>: as long as they are easy to use! We&#8217;ll talk about this later.</li>
<li><strong>Store personal data only if necessary and process only for the intended purpose</strong>: you have to put a little GDPR message in the formula&#8230;</li>
<li><strong>Think twice before opening an attachment, clicking on the web link, and working in transport </strong><strong>and public places</strong>: &#8220;but you just told us it was the role of IT management!&#8221; Yes, sure, you&#8217;re right, but it doesn&#8217;t cost anything to add it at the end. Anyway, we always forget the last piece of advice!</li>
</ol>
<p>5 messages. Perhaps the more visual among you have noticed&#8230; but the first letter of each line combines to form…</p>
<p>&nbsp;</p>
<figure id="post-13249 media-13249" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-13249 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-3.png" alt="" width="1163" height="565" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-3.png 1163w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-3-393x191.png 393w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-3-71x34.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-3-768x373.png 768w" sizes="auto, (max-width: 1163px) 100vw, 1163px" /></p>
<figure id="post-13249 media-13249" class="align-none"></figure>
</figure>
<p>&nbsp;</p>
<p>And here&#8217;s the TRUST brand that was born, with its logo, design, style guide and visuals.</p>
<p>&nbsp;</p>
<h2>We have the brand! Like any good marketing product, it must now be broken down into multiple promotional formats.</h2>
<p>Once we had our central theme in terms of messages and visuals, all that remained was to communicate it, but not in a single action, in a series of actions linked to each other to simultaneously increase formats, channels and messages to different categories of users.</p>
<h3>Production of the TRUST video. 5-minute film in 3 parts:</h3>
<ol>
<li>An introduction to set the scene with fictional press or radio articles presenting the consequences for Wavestone of a security incident (loss of clients, loss of turnover, stock market decline, etc.).</li>
<li>5 messages: 5 humorous sketches including a Wavestone employee and a different CISO. What better than CISOs to play their own role? I was lucky that the CISOs of 2 CAC40 companies, a large French public company and a large English bank agreed to play the game in a humorous way. Many thanks again to them! Each consequence of the scene is then explained by the managing director of Wavestone, Mr Patrick HIRIGOYEN. Small video excerpt <a href="https://youtu.be/I3dbj1SHvgw">here</a>.</li>
</ol>
<ol start="3">
<li>Finally, a conclusion with a message from Mr. Pascal IMBERT, Chairman and Chief Executive Officer of Wavestone, as a more serious reminder of the risks involved for the firm and the need for each employee to feel committed and to apply the proposed measures.</li>
</ol>
<p>We received a very good feedback from the employees on this humorous film, which was widely distributed through all the firm&#8217;s communication channels.</p>
<p>The TRUST brand was quickly identifiable. But this film was just for the launch, it needs more!</p>
<h3>Creation of cybercoffee quizzes</h3>
<p>The principle is simple: answer at least 3 security questions and get a free coffee and 1 goodies (a TRUST webcam cover for this year).</p>
<p>An excellent opportunity to meet employees at a time when they are open to discussion: during their coffee break.</p>
<p>For this, you need visuals: kakemonos, polo shirts, screens with the awareness film and 1 coffee machine with free coffee. You can’t miss us!</p>
<p>&nbsp;</p>
<figure id="post-13251 media-13251" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-13251 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-4.jpg" alt="" width="658" height="878" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-4.jpg 658w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-4-143x191.jpg 143w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-4-29x39.jpg 29w" sizes="auto, (max-width: 658px) 100vw, 658px" /></figure>
<p>&nbsp;</p>
<p>Every fortnight, my team would go to a different break room in our offices to introduce TRUST, get the staff playing and answer their questions. This initiative was greatly appreciated by the employees. Beyond the lure of winning, they were delighted that we took the time to explain to them individually things they didn&#8217;t know or didn&#8217;t know well and all the simple things that were available to them. <strong>&#8220;It&#8217;s not as complicated as it sounds!”</strong></p>
<p>These quizzes, in the form of presentations at management meetings or team meetings in our various offices, enabled us to meet with more than <strong>1,000</strong> employees in person in 9 months, i.e. around 1/3 of our staff. Although time-consuming, this action remains one of the most impactful in terms of making ourselves known and getting our messages across.</p>
<p><em>Technical tip:</em> it&#8217;s very easy to implement in practice:</p>
<ul>
<li>3-question form, for us, made on Microsoft Forms,</li>
<li>QR code displayed on a kakemono or a poster so that from its phone, the participant can easily access this form (just take out the camera, no application to install)</li>
<li>Finally, a simple workflow (via Power Automate) to save the result in a database and automatically send a summary email to the participant with key messages and links to videos.</li>
</ul>
<p>The score and corrections being displayed directly on the phone after confirmation, the facilitator can directly discuss with the participant to explain their mistakes and offer them their gift.</p>
<h3>What if the security tools were superheroes?</h3>
<p>&#8220;Encrypt your document&#8221;, &#8220;Protect your passwords&#8221;, &#8220;Encrypt your emails&#8221;&#8230; so many instructions given to users who, despite their good intentions, often find themselves saying &#8220;I want to, but how can I do it?”</p>
<p>We had a whole catalog of tools installed on the workstations and were available for employees, which were simply unknown to everyone. So, we had to bring them out of the shadows and into the spotlight to show their existence and their usefulness. That&#8217;s how our League of Trustees was born!</p>
<p>&nbsp;</p>
<figure id="post-13279 media-13279" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-13279 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-5-EN.png" alt="" width="1012" height="571" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-5-EN.png 1012w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-5-EN-339x191.png 339w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-5-EN-69x39.png 69w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-5-EN-768x433.png 768w" sizes="auto, (max-width: 1012px) 100vw, 1012px" /></figure>
<p>&nbsp;</p>
<p>Each tool has its own superhero whose duty is to show our employees what they are used for and how easy it is to use them in less than 1 minute:</p>
<p>&#8220;I want to send a secure document to my client&#8221;: Encrypt it with 7zip!</p>
<p>&#8220;I want to protect the documents on my USB flash drive&#8221;: Encrypt it with BitlockerToGo, it&#8217;s on your computer!</p>
<p>Posters and short demonstration videos were used to communicate on our different channels and to present them during our Cybercoffee quizzes.</p>
<p>I wouldn&#8217;t say that they are now used every time, but at least they are better known and therefore are used more than they were before.</p>
<p>&nbsp;</p>
<figure id="post-13281 media-13281" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-13281 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-6-EN.png" alt="" width="497" height="722" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-6-EN.png 497w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-6-EN-131x191.png 131w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-6-EN-27x39.png 27w" sizes="auto, (max-width: 497px) 100vw, 497px" /></figure>
<p>&nbsp;</p>
<p><em>Technical tip:</em> did you know that you don&#8217;t need professional software and a 5-year degree in audiovisuals to make short animated films?</p>
<p>There are tools such as Powtoon or Vyond that allow you to make awareness videos very easily with a whole series of characters or settings already proposed. In 1 to 2 days you can already make your first one-minute video. Quickly, you will only need half a day of editing. The most complex part is always the script writing, the duration of this step can be very varied depending on the message you want to convey, your context or requirements (it&#8217;s this last point that personally takes me a lot of time!).</p>
<p>For simpler films, including video clips and text, personally, my new video editing tool has become Microsoft PowerPoint! You all already know how to use it to put text, animations and transitions. All you have to do now is use the video insertion, screen recording and video export functions. 3 features that make your life easier because usually you always have to find third party tools to record your screen, cut them and convert videos.</p>
<p>You can even save your films in GIF format to integrate them directly into your awareness emails! No need to redirect your user to a video site!</p>
<p>The ultimate advantage is that you can have your videos edited by other people and modified afterwards by others without training because most of your employees know how to use PowerPoint. Creativity becomes your only limit.</p>
<p>&nbsp;</p>
<h2>3 new materials, that&#8217;s it?</h2>
<p>As soon as our new materials were ready, we took the opportunity to bring our old awareness tools back to TRUST&#8217;s colours:</p>
<p>The e-learning for all new employees has been revamped with TRUST visuals by integrating the videos presented previously and refocusing the questions on our 5 messages. This more entertaining aspect enabled us to achieve our goal of having 100% of our new employees completing this e-learning programme by 2019. It is also thanks to good follow-up efforts and perseverance that this objective has been achieved! It&#8217;s not that easy getting 100%&#8230;</p>
<p>The Intranet page has also undergone a makeover to centralize all these resources and highlight the messages.</p>
<p>The security alerts for employees have also been rebranded under the TRUST brand. It should not be forgotten, but these alerts can be a great tool for raising awareness. Between the automatic email saying &#8220;We saw you, it&#8217;s not right, you&#8217;re going to be punished&#8221; and the prevention email sent by the awareness character explaining the right way to do things, the message gets across differently. And I strongly believe that it is more effective&#8230; the proof is in the observed decrease of these alerts since their implementation.</p>
<p>&nbsp;</p>
<figure id="post-13275 media-13275" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-13275 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-7-EN-1.png" alt="" width="1244" height="513" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-7-EN-1.png 1244w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-7-EN-1-437x180.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-7-EN-1-71x29.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/Image-7-EN-1-768x317.png 768w" sizes="auto, (max-width: 1244px) 100vw, 1244px" /></figure>
<p>&nbsp;</p>
<p><strong>End of the first article&#8230; how to keep it going and my conclusion soon to be published in part 2.</strong></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/06/the-creation-of-wavestones-new-internal-awareness-program-1-2/">The creation of Wavestone’s new internal awareness program (1/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Créer une relation de confiance avec son comité exécutif : première étape, la sensibilisation !</title>
		<link>https://www.riskinsight-wavestone.com/en/2020/06/creer-une-relation-de-confiance-avec-son-comite-executif-premiere-etape-la-sensibilisation/</link>
		
		<dc:creator><![CDATA[Gérôme Billois]]></dc:creator>
		<pubDate>Mon, 08 Jun 2020 11:00:06 +0000</pubDate>
				<category><![CDATA[Cyberrisk Management & Strategy]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[COMEX]]></category>
		<category><![CDATA[How-to]]></category>
		<category><![CDATA[maturité]]></category>
		<category><![CDATA[sensibilisation]]></category>
		<category><![CDATA[stratégie]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=13165</guid>

