Among the many techniques for ensuring network security, employee training is often mentioned as one of the most effective. It makes sense: More than 80 percent of recent data breaches were caused in at least some part by employee negligence, and more than half of all security professionals believe that employees are the weakest link in any security program.

However, despite these statistics, most employee training in cybersecurity is inadequate. In some cases, it’s simply a matter of the training being rushed or treated as an afterthought. All too often, cybersecurity is included as a short session during employee orientation, where an IT staff member tells a group of new hires about creating safe passwords and avoiding suspicious emails, and never addressed again. Even in companies with a more robust training protocol, cybersecurity training is often inconsistent and doesn’t always address the real issues that lead to data breaches.

It’s clear that most organizations need to do a better job of equipping their employees to avoid security risks. Short of training everyone to be an IT security expert, here are some tips on using training to protect your corporate network.

Provide More In-Depth Training to Security Staff

One of the best ways companies can keep their networks safe is to equip the people charged with protecting it with the best possible tools. These tools often require advanced training, which can provide them with the skills and knowledge necessary to use security tools like a pfSense appliance successfully. Without the right training, even your most expert staff members may not be able to use their equipment to its greatest advantage, potentially leaving you vulnerable to attack. Invest in training for the IT security team on a regular basis so that they remain up to date.

Address Physical Security

Often, the actual physical protection of network assets is overlooked — even though a startling number of data breaches stem from the theft of or unauthorized access to equipment. For example, the massive data breach at the Department of Veterans Affairs stemmed from a stolen laptop computer. Employees need to be trained to secure their devices both in and out of the office and know what to do if they see something suspicious or suspect that their devices are compromised. Equipping all company mobile devices with remote lock and wipe capabilities can help protect information as well, by restricting access if the device is lost or stolen.

Support Security Leadership

Ideally, a commitment to cybersecurity should start at the top of the organization, with a chief information security officer (CISO) who reports to the CEO or the board. However, the CISO should not be simply a figurehead leader who acts solely under the direction of the CEO or board. He or she needs actual authority to make decisions related to security and the budget necessary to keep the network safe. The CISO should have input into every major company project – especially cybersecurity training programs – in order to address concerns and put a hold on any project that does not adequately address security. In short, by helping to develop an executive with actual authority, you can ensure that employees know your company takes security seriously and see real consequences for failing to consider it.

Provide Better Guidance for Security Questions

No matter how well you train your employees, they will undoubtedly have questions at some point. It’s unreasonable to expect them to know everything they need to know and be able to respond appropriately in every circumstance. Therefore, it’s important to communicate proactively with employees to ensure that that they have a solid understanding of security policy, what to do when they have questions and that the IT security team will be willing to help when the need arises.

This may entail ongoing security training as well as regular updates and even testing to ensure that everyone is on the same page and is continuing to make security a priority. For many people, security is “something that IT takes care of,” and they simply don’t understand their role. Training leaders can change that perception.

Employee training remains an important piece of the security puzzle, but it needs to be done right to ensure that it is effective. By making it an ongoing priority and addressing the right issues, it will be.