Today we live in a digitalized world, both professionally and personally, which creates a favorable environment for “cybercriminals” to profit from their illicit activities on the Web.
To put this into context, according to the National Cybersecurity Institute (INCIBE), through INCIBE-CERT (Security Incident Response Center), during the year 2020, 133,155 cybersecurity incidents were managed, of which 106,466 were directed at citizens and companies, 1,190 at strategic operators, with the risks that this entails, and 25,499 at the Spanish Academic and Research Network (Source: www.incibe.es published on 23/03/2021), this without taking into account cyberattacks that have not been reported to INCIBE.
To give a more recent example, at the beginning of this year 2021, a year marked by the Coronavirus pandemic, the public administration has suffered intentional attacks that have paralyzed the provision of critical services such as the SEPE (State Public Employment Service), making it impossible for citizens to access their benefits or job offers.
Cybersecurity training, the key
In this respect, we can note that none of us are safe from being attacked and extorted online, which makes cybersecurity training and awareness a strategic requirement in any organization. We must be aware that we users are the weakest point in the management chain; we need only consider everyday situations where users don’t know they are being attacked — such as recognizing the legitimacy of an email, being suspicious of requests for banking data from dubious senders (email, password, PIN number), offers of free products to gain the user’s trust, or using external devices (USB drives, hard drives) without the proper precautions, with the risks that this can entail.
This weakness is well known to cybercriminals, who take advantage of users’ lack of cybersecurity awareness or training to focus their attacks and continuously improve their methods. Therefore, if we know how to detect and act against these intentional attacks, we can avoid greater harm.
Within this framework, organizations play a fundamental role in the awareness and training of users, which will bring benefits not only in the workplace but will also allow them to apply it in their personal lives.
What cybersecurity training and awareness actions can be carried out?
Aside from the security measures established by organizations — such as network filtering (firewall), the deployment of antivirus and anti-malware systems, encryption of connections, and backups, which users are generally unaware of — there are two specific actions that impact the end user and that are of great importance when it comes to preventing cyberattacks. In this respect, we can speak of:
- Cybersecurity training: Attendance at specific security training courses based on different profiles, training sessions for the organization’s staff, participation in security events, ongoing contact with specialized providers, etc. This type of training is aimed at specialized professionals (CISO, CIO, Systems Managers, etc.) in companies, who will largely be responsible for applying security measures in organizations to prevent attacks.
- Cybersecurity awareness: Regular informational briefings for staff, sharing examples of the most common attacks, and planned cyberattack tests to verify staff awareness. This awareness is aimed at the general public, without requiring advanced technical knowledge, in order to plant that seed of security awareness.
Broadly speaking, if we strengthen these lines of action in our organization, we will reinforce the protection of our infrastructure and corporate information systems, as well as transfer it to the personal sphere since, ultimately, cybersecurity is a problem that affects us all and only together will we be able to detect these threats earlier and spread actions to prevent them.
At GlobalSuite Solutions, we provide the necessary help to cover the needs of any organization with our cybersecurity solutions and by conducting online or in-person courses, adjusted and tailored with the aim of training and raising awareness among your organization’s resources for a substantial improvement in security. In this respect, we support your organization in managing security with GlobalSuite®, a GRC platform (Governance, Risk and Compliance) where you can access the information you need to monitor and establish continuous improvement actions in your organization.