					<description><![CDATA[<p>Le sujet de la cybersécurité requiert une implication à tous les niveaux de l’entreprise, mais aussi et surtout avec le comité exécutif ! Evidemment le management doit montrer l’exemple mais c’est aussi ce comité qui va décider des investissements majeurs...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/06/creer-une-relation-de-confiance-avec-son-comite-executif-premiere-etape-la-sensibilisation/">Créer une relation de confiance avec son comité exécutif : première étape, la sensibilisation !</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p style="text-align: justify;">Le sujet de la cybersécurité requiert une implication à tous les niveaux de l’entreprise, mais aussi et surtout avec le comité exécutif ! Evidemment le management doit montrer l’exemple mais c’est aussi ce comité qui va décider des investissements majeurs et qui saura déverrouiller les situations les plus complexes dans l’entreprise. C’est donc un enjeu clé pour tous les responsables cybersécurité que de créer une relation de confiance pérenne avec son COMEX ! Mais c’est aussi un exercice à haut risque, qui nécessite une approche graduée et de la constance dans les engagements.</p>
<p style="text-align: justify;">Après avoir réalisé plusieurs dizaines d’interventions auprès de comité exécutif, de comités d’audit ou de conseil d’administration, je souhaitais partager avec vous les étapes essentielles pour faire progresser la relation dans la durée. La première phase de ce voyage devra permettre de créer un premier contact et à sensibiliser le comité exécutif aux enjeux de cybersécurité. Première étape, la sensibilisation ! L’objectif pour ces séances est souvent d’arriver à attirer l’attention pour pouvoir déclencher une réflexion plus approfondie dans l’organisation. Nous verrons plus tard les étapes suivantes : présenter un bilan, obtenir un budget, suivre la progression du niveau de sécurité…</p>
<p>&nbsp;</p>
<h2 style="text-align: justify;">Un pré-requis essentiel, savoir d’où l’on part et avec qui l&#8217;on va échanger !</h2>
<p style="text-align: justify;">Cela peut apparaitre comme un poncif, mais cet élément est certainement le plus important avant d’aller rencontrer un comité exécutif ou un conseil d’administration. Grâce à sa large couverture médiatique, le sujet de la cybersécurité est souvent déjà présent dans l’esprit des exécutifs. Mais leur degré de connaissance du numérique et leur niveau d’appétence pour le sujet peuvent changer complètement la manière d’aborder le sujet. Faudra-t-il être très didactique (en allant jusqu’à réexpliquer le principe de données, d’applications, si si) ou alors faudra-t-il tout de suite aborder des points complexes comme les dernières attaques observées et leurs méthodologies ? Vous seriez surpris de voir la diversité des niveaux entre les entreprises, mais aussi au sein d’un même COMEX. Et il est nécessaire d’intéresser chacun des acteurs, au prix d’avoir des commentaires peu amènes pendant l’intervention.</p>
<p style="text-align: justify;">Il s’agit donc de bien préparer cette première réunion en échangeant avec d’autres membres du COMEX, leurs adjoints ou avec des personnes familières de cette enceinte pour déterminer le ton à adopter et le niveau du discours à tenir. Evidemment, les règles de fonctionnement devront aussi être connues : est-il courant que les questions soient posées au fil de l’eau ? Peut-on interpeller un membre ? Doit-on évoquer dès le début les sujets relatifs à l’entreprise ? Prévoyez de déminer le terrain en amont ! Et même s’il n’y a pas de recette parfaite, je vous livre ci-dessous les éléments que j’utilise le plus souvent pour faire de ces rencontres des moments utiles et efficaces.</p>
<p>&nbsp;</p>
<h2 style="text-align: justify;">Pour commencer, attirer l’attention en dévoilant les coulisses d’une attaque</h2>
<p style="text-align: justify;">Les sujets s’enchaînent rapidement durant les COMEX, les directeurs réfléchissent très très vite, il faut donc très rapidement être dans le concret et donner de la matière à réflexion, du vécu. L’élément que je trouve le plus efficace consiste à présenter une attaque récente, parue dans la presse ou ayant touché le secteur, et en décrypter les enjeux et les coulisses : quelle temporalité ? quelle motivation pour les attaquants ? quelles faiblesses dans l’entreprise ? quelle réaction en interne ? publique ? avec les autorités ? Cela aura pour effet de projeter mentalement les directeurs concernés dans leur rôle s’ils vivaient la même chose. Nous avons la chance <a href="https://www.wavestone.com/app/uploads/2019/10/2019-Security-incident-response-benchmark-Wavestone.pdf" target="_blank" rel="nofollow noopener noreferrer">chez Wavestone de gérer fréquemment des grandes crises cyber et nous utilisons ces éléments</a>, à la fois sous forme de benchmark mais aussi en les anonymisant ou en accord avec les victimes, pour donner un sens très concret à nos retours d’expérience.</p>
<p>&nbsp;</p>
<h2 style="text-align: justify;">Enchaîner avec une généralisation sur la cybercriminalité</h2>
<p style="text-align: justify;">Une attaque, c’est bien mais ça n’explique pas tout ! Il s’agit après avoir zoomé sur un cas de le généraliser en expliquant quels sont les ressorts du fonctionnement de la cybercriminalité. Nous analysons alors les motivations des groupes criminels, leurs organisations, mais aussi et peut être surtout comment ils gagent de l’argent !</p>
<div class="slate-resizable-image-embed slate-image-embed__resize-left" style="text-align: justify;">
<figure id="post-14710 media-14710" class="align-none"><img loading="lazy" decoding="async" class="size-medium wp-image-14710 alignleft" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/0-3-327x191.jpg" alt="" width="327" height="191" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/0-3-327x191.jpg 327w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/0-3-67x39.jpg 67w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/0-3-120x70.jpg 120w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/0-3.jpg 390w" sizes="auto, (max-width: 327px) 100vw, 327px" /></figure>
</div>
<div></div>
<div style="text-align: justify;">Pour un COMEX savoir que c’est une attaque DDoS ou un ransomware qui a fait des dégâts n’a que peu d’intérêt, il faut surtout leur montrer que les activités cybercriminelles sont rentables, voire très rentables. Nous avons calculé le ROI de plusieurs types d’attaques et je peux vous dire que quand vous expliquez une attaque à 600% de rentabilité comme un ransomware, les yeux des directeurs sont grands ouverts. Nous mettons alors en lumière très concrètement pourquoi leur structure pourrait être attaquée et surtout quelle quantité d’argent gagnerait les criminels. Cela met souvent un terme à la question « mais pourquoi serions-nous visés par une attaque ? Nous ne sommes pas connus/nous sommes petits/nous ne faisons rien de stratégique…».</div>
<div></div>
<div style="text-align: justify;">
<h2>Expliquer concrètement où en est l’entreprise</h2>
<p>C’est le bon moment pour présenter la posture IT de l’entreprise et son organisation actuelle en terme de sécurité. Il s’agit alors de la présenter simplement, avec des images claires et parlantes : <a href="https://www.riskinsight-wavestone.com/en/2016/05/levolution-modele-de-securite-chateau-fort-a-laeroport/" target="_blank" rel="nofollow noopener noreferrer">êtes-vous plutôt dans un modèle « château fort » à l’ancienne</a> ? Ou avez-vous déjà ouvert vos portes suite à la transformation numérique et avez-vous adopter un modèle porche de l’aéroport ou la sécurité est renforcée plus on va vers des systèmes critiques ? Cela permettra de concrétiser la situation.</p>
<p>Après cette phase de mobilisation et d’explication, vient naturellement la phase d’interrogation par les membres du comité exécutif. « Mais alors nous, nous en sommes ou face à ce risque de cyberattaque ? ». Face à cette question, soit vous avez la chance d’avoir <a href="https://www.riskinsight-wavestone.com/en/2020/06/how-to-effectively-evaluate-your-cybersecurity/" target="_blank" rel="nofollow noopener noreferrer">un bilan de maturité fin et vous pouvez tout de suite le présenter</a>, soit vous pouvez amener des premiers éléments qualitatifs voire quantitatifs partiels et expliquer qu’aujourd’hui vous avez besoin d’avoir plus de visibilité. Les éléments qui parlent sont les derniers rapports d’audits, les derniers incidents, des éléments budgétaires.</p>
<p>&nbsp;</p>
<figure id="post-14712 media-14712" class="align-none"><img loading="lazy" decoding="async" class="size-medium wp-image-14712 alignright" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/0-4-248x191.jpg" alt="" width="248" height="191" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/0-4-248x191.jpg 248w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/0-4-51x39.jpg 51w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/0-4-156x121.jpg 156w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/0-4-155x120.jpg 155w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/06/0-4.jpg 598w" sizes="auto, (max-width: 248px) 100vw, 248px" /></figure>
</div>
<p style="text-align: justify;">S’il est difficile au début de la démarche de parler budget et de se comparer car les données manquent, il est possible d’utiliser un indicateur simple et efficace, celui de vos effectifs dédiés à la cybersécurité. Nous disposons d’une base de données sur ce point et nous pouvons rapidement montrer à un COMEX où il en est rien que par sa mobilisation sur le plan RH. C’est simple et efficace pour les convaincre !</p>
<p>&nbsp;</p>
<h2 style="text-align: justify;">Ne pas repartir bredouille</h2>
<p style="text-align: justify;">Le risque majeur de cette sensibilisation, c’est que tout se passe bien mais que rien ne bouge ! En effet, vous pouvez avoir un message positif, « merci et rendez-vous dans un an pour une mise à jour », vous serez content mais vous n’aurez pas débloqué pour autant la situation. Il faut alors bien préparer l’étape d’après en indiquant dès cette présentation les principaux points de faiblesses ou de force ressenti et de quelle manière vous souhaiteriez les évaluer de manière plus précise.</p>
<p style="text-align: justify;">En effet la deuxième étape est souvent la réalisation d’un bilan de maturité dédié pour bien savoir comment se positionner ! Si à ce moment, la réunion s’est déroulé, le COMEX intrigué et intéressé par le sujet voudra en savoir plus et donnera un accord de principe. Attention cela ne sera peut-être pas directement un budget, il vous renverra certainement vers le DSI ou le directeur des risques pour l’obtenir, mais vous aurez avec leur accord un levier formidable pour passer à l’étape d’après ! Rendez-vous au prochain épisode.</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/06/creer-une-relation-de-confiance-avec-son-comite-executif-premiere-etape-la-sensibilisation/">Créer une relation de confiance avec son comité exécutif : première étape, la sensibilisation !</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Prévention des risques cyber : sensibiliser les plus jeunes par le jeu !</title>
		<link>https://www.riskinsight-wavestone.com/en/2019/09/prevention-des-risques-cyber-sensibiliser-les-plus-jeunes-par-le-jeu/</link>
		
		<dc:creator><![CDATA[3tienneC@pgras]]></dc:creator>
		<pubDate>Mon, 09 Sep 2019 11:59:29 +0000</pubDate>
				<category><![CDATA[Cyberrisk Management & Strategy]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[cyberawareness]]></category>
		<category><![CDATA[Risque]]></category>
		<category><![CDATA[sensibilisation]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=12071</guid>

