According to the Clearswift Insider Threat Index (CITI), 37 percent of firms expect a data breach in the next 12 months as a result of employee behavior. Further, the report states that employees indicated a widespread lack of awareness of good cybersecurity practice. The consequence is that over the last year, 74 percent of breaches originated from within the extended enterprise (including suppliers and former employees).

So, are you in the 37 percent? If so, how do you mitigate that threat? Where do you even start?

Most business leaders have read the headlines about growing concerns over cybersecurity and have made investments to protect their networks with hardware and software solutions. Those are important steps to take, but don’t stop there. Whether a breach results from a hacking attempt on your network or an employee who inserts a corrupt USB drive into their laptop, the damage is the same.

In the 2015 Spiceworks Security Survey, 69 percent of IT professionals identified limited end-user knowledge of security risks as a challenge, and 57 percent said they experience end-user resistance to following security best practices. The course of action should be clear: We need to train our employees.

But let’s face it: Compliance training of any sort has a history of being boring and time-consuming. We often set the parameters of success by requiring a 100 percent on the test, a date and a signature. But can we really be certain that our employees learned anything, or did they just go through the motions?

That’s why we can’t treat cybersecurity training as a form of compliance training. It is not “one-and-done” training. Cybersecurity training needs to be conducted with performance as the key metric. Take it out of the realm of required compliance, and shift the focus to actually learning the best practices and policies that will protect your business. Your employees need to become as performance-oriented in their approach to securing the network as they are in their key roles and responsibilities. It should be a top-of-mind, everyday approach rather than a one-time training event.

Here are some suggestions for achieving a performance culture regarding cybersecurity:

  • Use training methods that have a history of success in your organization.
  • Compliance is generally boring; spice it up with video clips and music.
  • Use story-based scenarios, which are generally easier for learners to remember.
  • Use microlearning so learners can consume content a little at a time, at their own pace.
  • Make the training available in phases so it stays fresh and continually reinforces the key ideas and best practices.
  • Have the training database available year-round for new hires and for remedial and review access.
  • Create the content in house if it’s very specific, or contract with a third-party specialist who can bring your vision to life.

This solution is very feasible, because you are probably already using many of these techniques to train your employees. If they are already familiar with your methodology, you are one step closer to higher participation and success.

In today’s world, the harsh truth is your organization either has been or will be a victim of a cyberattack. Treating it as a compliance issue will create internal resistance and likely will not change the behavior of most employees. It’s time to change up the game, make it a daily performance indicator and get better results to protect your business!