					<description><![CDATA[<p>Un sondage IFOP*, publié en début d’année 2019, révélait que 22% des jeunes avaient déjà fait les frais de « cyber harcèlement » et, selon l&#8217;association e-enfance, qui gère le numéro Net Écoute, 2 à 3 enfants par classe seraient...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2019/09/prevention-des-risques-cyber-sensibiliser-les-plus-jeunes-par-le-jeu/">Prévention des risques cyber : sensibiliser les plus jeunes par le jeu !</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Un sondage IFOP*, publié en début d’année 2019, révélait que 22% des jeunes avaient déjà fait les frais de « cyber harcèlement » et, selon l&#8217;association e-enfance, qui gère le numéro Net Écoute, 2 à 3 enfants par classe seraient concernés… Des chiffres alarmants qui s’inscrivent plus largement dans les nouvelles menaces présentes sur Internet : chantage en ligne, challenges tels que le « blue whale challenge » ou le « momo challenge », prédateurs sur internet, contenu inadapté, usurpation d’identité, etc. Autant de dangers virtuels qui ont des conséquences bien réelles et parfois dramatiques.</p>
<p><strong>La prévention des risques cyber auprès des plus jeunes, mais aussi des parents, </strong><strong>est</strong><strong> un véritable enjeu de société.</strong> C’est pour apporter une <strong>nouvelle solution de sensibilisation et d’accompagnement</strong> que le Centre de la Cybersécurité pour les Jeunes (CCJ) et le cabinet de conseil Wavestone – avec la contribution de Cybermalveillance.gouv.fr – lancent le kit de jeu &#8220;1,2,3 CYBER!&#8221;, une initiative ludique et participative.</p>
<h1>Une approche ludique pour sensibiliser les plus jeunes aux dangers du net</h1>
<p>Face au constat de l’exposition croissante des plus jeunes aux multiples visages de la menace cyber, l’association « Centre de la Cybersécurité pour les Jeunes » (CCJ) s’est rapprochée du cabinet de conseil Wavestone au début de l’année 2019. L’objectif : relever le défi de la création d’un jeu destiné à <strong>sensibiliser les 11-14 ans aux dangers du net tout en s’amusant</strong>, mais également <strong>outiller les éducateurs et les parents </strong>pour un accompagnement adapté à cette tranche d’âge. De cette collaboration est né le jeu « 1, 2, 3 Cyber ! ».</p>
<figure id="post-12073 media-12073" class="align-center"><img loading="lazy" decoding="async" class="aligncenter wp-image-12073 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/Image-1-1.png" alt="1,2,3 CYBER - un jeu pour sensibiliser les plus jeunes à la cybersécurité" width="841" height="632" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/Image-1-1.png 841w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/Image-1-1-254x191.png 254w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/Image-1-1-768x577.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/Image-1-1-52x39.png 52w" sizes="auto, (max-width: 841px) 100vw, 841px" /></figure>
<p style="text-align: center;"><em>1,2,3 CYBER &#8211; un jeu de sensibilisation des plus jeunes au risque cyber</em></p>
<p>Le jeu de société met en avant <strong>35 thématiques clés</strong> telles que le cyberharcèlement, l’ami virtuel, la vie privée, le hameçonnage, les mots de passe, le signalement, le chantage, le challenge, la cellule d’écoute, sans oublier les <em>fake news</em>…. Une session, qui peut compter de 6 à 12 joueurs, dure environ 1h15 (l’introduction, le temps de jeu et le bilan).</p>
<p>Le jeu est inspiré du Time&#8217;s Up, souvent connu et apprécié par la population visée, et se déroule en trois manches. Le but étant, à chacune de ces manches, de faire deviner un maximum de mots inscrits sur les cartes mises à disposition.</p>
<ul>
<li>Lors de la première manche, les joueurs doivent<strong> user de leur voix</strong> pour faire deviner les mots inscrits sur la carte. Si le jeu est trop simple et que les joueurs sont particulièrement sachants en la matière, il est possible d&#8217;apporter une complication : trois mots sont inscrits sur la carte qu&#8217;il ne faut pas prononcer, et ce sous peine de pénalité.</li>
<li>Lors de la deuxième manche, les joueurs doivent faire deviner les mots grâce <strong>au dessin.</strong> Pour cela, il vous est conseillé de vous munir d&#8217;ardoises / feutres véledas.</li>
<li>Enfin lors de la troisième manche, les joueurs ne <strong>peuvent prononcer qu&#8217;un mot</strong> afin de faire deviner celui inscrit sur la carte.</li>
</ul>
<p>Les mêmes cartes sont utilisées pour les trois parties, et le niveau de difficulté est croissant pour assurer <strong>la bonne appropriation des termes par tous les participants.</strong> En déroulant le jeu, il est possible que les participants rencontrent des difficultés pour faire deviner certains mots. C&#8217;est notamment le cas de hameçonnage, vie privée, etc. Pas de panique pour autant, la difficulté permet de s&#8217;imprégner davantage de leur signification et les jeunes trouvent toujours un moyen de s&#8217;en défaire (rébus, devinette, etc.).</p>
<p><strong>L’animateur joue un rôle clé dans ce jeu</strong> : à la fin de chaque manche, celui-ci doit déboucher sur un moment d’échange sur plusieurs mots. Il devra ainsi faciliter les échanges avec et entre les joueurs, orienter les discussions pour en déduire les bonnes pratiques à adopter sur Internet. Pour ce faire, un livret est mis à sa disposition. Il contient les règles du jeu détaillées ainsi qu’un guide leur permettant de rebondir sur certains termes clés et les bonnes pratiques qui devront être partagées.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #dbdbdb;">
<tbody>
<tr>
<td style="width: 100%;"><strong>Une synthèse des bons comportements à partager aux joueurs<br />
</strong></p>
<ul>
<li style="text-align: left;">En cas de doute sur les intentions d’un message reçu, le plus simple est de ne pas donner suite. Si ce doute arrive dans un second temps, il n’est jamais trop tard : parlez-en autour de vous à des personnes de confiance. Selon les cas, un signalement sur le site <a href="http://www.internet-signalement.gouv.fr">internet-signalement.gouv.fr</a>peut être fait et de l&#8217;aide peut être apportée via le site <a href="http://www.cybermalveillance.gouv.fr">www.cybermalveillance.gouv.fr</a>.</li>
<li style="text-align: left;">De manière plus générale : vous n’êtes pas seuls ! Victime ou témoin de comportements anormaux, il est nécessaire et important d’en parler pour trouver des solutions : vos parents, le signalement, les cellules d’écoute</li>
<li style="text-align: left;">Restreindre aux seules personnes de confiance les informations personnelles ou sensibles que vous ne voudriez pas voir diffusées sur Internet : ne pas communiquer ces informations à des inconnus, configurer ses paramètres de sécurité et confidentialité sur les réseaux sociaux, désactiver la géolocalisation des photos partagées publiquement, etc.</li>
<li style="text-align: left;">Protéger l’accès à vos comptes : vos mots de passe doivent rester secrets en toute circonstance, compliqués à deviner pour les autres et faciles à retenir par vous. Ils ne doivent pas être partagés et doivent régulièrement être changés, par précaution. Pour qu’ils soient plus sécurisés, préférez les mots de passe longs aux courts et faîtes une combinaison de lettres minuscules, majuscules, chiffres et caractères spéciaux.</li>
</ul>
</td>
</tr>
</tbody>
</table>
<h1>Un jeu testé en conditions réelles à diverses occasions</h1>
<p>La période de mai à juillet a été l’occasion de tester le jeu en conditions réelles à plusieurs dizaines de reprises, auprès de plusieurs tranches d’âge, potentiels joueurs ou animateurs (11-14 ans, 15-18 ans, etc.). Un franc succès, tant auprès des joueurs que des animateurs rencontrés ! Jusque-là, nous sommes ravis de l&#8217;engouement des jeunes et des animateurs pour ce jeu. Les premières sessions de test nous ont conforté sur le format qui permet d’<strong>échanger librement sur les </strong><strong>usages d’Internet et les </strong><strong>bonnes pratiques</strong><strong> associées</strong>.</p>
<p>Nous avons notamment pu constater que la sensibilisation effectuée dans les écoles ou par les diverses organisations portent leurs fruits : beaucoup de jeunes sont d&#8217;ores et déjà à l&#8217;aise avec certains termes inscrits sur les cartes, ce qui constitue une base solide au développement d&#8217;une meilleure hygiène numérique. L&#8217;objectif de ce jeu sera ainsi d&#8217;approfondir ces connaissances, de découvrir de nouvelles notions mais surtout de leur permettre d&#8217;en retirer des bonnes pratiques concrètes, à mettre en application sans plus attendre.</p>
<figure id="post-12075 media-12075" class="align-center"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-12075" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/Image-2.png" alt="" width="1286" height="369" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/Image-2.png 1286w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/Image-2-437x125.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/Image-2-768x220.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/Image-2-71x20.png 71w" sizes="auto, (max-width: 1286px) 100vw, 1286px" /></figure>
<h1>Un jeu gratuit et accessible à tous</h1>
<p>Pour une diffusion et une utilisation les plus larges possible, <strong><a href="https://github.com/wavestone-cdt/1-2-3-Cyber">le kit 1, 2, 3 Cyber est en téléchargement libre et gratuit depuis début août sur la plateforme Github</a></strong>. Ainsi, tous les parents, éducateurs et toute autre personne ayant des jeunes de cette tranche d’âge dans leur entourage peuvent sans difficultés dérouler le jeu.</p>
<p>Pour répondre aux besoins de tous et continuer à le faire évoluer, le jeu est diffusé en licence libre : <em>« la mise à disposition du jeu en open source n&#8217;est que le début, le but est que chacun puisse participer à son amélioration dans le temps ! » </em>affirme Etienne Capgras, manager cybersécurité chez Wavestone. Création de nouvelles cartes de jeu, ajout d’informations pratiques spécifiques à d’autres pays que la France, traduction dans d’autres langues… Toute volonté de contribuer sera la bienvenue ! Pour cela, il suffit de se rendre sur la plateforme Github ou de contacter le CCJ (<a href="mailto:contact@cyberccj.com">contact@cyberccj.com</a>) et Wavestone (<a href="mailto:123cyber@wavestone.com">123cyber@wavestone.com</a>).</p>
<p>&nbsp;</p>
<p>* Sondage réalisé par questionnaire auto-administré en ligne du 13 au 14 février 2019 auprès d‘un échantillon de 1 003 personnes, représentatif de la population âgée de 18 ans et plus résidant en France métropolitaine.</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2019/09/prevention-des-risques-cyber-sensibiliser-les-plus-jeunes-par-le-jeu/">Prévention des risques cyber : sensibiliser les plus jeunes par le jeu !</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Les As du Web : Participez à l’initiative de sensibilisation des 7-11 ans aux risques du web</title>
		<link>https://www.riskinsight-wavestone.com/en/2018/11/les-as-du-web/</link>
		
		<dc:creator><![CDATA[Gérôme Billois]]></dc:creator>
		<pubDate>Tue, 27 Nov 2018 08:25:51 +0000</pubDate>
				<category><![CDATA[Cyberrisk Management & Strategy]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[cyberawareness]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[ISSA]]></category>
		<category><![CDATA[Risque]]></category>
		<category><![CDATA[sensibilisation]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=11430/</guid>

					<description><![CDATA[<p>« Va parler à la maitresse si quelqu’un t’embête à l’école », « Je ne te louerai pas ce DVD, ce film est trop violent pour toi » ou encore le classique « Surtout, ne suis pas un inconnu, même s’il t’offre des bonbons ». On...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2018/11/les-as-du-web/">Les As du Web : Participez à l’initiative de sensibilisation des 7-11 ans aux risques du web</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<figure id="post-11434 media-11434" class="align-center"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-11434" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2018/11/Sans-titre.png" alt="" width="660" height="282" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2018/11/Sans-titre.png 660w, https://www.riskinsight-wavestone.com/wp-content/uploads/2018/11/Sans-titre-437x187.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2018/11/Sans-titre-71x30.png 71w" sizes="auto, (max-width: 660px) 100vw, 660px" /></figure>
<p><em>« Va parler à la maitresse si quelqu’un t’embête à l’école », « Je ne te louerai pas ce DVD, ce film est trop violent pour toi » ou encore le classique « Surtout, ne suis pas un inconnu, même s’il t’offre des bonbons ». On a tous encore en tête, même après des décennies, les conseils de nos parents concernant notre sécurité dans la vie de tous les jours. Mais avec une utilisation de plus en plus précoce d’Internet par les enfants, cette vie de tous les jours s’est maintenant étendue à la toile. Il est donc devenu impératif de sensibiliser les plus jeunes aux risques auxquels ils s’exposent en surfant sur le web pour qu’ils puissent en tirer tous les bénéfices !</em></p>
<h2>L&#8217;éducation aux risques numérique, une nécessité</h2>
<p>C’est la mission que se donne ISSA France sous le patronage du secrétariat d’état chargé du numérique avec <a href="http://securitytuesday.com/wp-content/uploads/2018/10/ISSA.Cahier.SecNum777.pdf">son cahier de vacances « Les As du Web ».</a> Et le besoin est là : selon un récent <a href="https://www.ipsos.com/fr-fr/les-enfants-et-internet-56-des-jeunes-pensent-pouvoir-aller-sur-internet-en-toute-impunite">sondage IPSOS</a>, plus d’un tiers des jeunes interrogés (entre 9 et 17 ans) ne protègent en rien les informations personnelles qu’ils mettent en ligne. Plus inquiétant, un cinquième de ces enfants pourrait envisager de donner rendez-vous à un étranger rencontré sur Internet, et 10% discutent d’ailleurs régulièrement avec de parfaits inconnus.</p>
<p>La sensibilisation de cette population à ces dangers est d’autant plus importante que l’autorité parentale ne suffit pas toujours : ils sont 65% à déclarer ne pas respecter au moins une règle de conduite édictée par leurs parents&#8230; Ces derniers ne sont d’ailleurs pas toujours très au courant eux-mêmes des dangers de la toile.</p>
<p>Sensibiliser les enfants, et par transitivité des parents, est donc un enjeu qui a déjà fait l’objet d’initiatives, avec notamment la création du <em>Permis Internet</em> par le Ministère de l’Intérieur. La publication de ce cahier de vacances « Les As du Web » est une étape supplémentaire dans l’intégration du numérique au sein de l’éducation des jeunes générations.</p>
<h2>Comment parler simplement d&#8217;un sujet complexe</h2>
<p>Pour autant, aborder une thématique technologique avec un public aussi particulier peut relever d’une véritable gageure, et ce d’autant plus qu’ISSA France a choisi de s’adresser aux 7 – 11 ans. Cibler cette tranche d’âge tombe sous le sens car c’est l’âge auquel ces internautes en herbe accèdent à Internet et sont les plus vulnérables.</p>
<p>Le premier challenge est donc d’arriver à isoler les sujets à aborder dans l’ouvrage. Ils doivent traiter les grands risques auxquels les enfants seront exposés de la manière la plus didactique et rassurante possible. Le choix d’un cahier de vacances, avec ses jeux et son graphisme ludique répond à cet objectif. Ensuite, il s’agit de trouver les bons mots. Le monde du numérique est truffé d’anglicismes et utilise un vocabulaire très particulier qu’il faut simplifier et expliquer si besoin au jeune lecteur afin de faciliter sa compréhension.</p>
<h2>Les grands thèmes du petit cahier</h2>
<p>Le cahier de vacances « Les As du Web » aborde donc dans un ouvrage ludique et pédagogique d’une vingtaine de pages les six thématiques suivantes :</p>
<ul>
<li><strong>Qui se cache derrière ton écran ? Et pour quoi faire ?</strong> Pour bien expliquer que l’on peut facilement masquer son identité et prétendre être celui que l’on n’est pas.</li>
<li><strong>Tes données personnelles : apprends à les reconnaitre et protège-les !</strong> Pour montrer la valeur de ses données et les enjeux à long terme.</li>
<li><strong>Le monde numérique n’est pas que pour les enfants. Ne t’y promène pas seul.</strong> Pour démontrer que le web n’est finalement pas si différent du monde « réel ».</li>
<li><strong>Le cyberharcèlement : c’est grave !</strong> Cette partie donne les bons réflexes sur comment réagir lorsque l’on est visé ou témoin ?</li>
<li><strong>Internet ne dit pas toujours la vérité.</strong> Gare aux mensonges pour ne pas les répéter. Important en ces temps-de « fake news ».</li>
<li><strong>Sur Internet, reste cool et toi-même</strong>. Afin de démystifier et donner les bons réflexes de posture.</li>
</ul>
<h2>De la page web aux enfants, il reste du chemin à parcourir</h2>
<p>Le projet est maintenant arrivé au bout de sa première phase : la création du contenu. Wavestone est d’ailleurs très heureux d’y avoir, avec d’autres, participé. Mais cette première étape ne constitue que 10% du chemin car tout l’enjeu maintenant est de faire que ce contenu atteigne sa cible !</p>
<p>Pour se donner les moyens d’y arriver, ISSA France souhaite imprimer un million de copies papier d’ici cet été. Car si pour le moment, le cahier n’est disponible qu’en ligne, l’association souhaite en effet placer de nombreux exemplaires physiques à des endroits stratégiques, comme les gares, les aéroports ou les aires d’autoroute lors des départs en vacances. Et c’est là que vous pouvez aider et participer au succès de cette initiative. A votre échelle en partageant autour de vous le cahier de vacances mais aussi à l’échelle de votre entreprise, puisqu’ISSA France est toujours à la recherche de partenaires pour participer à la diffusion de cet ouvrage et lui permettre d’atteindre sa cible.</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2018/11/les-as-du-web/">Les As du Web : Participez à l’initiative de sensibilisation des 7-11 ans aux risques du web</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>JO2016 : qui aura la médaille d’or chez les cybercriminels ?</title>
		<link>https://www.riskinsight-wavestone.com/en/2016/08/jo2016-medaille-dor-cybercriminels/</link>
		
		<dc:creator><![CDATA[Gérôme Billois]]></dc:creator>
		<pubDate>Thu, 04 Aug 2016 13:55:15 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Ethical Hacking & Incident Response]]></category>
		<category><![CDATA[bonnes pratiques]]></category>
		<category><![CDATA[Cybercriminalité]]></category>
		<category><![CDATA[menace]]></category>
		<category><![CDATA[sensibilisation]]></category>
		<category><![CDATA[Threat intelligence]]></category>
		<guid isPermaLink="false">https://www.solucominsight.fr/?p=9143</guid>

					<description><![CDATA[<p>Les JO approchent et les risques cyber associés également, n’hésitez pas à relayer cet article de sensibilisation au ton volontairement ludique. Il n’y a pas que les athlètes qui préparent l’événement sportif international de l’année, les cybercriminels également. Chaque spécialité...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2016/08/jo2016-medaille-dor-cybercriminels/">JO2016 : qui aura la médaille d’or chez les cybercriminels ?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><em>Les JO approchent et les risques cyber associés également, n’hésitez pas à relayer cet article de sensibilisation au ton volontairement ludique.</em></p>
<p>Il n’y a pas que les athlètes qui préparent l’événement sportif international de l’année, les cybercriminels également. Chaque spécialité est bien représentée et va lutter pour obtenir la médaille d’or de la méthode la plus efficace de vol et de fraude. Tour d’horizon des équipes en présence et de leur stratégie.</p>
<h1>L’équipe Phishing et son lancer de faux emails</h1>
<p>Habituée des grands événements, <strong>l’équipe Phishing inonde les boîtes emails de faux messages demandant de communiquer des données sensibles</strong> comme ses identifiants ou ses coordonnées bancaires. Leur meilleure technique pendant les JO : vous proposer des loteries pour gagner des tickets gratuits ou des accès à des retransmissions TV ! Le meilleur moyen de leur résister ? Être attentif aux messages trop alléchants, trop urgents et qui contiennent des fautes de frappe ou de grammaire. Un bon réflexe : ne jamais aller sur un site en cliquant sur un lien depuis un email, mais le retaper directement dans le navigateur.</p>
<h1>Les cybersquatters et leurs tours de passe-passe quasi indétectables</h1>
<p>Les cybersquatters affutent leurs méthodes depuis plusieurs mois, ils ont créé près de <strong>4000 faux sites web</strong> dont l’adresse <a href="http://www.computerworld.com/article/3103289/security/cybercrime-infrastructure-being-ramped-up-in-brazil-ahead-of-olympics.html">ressemble étrangement à celle des sites officiels</a> mais qui vous emmènent dans leurs pièges ! Quoi de plus ressemblant entre www.rio-olympics.com et www.rio-olympisc.com ? Restez donc attentifs aux sites que vous visitez en vous assurant qu’ils ne contiennent pas d’erreur dans leur nom. Vous éviterez ainsi de tomber sur des sites dangereux qui pourraient vous forcer à télécharger des logiciels malveillants ou vous demander des données personnelles.</p>
<h1>L’équipe Ransomware et sa clé de bras numérique</h1>
<p>Cette équipe a un moyen très efficace pour vous soutirer de l’argent, elle bloque votre ordinateur et/ou votre téléphone portable et vous demande une rançon ! Une vraie clé de bras numérique digne d’un lutteur ou d’un judoka. <strong>L’équipe Ransomware joue collectif car elle fait souvent alliance avec les équipes Phishing et Cybersquatteurs</strong> qui leurs ouvrent la route via des faux emails ou des faux sites qui ensuite vous demande d’installer des logiciels complémentaires… Et c’est là où l’équipe Ransomware surgit et qu’<a href="http://www.businessrevieweurope.eu/technology/960/Phishing-ransomware-and-fake-tickets:-how-to-avoid-Rio-2016-cyber-crime">elle déploie ses outils qui bloqueront votre ordinateur</a>. Pour éviter d’être piégé, soyez très attentif et surtout n’installez pas d’applications alléchantes qui vous propose des accès gratuits à des flux TV ou à du contenu exclusif. Utilisez les boutiques d’applications officielles qui disposent d’un choix très fourni et légal.</p>
<h1>Les cybercriminels locaux et leurs faux points d’accès Wi-Fi</h1>
<p>Une équipe à domicile est toujours plus forte, c’est bien connu ! Et il faut s’attendre à ce que les cybercriminels brésiliens, présent sur place, essaient de <strong>détourner les bornes Wifi mises à disposition des visiteurs dans les lieux publics</strong> pour intercepter leurs échanges et ainsi voler des données. Le meilleur réflexe c’est d’acheter une <a href="http://prepaid-data-sim-card.wikia.com/wiki/Brazil">carte SIM locale</a> pour utiliser votre téléphone et accéder à Internet. Pour les plus férus de technologies, un VPN apportera également un bon niveau de protection, il existe de <a href="http://www.opera.com/blogs/news/2016/05/vpn-app-for-ios-free-surfeasy/">nombreuses applications comme celle d’Opera</a>. Et si vous devez vraiment utiliser du Wi-Fi, restez attentifs au moindre message d’erreur concernant la sécurité. Lorsque vous allez sur des sites Internet et que de tels messages apparaissent, c’est un signe que le point d’accès est peut-être piraté : déconnectez-vous immédiatement.</p>
<h1>L’équipe APT et sa précision redoutable</h1>
<p>Cette équipe ne vise pas le grand public, elle cherche à gagner la course en s’<strong>introduisant frauduleusement dans les systèmes de l’organisation des JO</strong>. Elle pourra ainsi y voler directement les données des athlètes, des spectateurs, mais aussi aller jusqu’à modifier des résultats, interrompre des compétitions ou empêcher leur rediffusion ! Le <strong>CIO est mobilisé sur ces menaces</strong> depuis de nombreuses années et met en œuvre un dispositif spécifique de cybersécurité. Le retour des JO de Londres nous montre clairement la <a href="http://www.computing.co.uk/ctg/news/2252841/how-the-london-olympics-dealt-with-six-major-cyber-attacks">réalité de cette menace avec plus de 165 millions d’événements </a>liés à la cybersécurité qui ont conduit à 6 attaques majeures. Rio devrait subir une pression encore plus forte au regard de l’évolution de la cybercriminalité sur ces 4 dernières années.</p>
<h1>Un bon réflexe : ce qui est trop beau pour être vrai est certainement un piège</h1>
<p>Ne tombez pas dans les pièges des cybercriminels, soyez <strong>attentifs</strong> lorsque vous surfez et lisez vos emails. Et n’oubliez pas de faire une <strong>sauvegarde de vos données</strong>, de <strong>mettre à jour votre ordinateur et votre téléphone</strong> en appliquant les<strong> correctifs de sécurité proposés</strong> et en vous assurant d’avoir un <strong>anti-virus à jour</strong>.</p>
<p>Voici l’entraînement que vous devez suivre pour vivre des Jeux Olympiques en toute cybersécurité !</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2016/08/jo2016-medaille-dor-cybercriminels/">JO2016 : qui aura la médaille d’or chez les cybercriminels ?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Sensibilisation à la cybersécurité : où en sont les entreprises françaises ?</title>
		<link>https://www.riskinsight-wavestone.com/en/2016/01/sensibilisation-a-la-cybersecurite-ou-en-sont-les-entreprises-francaises/</link>
		
		<dc:creator><![CDATA[SopHi8Then0t]]></dc:creator>
		<pubDate>Mon, 25 Jan 2016 07:30:24 +0000</pubDate>
				<category><![CDATA[Cyberrisk Management & Strategy]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[benchmark]]></category>
		<category><![CDATA[cyberawareness]]></category>
		<category><![CDATA[sensibilisation]]></category>
		<guid isPermaLink="false">http://www.solucominsight.fr/?p=8705</guid>

					<description><![CDATA[<p>À l’occasion du FIC 2016, Solucom et Conscio Technologies, spécialiste de la sensibilisation à la sécurité de l’information, révèlent les résultats de leur étude exclusive sur la sensibilisation à la cybersécurité dans les grandes entreprises françaises. Fondée sur un panel...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2016/01/sensibilisation-a-la-cybersecurite-ou-en-sont-les-entreprises-francaises/">Sensibilisation à la cybersécurité : où en sont les entreprises françaises ?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><em>À l’occasion du FIC 2016, Solucom et <a href="http://www.conscio-technologies.com/">Conscio Technologies</a>, spécialiste de la sensibilisation à la sécurité de l’information, révèlent les résultats de leur <a href="http://www.solucom.fr/wp-content/uploads/2016/01/Solucom-Conscio-Sensibilisation-SSI-Benchmark-2015.pdf">étude exclusive sur la sensibilisation à la cybersécurité dans les grandes entreprises françaises</a>.</em></p>
<p><em>Fondée sur un panel de 28 000 personnes interrogées dans 12 entreprises majeures, cette étude met en lumière des points cruciaux sur lesquels les entreprises doivent agir aujourd’hui afin d’éviter d’être, une fois de plus, victimes de cyberattaques. Cette analyse complète, unique en France, a été réalisée avec la solution ISAM de Conscio Technologies, qui permet d’auditer le niveau de sensibilisation des salariés en matière de sécurité informatique.</em></p>
<h2>46% des collaborateurs ne connaissent pas les comportements à adopter face à l’ingénierie sociale</h2>
<p>Premier enseignement, la fragilité des entreprises face à l’ingénierie sociale (faux emails de type phishing, escroqueries au président, appels téléphoniques frauduleux…) est clairement démontrée. 46% des collaborateurs ne connaissent pas les comportements à adopter face à ce type d’attaques. « <em>L’ingénierie sociale est aujourd’hui le vecteur n°1 pour réaliser des fraudes ou s’introduire dans les réseaux d’entreprise. L’ensemble des collaborateurs doit connaître cette menace et surtout savoir comment se comporter, en particulier en alertant rapidement les responsables sécurité</em> » détaille Gérôme Billois, senior manager cybersécurité chez Solucom. « <em>La majorité des incidents ou pertes de données sont déclenchés par le facteur humain. Il est donc primordial de sensibiliser les salariés aux bonnes pratiques et d’envisager la sécurité dans son ensemble</em> » confirme Michel Gérard, directeur de Conscio Technologies.</p>
<h2>Les bonnes pratiques de sécurité des mots de passe maitrisées par 47% des collaborateurs</h2>
<p>Deuxième enseignement, les mots de passe restent un sujet complexe pour les collaborateurs des entreprises. 88% d’entre eux sont sensibilisés sur la nécessité d’avoir un mot de passe de bonne qualité (longueur, absence de mots existants…) mais seulement 47% adoptent les bonnes pratiques dans leurs activités quotidiennes. « <em>Ce chiffre montre que malgré de bonnes intentions, seule la mise en place de mécanismes techniques pour forcer la qualité des mots de passe fera évoluer la situation</em> » analyse Gérôme Billois.</p>
<h2>La réglementation, un sujet connu uniquement par 63% des collaborateurs</h2>
<p>Enfin, il apparaît que les collaborateurs des grandes entreprises sont très peu sensibilisés aux réglementations sur la protection des données à caractère personnel. Ce thème obtient globalement le plus faible des scores, avec 63% des répondants connaissant les règles de base sur la protection des données des clients ou des collaborateurs. « <em>Ceci fait courir un risque juridique direct aux entreprises, d’autant plus que la réglementation va très prochainement se durcir avec le nouveau règlement européen sur les données à caractère personnel</em> » détaille Gérôme Billois.</p>
<p>La sensibilisation des collaborateurs est un facteur clé de la cyberprotection des entreprises. Aujourd’hui, de nombreuses structures réalisent des actions dans ce domaine mais peu en évaluent réellement l’effet. « <em>C’est pourtant cette évaluation qui permet de mesurer l’efficacité et d’orienter les prochaines actions vers les populations les plus à risque</em> » ajoute Michel Gérard.</p>
<p><a href="http://www.solucom.fr/wp-content/uploads/2016/01/Solucom-Conscio-Sensibilisation-SSI-Benchmark-2015.pdf">Téléchargez le benchmark 2015 de la sensibilisation à la cybersécurité</a></p>
<p><em>Etude menée par Solucom et Conscio Technologies en 2015 sur un panel de 28 000 utilisateurs de la solution ISAM de 12 entreprises majeures en France. L</em><em>’étude est disponible auprès de Solucom et Conscio Technologies et sera distribuée lors du FIC 2016 qui se tiendra à Lille les 25 et 26 janvier 2016.</em></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2016/01/sensibilisation-a-la-cybersecurite-ou-en-sont-les-entreprises-francaises/">Sensibilisation à la cybersécurité : où en sont les entreprises françaises ?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>La Hack Academy, première campagne nationale de sensibilisation à la cybersécurité</title>
		<link>https://www.riskinsight-wavestone.com/en/2015/10/la-hack-academy-premiere-campagne-nationale-de-sensibilisation-a-la-cybersecurite/</link>
		
		<dc:creator><![CDATA[SopHi8Then0t]]></dc:creator>
		<pubDate>Wed, 07 Oct 2015 11:16:56 +0000</pubDate>
				<category><![CDATA[Cyberrisk Management & Strategy]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[cyberawareness]]></category>
		<category><![CDATA[Hack Academy]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[sensibilisation]]></category>
		<guid isPermaLink="false">http://www.solucominsight.fr/?p=8354</guid>

					<description><![CDATA[<p>A l&#8217;occasion du &#8220;mois Européen de la cybersécurité&#8221;, le CIGREF (Club Informatique des Grandes Entreprises Françaises) a lancé le 1er Octobre, une vaste campagne grand public de sensibilisation pour valoriser les bonnes pratiques informatiques et contribuer à une meilleure connaissance...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2015/10/la-hack-academy-premiere-campagne-nationale-de-sensibilisation-a-la-cybersecurite/">La Hack Academy, première campagne nationale de sensibilisation à la cybersécurité</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><em>A l&#8217;occasion du &#8220;mois Européen de la cybersécurité&#8221;, le CIGREF (Club Informatique des Grandes Entreprises Françaises) a lancé le 1er Octobre, une vaste campagne grand public de sensibilisation pour valoriser les bonnes pratiques informatiques et contribuer à une meilleure connaissance des risques sur Internet. Conscient de l&#8217;importance de cette démarche, le cabinet Solucom s&#8217;est associé à cette opération d&#8217;envergure nationale.</em></p>
<h2>Un message à faire passer &#8220;Sur Internet, je reste en alerte&#8221;</h2>
<p>Alors que les menaces se multiplient concernant aussi bien les entreprises que les citoyens, cette opération ludique et décalée a pour objectif de montrer qu&#8217;il est possible de lutter contre le piratage en adoptant les bons réflexes.</p>
<p>Conçue par l&#8217;agence W, cette campagne de sensibilisation se décline au travers du site internet <a href="http://www.hack-academy.fr/" target="_blank" rel="noopener noreferrer">www.hack-academy.fr</a>. Le CIGREF a choisi de se servir des codes qui parlent à tout le monde, ceux de la télé-réalité pour faire passer des messages et élever le niveau de conscience.</p>
<h2>Qui sera le hacker de demain ?</h2>
<p>Les quatre vidéos publiées sur le site mettent en scène des jeunes candidats révélant leurs talents de pirate informatique devant un jury de professionnels de la &#8220;Hack Academy&#8221; dont l&#8217;objectif est de découvrir les hackers de demain.</p>
<p>Les candidats Jeny, Dimitri, Martin et Willy s&#8217;attaquent aux principales attaques auxquelles les internautes peuvent être confrontés. Ils abordent avec humour le phishing, le piratage de mot de passe ou encore le cheval de Troie.</p>
<p>En plus des vidéos, le site hack-academy.fr propose également de défier chacun des candidats au travers d&#8217;un quizz encore une fois basé sur l&#8217;humour et la pédagogie.</p>
<figure id="post-8367 media-8367" class="align-none"><img decoding="async" src="http://www.solucominsight.fr/wp-content/uploads/2015/10/quizz.png" alt="" /></figure>
<p>Le site permet également d’accéder à des fiches pratiques sur les différents types d&#8217;attaques et les façons de se protéger.</p>
<figure id="post-8365 media-8365" class="align-none"><img decoding="async" src="http://www.solucominsight.fr/wp-content/uploads/2015/10/contenu.png" alt="" /></figure>
<p>Pour <strong>Jean-Paul Mazoyer</strong>, Président du cercle Cybersécurité du CIGREF : « <em>Grâce à l’efficacité des campagnes grand-public par exemple sur l’alcool au volant ou la ceinture de sécurité, nous nous sentons maintenant concernés par ces questions… Hack-academy  sera la première campagne touchant la cybersécurité ! L’histoire du premier geste qui protège les données sur Internet ne fait que commencer</em> »</p>
<p><strong>Découvrez Willy, le spécialiste du phishing, selon lui « <em>Avec un simple mail et une photo on peut berner n’importe qui … </em>»</strong></p>
<p><iframe loading="lazy" src="https://www.youtube.com/embed/2OTdWaTlUBo" width="560" height="315" frameborder="0" allowfullscreen="allowfullscreen"></iframe></p>
<p>Et pour voir toutes les vidéos, rendez-vous sur : <a href="http://www.hack-academy.fr">www.hack-academy.fr</a></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2015/10/la-hack-academy-premiere-campagne-nationale-de-sensibilisation-a-la-cybersecurite/">La Hack Academy, première campagne nationale de sensibilisation à la cybersécurité</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Comment mesurer l’impact des campagnes de sensibilisation ?</title>
		<link>https://www.riskinsight-wavestone.com/en/2015/06/comment-mesurer-limpact-des-campagnes-de-sensibilisation/</link>
		
		<dc:creator><![CDATA[SopHi8Then0t]]></dc:creator>
		<pubDate>Thu, 18 Jun 2015 14:47:06 +0000</pubDate>
				<category><![CDATA[Cyberrisk Management & Strategy]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[cyberawareness]]></category>
		<category><![CDATA[maturité]]></category>
		<category><![CDATA[sensibilisation]]></category>
		<guid isPermaLink="false">http://www.solucominsight.fr/?p=7857</guid>

					<description><![CDATA[<p>Il faut bien le dire, la sensibilisation du personnel a, pendant longtemps, été le parent pauvre des stratégies de sécurité mises en œuvre dans les entreprises. Quelques contre-exemples notables ne peuvent dissimuler le fait que ce sujet ait été peu,...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2015/06/comment-mesurer-limpact-des-campagnes-de-sensibilisation/">Comment mesurer l’impact des campagnes de sensibilisation ?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><em>Il faut bien le dire, la sensibilisation du personnel a, pendant longtemps, été le parent pauvre des stratégies de sécurité mises en œuvre dans les entreprises. Quelques contre-exemples notables ne peuvent dissimuler le fait que ce sujet ait été peu, pas ou mal traité dans la majorité des entreprises.</em></p>
<p>Parmi les raisons qui ont pu conduire à cette situation, il est possible de recenser notamment le manque de budget ; la difficulté de mobiliser des intervenants aux métiers différents ; la difficulté de montrer des résultats car l’effort doit être porté dans la durée ; les a priori de certains dirigeants : «  la sensibilisation, ça ne sert à rien. »</p>
<p>C’est pourquoi, si l’on veut être capable de placer le traitement du volet humain de la sécurité et donc la sensibilisation à sa juste place, il est indispensable de disposer d’une mesure qui va nous permettre de savoir d’où on part, quel est le chemin parcouru et donc de placer les travaux de sensibilisation dans une démarche d’amélioration continue.</p>
<p>Enfin si l’on veut pouvoir intégrer le processus de sensibilisation dans l’élaboration d’un tableau de bord SSI, il est nécessaire de disposer des bons indicateurs.</p>
<h2>Que mesure-t-on ?</h2>
<h3>Un modèle de maturité</h3>
<p>A des fins de benchmark et pour pouvoir se donner des objectifs clairs et réalistes, il peut être utile de pouvoir se positionner et se fixer des objectifs à atteindre au travers d’un modèle de maturité.</p>
<p>C’est pourquoi nous proposons ici un modèle de maturité adapté à la problématique de sensibilisation. La classification ci-dessous illustre les différents niveaux que l’on peut rencontrer quant au développement d’une culture sécurité :</p>
<ul>
<li><strong>Niveau 0</strong> : les utilisateurs sont laissés à eux même, aucune consigne particulière ne leur est donnée, seuls les équipements d’infrastructure assurent la sécurité ;</li>
<li><strong>Niveau 1</strong> : des outils sont mis en place sur l’initiative de l’équipe SSI (charte, affiches…) Aucun retour quant à l’efficacité de ces mesures n’existe, on communique quelques messages en espérant qu’ils seront entendus.</li>
<li><strong>Niveau 2</strong> : la Direction s’assure que tout le personnel est formé. Elle a délégué à l’équipe SSI le soin d’assurer des actions d’information et de sensibilisation. Des tests sont menés afin de s’assurer que la connaissance des bonnes pratiques est bien diffusée ;</li>
<li><strong>Niveau 3</strong> : correspond aux caractéristiques du niveau 2 auxquelles on rajoute une communication claire et directe par la direction d’une vision ; des actions sont menées afin de modifier les comportements et des indicateurs sont mis en place et suivis ;</li>
<li><strong>Niveau 4</strong> : on retrouve les caractéristiques du niveau 3 et : la sécurité est intégrée à chaque processus et fait partie de la culture d’entreprise, chaque manager suit la qualité du travail fourni en regard de la sécurité, les incidents sont analysés et cette analyse donne lieu à une amélioration continue.</li>
</ul>
<p>Dans notre modèle de maturité, il apparaît clairement que le fait d’apporter une mesure dans la mise en œuvre des campagnes de sensibilisation n’apparaît qu’au niveau 2. Ce n’est qu’à partir de ce niveau qu’on commence à se préoccuper des résultats de ce qui est fait.</p>
<h3>Une mesure sur 3 axes</h3>
<p>Le niveau de maturité d’une population concernant la sécurité numérique se mesure sur trois axes :</p>
<ul>
<li><strong>L’axe sensibilité</strong> correspond à la perception que les collaborateurs ont de la sécurité comme étant un sujet important dans l’organisation.</li>
<li><strong>L’axe connaissances</strong> correspond au niveau de connaissance des utilisateurs sur les enjeux, les bonnes pratiques.</li>
<li><strong>L’axe comportements</strong> correspond au niveau de respect, par les utilisateurs, des comportements souhaités.</li>
</ul>
<p>Plusieurs méthodes existent pour visualiser les mesures obtenues. Une manière classique consiste à représenter sur une figure multi axes les résultats obtenus en pourcentage d’un résultat maximal possible. C’est ce que l’on retrouve dans le schéma suivant.</p>
<p>&nbsp;</p>
<p style="text-align: center;"> <img decoding="async" class=" alignnone" src="http://www.solucominsight.fr/wp-content/uploads/2015/06/figure1.jpg" alt="" /></p>
<p style="text-align: center;"><strong>Figure 1.</strong> C’est en développant la sensibilité et les connaissances au travers d’une communication engageante que l’on finit par obtenir les comportements souhaités</p>
<p>La valeur obtenue pour chacun des axes est directement liée à la campagne de mesures qui est faite sur les indicateurs propres à chaque axe. Les graphiques suivants donnent des exemples de ce qui peut être fait en la matière.</p>
<p>Ainsi la mesure des connaissances peuvent se faire selon les thématiques choisies pour les campagnes et regroupant l’ensemble des sujets à traiter.</p>
<p>La mesure de la sensibilité peut se faire sur quelques indicateurs permettant d’objectiver un sujet à priori difficile à évaluer. Ainsi cette mesure peut s’effectuer en évaluant au travers d’un processus d’audit tout ce qui participe à faire du sujet quelque chose d’important et la perception que les collaborateurs en ont.</p>
<p>On définit ensuite, pour chacune des réponses proposées, le nombre par lequel sera incrémenté l’attribut si cette réponse est choisie. Chaque répondant obtient ainsi une note sur cet attribut. On calcule ensuite la moyenne des résultats obtenus que l’on met en regard de la note maximale qu’il est possible d’obtenir.</p>
<p>La mesure des comportements portera sur certaines catégories de comportements a priori plus facilement observables.</p>
<h2>Comment mesure-t-on ?</h2>
<h3>Réalisation d’une enquête physique</h3>
<p>Relativement peu usité, la réalisation d’une enquête physique peut avoir l’avantage de permettre de prendre le pouls d’une population au regard de la sécurité de l’information. En effet, au-delà des aspects quantitatifs, le retour effectué par des enquêteurs peuvent, dans ce cas, incorporer des éléments d’ « ambiance » difficile à évaluer par d’autres procédés. En revanche le procédé prend du temps et est couteux.</p>
<p>L’enquête est alors réalisée sur un échantillon représentatif de la population ciblée. L’échantillonnage sera effectué selon la méthode des quotas, c&#8217;est-à-dire respectant en proportion les différentes caractéristiques de la population de l’organisation.</p>
<p>Cet état des lieux s’exprime ensuite au travers d’un rapport constitué d’éléments qualitatifs et quantitatifs.</p>
<p>La situation de l’organisation au regard du développement d’une culture sécurité sera rapprochée du modèle de maturité. On tentera également de dégager des axes de progression et de définir des objectifs à atteindre en vue de faire progresser la culture sécurité dans l’organisation.</p>
<h3>Mesure en ligne</h3>
<p>La réalisation d’une enquête en ligne est un excellent moyen pour réaliser une évaluation de la maturité d’une population au regard des questions de sécurité. Ce procédé permet de cibler la totalité de la population et de rester à un coût de mise en œuvre raisonnable.</p>
<p>Afin de permettre, comme nous l’avons vu, une mesure sur les trois axes de sensibilité, de connaissances et de comportements, une telle enquête doit :</p>
<ul>
<li>Être composée d’une série de QCM, traitant des différentes thématiques à couvrir (aspects légaux, organisation, mot de passe, ingénierie sociale…) ;</li>
<li>Permettre la mesure de la connaissance par un rattachement des questions aux différents sujets à couvrir ;</li>
<li>Associer les attributs sensibilité, connaissances et comportements aux questions afin de donner une valeur à ces attributs en fonction des réponses choisies par le répondant.</li>
</ul>
<p>La diffusion de l’enquête pourra également s’appuyer sur un outil permettant d’identifier les niveaux de réponses en fonction d’un profilage particulier de la population cible. Cela permet notamment de mesurer l’impact d’une campagne de sensibilisation en fonction des métiers de l’entreprise.</p>
<p>Des questions sont donc posées en ligne dans le cadre d’une enquête menée sur une période de quelques semaines.</p>
<h3>Évaluation des comportements par observation</h3>
<p>La finalité des campagnes de sensibilisation étant d’avoir un impact réel sur les comportements, il peut être particulièrement intéressant de mesurer l’évolution dans le temps de certains comportements réels. Il s’agit ici de mesurer ce que font les collaborateurs réellement et non ce qu’ils déclarent ou ce qui transparait dans leur réponse à une enquête. Cela passe par l’observation de ces comportements et la mise en œuvre de tests. On peut ainsi citer, à titre d’exemple :</p>
<ul>
<li>Test sur l’utilisation de la messagerie et sur le respect de la politique antivirale par envoi de messages de source inconnue avec une pièce jointe exécutable mais inoffensive et mesure du taux d’ouverture de ces pièces jointes ;</li>
<li>Test de phishing : envoi d’un message de type phishing mais au contenu inoffensif et permettant de mesurer le taux de clics ;</li>
<li>Test sur le respect de la politique de création de mot de passe par un test de résistance sur la base de mots de passe ;</li>
<li>Test sur le respect de la politique de l’utilisation d’Internet par examen des traces et le recensement des urls visitées;</li>
<li>Etc…</li>
</ul>
<p>A chacun de ces tests est associé un indicateur qui peut être à chaque fois le taux de bons comportements sur le nombre de comportements observés. Ces indicateurs viennent ensuite enrichir la mesure faite sur l’axe comportements</p>
<h2>Rattachement au tableau de bord sécurité</h2>
<p>Le traitement du volet humain de la sécurité est un aspect essentiel de toute stratégie sécurité. Ainsi, s’il est élaboré un tableau de bord de la sécurité, il convient d’intégrer la mesure de maturité des collaborateurs de l’entreprise dans son élaboration.</p>
<p>Si ce tableau de bord suit une approche de type tableau de bord équilibré (Balanced Score Card) on doit identifier les Indicateurs Clés d’Objectif (ICO) et les Indicateurs Clés de Performance (ICP) applicables au processus de sensibilisation.</p>
<p>L’objectif de tout processus d’acculturation est, rappelons-le, d’obtenir des comportements conformes aux bonnes pratiques et, par-là, de diminuer le nombre d’incidents trouvant leur origine dans une cause humaine. Il est donc possible de choisir comme ICO :</p>
<ul>
<li>Le nombre d’incidents ayant pour origine un défaut de comportement d’un collaborateur, dans la mesure où le processus de gestion des incidents le permet ;</li>
<li>Le nombre de constatations de défauts de comportements dans le cadre d’un audit ou d’une enquête récurrents portant sur un référentiel constant.</li>
</ul>
<p><strong>Et comme ICP :</strong></p>
<ul>
<li>Les indicateurs choisis pour mesurer la sensibilité ;</li>
<li>Et, les indicateurs choisis pour mesurer la connaissance.</li>
</ul>
<h2>En conclusion</h2>
<p>Il faut inscrire la mesure dans une dynamique</p>
<p>A la question : « Comment intéresser ma Direction Générale aux opérations de sensibilisation ? »</p>
<p>La réponse est : « Donner lui un retour quantifié ! »</p>
<p>La mise en place d’une mesure dans le temps du niveau de maturité du Personnel au regard des questions de sécurité ne peut qu’intéresser une Direction Générale et la motiver à accorder des moyens à des actions dont elle mesure l’impact.</p>
<p>Le processus d’acculturation d’une population est un chantier de longue haleine, seule la mise en place d’une mesure permet de démontrer le chemin parcouru et de se donner des objectifs.</p>
<p>&nbsp;</p>
<p><em>Extrait du livre blanc « Comment mesurer les impacts des campagne de sensibilisation » rédigé par Hapsis en février 2015.</em></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2015/06/comment-mesurer-limpact-des-campagnes-de-sensibilisation/">Comment mesurer l’impact des campagnes de sensibilisation ?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Sensibilisation : quelles pratiques chez les grands comptes ?</title>
		<link>https://www.riskinsight-wavestone.com/en/2012/10/sensibilisation-quelles-pratiques-chez-les-grands-comptes/</link>
		
		<dc:creator><![CDATA[Marion Couturier]]></dc:creator>
		<pubDate>Tue, 23 Oct 2012 14:44:33 +0000</pubDate>
				<category><![CDATA[Cyberrisk Management & Strategy]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[benchmark]]></category>
		<category><![CDATA[cyberawareness]]></category>
		<category><![CDATA[sensibilisation]]></category>
		<guid isPermaLink="false">http://www.solucominsight.fr/?p=2414</guid>

					<description><![CDATA[<p>Face aux menaces pesant sur le patrimoine informationnel de l’entreprise la sensibilisation des collaborateurs est devenue un élément clé de la démarche de sécurité de l’information. Mais quelles sont les pratiques des grandes entreprises à ce sujet aujourd’hui ? Quels sont...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2012/10/sensibilisation-quelles-pratiques-chez-les-grands-comptes/">Sensibilisation : quelles pratiques chez les grands comptes ?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Face aux menaces pesant sur le patrimoine informationnel de l’entreprise la sensibilisation des collaborateurs est devenue un élément clé de la démarche de sécurité de l’information. Mais quelles sont les pratiques des grandes entreprises à ce sujet aujourd’hui ? Quels sont les nouveaux challenges de la sensibilisation ? Pour répondre à ces questions, Solucom a analysé les pratiques de près de 25 grandes entreprises françaises.</p>
<p>[Par Marion Couturier en collaboration avec  Loïc Dechoux]</p>
<p><a href="http://www.solucominsight.fr/2012/10/sensibilisation-quelles-pratiques-chez-les-grands-comptes/infographie-sensibilisation-2/" rel="attachment wp-att-2417"><img loading="lazy" decoding="async" class="size-full wp-image-2417 alignnone" title="Infographie Sensibilisation" src="http://www.solucominsight.fr/wp-content/uploads/2012/10/Infographie-Sensibilisation.jpg" alt="" width="544" height="630" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2012/10/Infographie-Sensibilisation.jpg 544w, https://www.riskinsight-wavestone.com/wp-content/uploads/2012/10/Infographie-Sensibilisation-165x191.jpg 165w, https://www.riskinsight-wavestone.com/wp-content/uploads/2012/10/Infographie-Sensibilisation-34x39.jpg 34w" sizes="auto, (max-width: 544px) 100vw, 544px" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2012/10/sensibilisation-quelles-pratiques-chez-les-grands-comptes/">Sensibilisation : quelles pratiques chez les grands comptes ?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Sensibilisation à la sécurité de l’information : où en sont les entreprises ?</title>
		<link>https://www.riskinsight-wavestone.com/en/2012/09/sensibilisation-a-la-securite-de-linformation-ou-en-sont-les-entreprises/</link>
		
		<dc:creator><![CDATA[Marion Couturier]]></dc:creator>
		<pubDate>Mon, 17 Sep 2012 07:30:49 +0000</pubDate>
				<category><![CDATA[Cyberrisk Management & Strategy]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Métiers - Digital & innovation]]></category>
		<category><![CDATA[benchmark]]></category>
		<category><![CDATA[cyberawareness]]></category>
		<category><![CDATA[gamification]]></category>
		<category><![CDATA[sensibilisation]]></category>
		<guid isPermaLink="false">http://www.solucominsight.fr/?p=2257</guid>

					<description><![CDATA[<p>La protection du patrimoine informationnel de l’entreprise contre les différentes menaces, qu’elles soient internes ou externes, est devenue un enjeu majeur pour les entreprises. Si de nombreuses solutions techniques et organisationnelles sont déjà en place, le maillon faible est souvent...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2012/09/sensibilisation-a-la-securite-de-linformation-ou-en-sont-les-entreprises/">Sensibilisation à la sécurité de l’information : où en sont les entreprises ?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>La protection du patrimoine informationnel de l’entreprise contre les différentes menaces, qu’elles soient internes ou externes, est devenue un enjeu majeur pour les entreprises. Si de nombreuses solutions techniques et organisationnelles sont déjà en place, le maillon faible est souvent le comportement des utilisateurs ! La sensibilisation des collaborateurs est donc un élément clé de la démarche de sécurité de l’information. Mais quelles sont les pratiques des grandes entreprises à ce sujet aujourd’hui ? Quels sont les nouveaux challenges de la sensibilisation ? Pour répondre à ces questions, Solucom a analysé les pratiques de près de 25 grandes entreprises françaises.</p>
<h2><strong>Sensibiliser, mais à quel prix ?</strong></h2>
<p>Affiches, e-mails, jeux, etc., il existe une multitude de moyens de sensibilisation présentant chacun leurs avantages et leurs défauts.  Largement plébiscité par 78% des entreprises du panel étudié, l’e-mail est le vecteur de sensibilisation le plus utilisé. Facile à déployer, peu coûteux, il n’est néanmoins pas suffisant pour garantir l’efficacité d’une campagne de sensibilisation à la sécurité de l’information. Ainsi, plus de 60% des entreprises optent pour la mise en place complémentaire d’évènements sécurité et de contenu dynamique sur Intranet, la diffusion de plaquettes et de fiches pratiques. Seules 25% des entreprises utilisent des solutions plus élaborées telles que la diffusion de contenu multimédia, la mise en place d’e-learning ou encore le déploiement de jeux et de quizz.</p>
<p>Comment expliquer l’utilisation massive d’e-mails qui ne seront pas forcement efficaces alors que la diffusion d’un contenu multimédia assurerait un impact plus important auprès des collaborateurs à sensibiliser ? La réponse tient en un mot : budget. Là où une campagne de mailing représentera un coût pratiquement nul pour l’entreprise, le tournage d’un clip vidéo de sensibilisation ou la mise en place d’un e-learning peuvent s’élever à plusieurs dizaines de milliers d’euros, notamment en cas de recours à une agence de communication. Seules les entreprises ayant les budgets sensibilisation les plus importants peuvent donc orienter vers cette solution.</p>
<h2><strong> </strong><strong>Les mêmes moyens de sensibilisation pour tous ? Focus sur le Plan de Continuité d’Activité (PCA)</strong></h2>
<p>Seules 25% des entreprises utilisent l’e-mail comme moyen de sensibilisation au PCA alors qu’elles sont 78% à l’utiliser pour la sensibilisation à la sécurité de l’information. Cette différence tient dans le fait que la sensibilisation au PCA vise notamment à inculquer les réflexes à avoir en cas de sinistre informatique. Les supports dématérialisés ne seraient donc plus accessibles ! Les plaquettes sont dès lors beaucoup plus utilisées. Cela illustre la nécessité d’adapter les supports de sensibilisation, que ce soit en fonction de la cible visée ou des spécificités du sujet traité.</p>
<h2> <strong>La sensibilisation à la sécurité de l’information et nouvelles technologies : une course contre la montre</strong></h2>
<p>Web 2.0, réseaux sociaux, Bring Your Own Device, etc., ces nouvelles pratiques ne cessent de se développer au sein des entreprises, amenant avec elles de nouvelles menaces pour la sécurité de l’information. La maîtrise des risques liés à ces services évoluant en permanence nécessite un effort constant pour rester efficace et ne pas subir l’innovation. La démocratisation progressive de l’utilisation de ces services au sein de l’entreprise doit donc s’accompagner d’une sensibilisation à leur utilisation en toute sécurité.</p>
<p>Parmi les usages récents, l’utilisation des réseaux sociaux s’est généralisée depuis 2008. 65% des entreprises en autorisent maintenant l’usage, majoritairement en en limitant l’accès à certaines populations métier (55%). Mais ces outils ayant pénétré aussi nos vies personnelles, elles sont aujourd’hui plus de 90% à sensibiliser leurs collaborateurs aux risques inhérents à leur utilisation. En revanche, le BYOD et les services de cloud computing personnels (Dropbox, Google Drive…) qui sont plus récents et moins répandus font encore peu l’objet de l’attention des utilisateurs : 12% des entreprises sensibilisent leurs collaborateurs au risque de fuite d’information que représentent ces derniers, et seulement 8% les sensibilisent aux risques du Bring Your Own Device.</p>
<p>L’un des grands enjeux de la sécurité de l’information aujourd’hui est donc, à défaut de pouvoir traiter immédiatement toutes les menaces, de tenter de réduire le délai entre leur apparition et leur prise en compte effective !</p>
<p>[Article rédigé en collaboration avec Loïc Dechoux, consultant]</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2012/09/sensibilisation-a-la-securite-de-linformation-ou-en-sont-les-entreprises/">Sensibilisation à la sécurité de l’information : où en sont les entreprises ?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>La sensibilisation : un dispositif à inscrire dans la durée !</title>
		<link>https://www.riskinsight-wavestone.com/en/2012/07/la-sensibilisation-un-dispositif-a-inscrire-dans-la-duree/</link>
		
		<dc:creator><![CDATA[Amal Boutayeb]]></dc:creator>
		<pubDate>Mon, 30 Jul 2012 14:38:53 +0000</pubDate>
				<category><![CDATA[Cyberrisk Management & Strategy]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Métiers - Marketing et relation client]]></category>
		<category><![CDATA[communication]]></category>
		<category><![CDATA[cyberawareness]]></category>
		<category><![CDATA[gamification]]></category>
		<category><![CDATA[sensibilisation]]></category>
		<guid isPermaLink="false">http://www.solucominsight.fr/?p=2064</guid>

					<description><![CDATA[<p>Faire prendre conscience des risques liés à la sécurité de l’information, inscrire des réflexes dans les gestes au quotidien, susciter les bonnes interrogations auprès de collaborateurs… c’est opérer un réel changement culturel dans les entreprises ! Or une telle évolution nécessite...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2012/07/la-sensibilisation-un-dispositif-a-inscrire-dans-la-duree/">La sensibilisation : un dispositif à inscrire dans la durée !</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><em>Faire prendre conscience des risques liés à la sécurité de l’information, inscrire des réflexes dans les gestes au quotidien, susciter les bonnes interrogations auprès de collaborateurs… c’est opérer un réel changement culturel dans les entreprises ! Or une telle évolution nécessite un effort dans la durée, dont l’efficacité ne peut se mesurer instantanément. </em></p>
<p><em>Le défi aujourd’hui est de réussir à ancrer la sécurité durablement dans les pratiques de chacun des utilisateurs</em>.</p>
<h2>L’inventivité, facteur de renouveau</h2>
<p>Que ce soit lors de la mise en place, ou dans les piqûres de rappel, l’originalité, la créativité, peut être un réel facteur d’attractivité et de différentiation de la compagne de sensibilisation à la sécurité. Pour autant ce facteur doit être mis en regard de la culture de communication interne de l’entreprise, et ce pour trouver le meilleur compromis entre originalité et crédibilité de la démarche.</p>
<p>La campagne doit ensuite évoluer dans le temps, ainsi que la posture en elle-même, mais également les canaux de communication. Nombreux sont les concepts, les supports qui peuvent être intégrés à la sensibilisation. Les <em>serious games</em>, la <em>gamification</em> et les applications pour smartphones ou tablettes en sont des illustrations.</p>
<h2>L’adaptabilité, une réponse aux nouveaux usages et les risques afférents</h2>
<p>L’évolution des usages permet de donner un nouveau souffle au catalogue de communication et formation, mais elle doit aussi être considérée sous l’angle des risques. Le BYOD (<em>Bring Your Own Device</em>) ou encore le Cloud en sont des cas concrets. Les objectifs de communication, les messages à diffuser vont évoluer, et ce dans l’objectif de responsabiliser davantage le personnel qui en fera l’usage. Un axe intéressant est de dresser un parallèle avec la vie quotidienne des collaborateurs afin de les responsabiliser.</p>
<h2>La mesure d’efficacité, source d’amélioration</h2>
<p>Chercher à s’améliorer implique de mesurer l’efficacité dans l’atteinte des objectifs initiaux. <em>In fine</em>, les collaborateurs sont-ils tous acteurs de la protection de l’information chacun à leur niveau ? La clé réside dans le fait que la sensibilisation est un dispositif de sécurité, et par conséquent il est important :</p>
<ul>
<li>D’identifier les éléments du plan de contrôle qui sont en lien avec le facteur humain d’une part. Un exemple ? Les audits  intègrent-ils la notion de « bureau net », de protection physique du matériel, d’exigence de port de badges, etc. ?</li>
<li>D’intégrer de nouveaux contrôles spécifiques d’autre part. Il peut s’agir de contrôles par échantillonnage qu’ils soient techniques (vérification des mots de passe par exemple) ou de l’ordre de la simple observation « terrain ».</li>
</ul>
<p>En conclusion, comme toute démarche liée à sécurité, la sensibilisation et la formation doivent s’inscrire dans un cycle de revue tant sur le fond (messages à faire passer, collaborateurs à cibler…), que sur la forme (canaux, supports, et conception…). L’ensemble doit s’intégrer dans l’existant de l’entreprise en respectant les pratiques des ressources humaines en termes de formation et de communication interne !</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2012/07/la-sensibilisation-un-dispositif-a-inscrire-dans-la-duree/">La sensibilisation : un dispositif à inscrire dans la durée !</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>La gamification : une solution pour sensibiliser la génération Y ?</title>
		<link>https://www.riskinsight-wavestone.com/en/2012/03/la-gamification-une-solution-pour-sensibiliser-la-generation-y/</link>
		
		<dc:creator><![CDATA[Marion Couturier]]></dc:creator>
		<pubDate>Fri, 16 Mar 2012 11:27:38 +0000</pubDate>
				<category><![CDATA[Cyberrisk Management & Strategy]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[cyberawareness]]></category>
		<category><![CDATA[gamification]]></category>
		<category><![CDATA[protection des données]]></category>
		<category><![CDATA[sensibilisation]]></category>
		<guid isPermaLink="false">http://www.solucominsight.fr/?p=1634</guid>

					<description><![CDATA[<p>La sensibilisation des utilisateurs est un chantier incontournable du RSSI : sans l’adhésion et la collaboration des utilisateurs, les stratégies de sécurisation de l’information et des SI restent partielles et inefficaces. Les campagnes de sensibilisation, qui constituent un moyen essentiel pour...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2012/03/la-gamification-une-solution-pour-sensibiliser-la-generation-y/">La gamification : une solution pour sensibiliser la génération Y ?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p align="left">La sensibilisation des utilisateurs est un chantier incontournable du RSSI : sans l’adhésion et la collaboration des utilisateurs, les stratégies de sécurisation de l’information et des SI restent partielles et inefficaces. Les campagnes de sensibilisation, qui constituent un moyen essentiel pour traiter ce facteur humain, sont donc aujourd’hui largement répandues en entreprise. Mais elles souffrent d’un certain nombre de limites !</p>
<h2 align="left">Un nouvel enjeu pour la sensibilisation à la sécurité de l’information : la génération Y pousse la porte des entreprises</h2>
<p align="left">La sensibilisation n’est pas un chantier sur lequel on peut se reposer une fois la première campagne achevée ! Comme toute campagne de prévention, des « piqûres de rappel » doivent être faites régulièrement, en variant la manière de communiquer pour assurer l’assimilation des messages dans la durée sans provoquer de lassitude.</p>
<p align="left">Par ailleurs, il est nécessaire de prendre en compte les nouveaux arrivants dans l’entreprise, qui n’ont pas reçu la sensibilisation initiale. Et il ne faut pas oublier que ces nouveaux arrivants sont majoritairement une population avec laquelle le niveau de risque pour la sécurité de l’information augmente : la fameuse génération Y.</p>
<p align="left">Les « digital natives », suréquipés, connectés en permanence, rendent de plus en plus perméable la frontière entre l’entreprise et leur vie personnelle. Leurs usages exposent largement les informations qu’ils manipulent : données personnelles, mais aussi professionnelles ! Et selon le Connected World Technology report de Cisco, 70% des jeunes employés admettent ne pas respecter les politiques de sécurité bien qu’ils en aient connaissance.  Plus exigeants que les générations X et baby-boomers, ils sont moins réceptifs à des campagnes de communication traditionnelles que leur aînés sur des sujets avec lesquels ils se sentent familiers, et ont encore plus besoin d’être convaincus et motivés.</p>
<h2 align="left">La gamification pour renforcer l’engagement et la motivation des collaborateurs</h2>
<p align="left">Face à ce nouvel enjeu, il est nécessaire de diversifier les méthodes et outils de sensibilisation pour assurer leur efficacité. La gamification, phénomène récent, apparaît comme un nouvel outil prometteur pour laquelle de plus en plus d’éditeurs  (Bunchball, Badgeville, Gamify…) proposent des solutions. Elle a pour principe l’application des mécanismes et de la dynamique du jeu à des activités non ludiques : points, niveaux, badges, challenges, statuts sont utilisés pour engager les gens, déclencher la motivation et changer les comportements (par exemple dans <a href="http://company.zynga.com/about/privacy-center/privacyville " target="_blank" rel="noopener noreferrer">le domaine de la protection des données</a>)</p>
<p align="left">Initialement utilisée auprès des clients à des buts marketing (Flying Blue, Accor, Starbucks…)  ou communautaires (Foursquare, Farmville, Nike+…), elle peut se transposer aisément au monde de l’entreprise et être un outil puissant pour accompagner les campagnes de sensibilisation, conduire le changement ou encore améliorer les performances. Cette technique rencontre un vif succès auprès de la génération Y aux codes de laquelle elle répond par ses dimensions sociale, ludique et technologique.</p>
<h2 align="left">Lancer le challenge sécurité !</h2>
<p align="left">Il n’y a plus qu’un pas à faire pour l’adapter à la sécurité de l’information en entreprise. En premier lieu, il s’agit de cibler les utilisateurs  et de définir les objectifs. Sur cette base, les compétences (savoir construire un mot de passe complexe…) et actions attendues (changer son mot de passe, suivre une formation, etc.) peuvent être formalisées avant de définir l’univers et les mécanismes de jeu qui seront appliqués. C’est là que résidera toute la dynamique de la démarche et l’adhésion des utilisateurs, il est donc nécessaire de travailler soigneusement cette partie, pour laquelle les solutions du marché offrent de nombreuses possibilités !</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2012/03/la-gamification-une-solution-pour-sensibiliser-la-generation-y/">La gamification : une solution pour sensibiliser la génération Y ?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
