Logo
Cybersecurity

Employees Want Better Cybersecurity Skills. The Training Has to Keep Up.

Most employees don’t need to become security analysts. They do need to know what a suspicious situation looks like in the work they actually perform.

ITSEC AsiaITSEC Asia
|
Okt 02, 2026
Employees Want Better Cybersecurity Skills. The Training Has to Keep Up.

Cybersecurity training has an awkward reputation.

For many employees, it arrives as an annual module, a collection of familiar warnings and a quiz that strongly encourages remembering whatever appeared on the previous screen.

Meanwhile, the workplace has become considerably less predictable.

ENISA’s latest Cybersecurity Month data shows that 74% of surveyed employees had received suspicious emails, messages, voice communications or links at work during the previous six months. Phishing remained the most common example, but employees also encountered attempts to steal personal information, passwords, AI-generated scams, malware and ransomware. ENISA

Yet only 45% said their organization regularly sends cybersecurity awareness information or updates.

The interesting part is that employees don’t appear uninterested. Eighty-five percent said they wanted to improve their cybersecurity skills. ENISA

The gap is partly about how training is delivered.

The Biggest Training Problem May Be the Calendar

Among employees who identified obstacles to developing cyber skills, 26% cited finding time during work, ahead of cost at 16%, followed by limited information about training and insufficient employer support. ENISA

That matters because cybersecurity training often competes with everything else people are expected to finish that day.

A better program has to respect that reality.

Useful workforce training can focus on specific decisions employees regularly face:

  • Whether an unusual request should be independently verified
  • What information is safe to enter into an AI tool
  • How to report suspicious activity quickly
  • What to do when a familiar login process suddenly behaves differently
  • How to handle customer or confidential information outside normal workflows
  • When an unusual request from a manager should still trigger a second check

These aren’t abstract cybersecurity concepts. They’re moments that can happen between two ordinary meetings.

Different Jobs Create Different Risks

A finance employee, software developer and communications manager don’t necessarily need identical cybersecurity training.

Finance teams may face payment fraud and impersonation. Developers need secure handling of code, credentials and dependencies. Communications teams can encounter compromised social accounts, fraudulent media requests or suspicious files arriving from external contacts.

The basics overlap, but the scenarios should feel familiar to the learner.

NIST’s FISSEA program takes a similar direction. Its 2026 training forums emphasize employee behaviour and practical learning, including short micro-training modules and methods that move users from passive awareness toward verification habits they can use in real situations. NIST

That’s a more useful objective than asking whether everyone remembers the definition of phishing.

Train the Decision, Not Just the Definition

Cybersecurity readiness improves when employees practise what to do.

Give a finance team a realistic payment-change request. Let employees inspect it, verify it through another channel and decide when to escalate. Give another group an AI tool and several documents with different sensitivity levels, then ask what can safely be uploaded.

The learning becomes a decision rather than a lecture.

For dedicated cyber professionals, the same principle can continue into deeper practical environments. ITSEC Cyber & AI Academy connects cybersecurity and AI learning with hands-on exercises where participants can investigate, test and respond rather than simply consume material.

Most employees already know cybersecurity matters.

The more useful training question is whether they’ll know what to do when something slightly strange appears at 3:47 on a busy afternoon.

Explore practical cybersecurity and AI learning at ITSEC Cyber & AI Academy.

References: ENISA: Cybersecurity Month @ Work, 30 September 2026 · NIST FISSEA Spring Forum 2026 · NIST FISSEA Fall Forum 2026

Share this post

You may also like

What Is Continuous Security Validation and Why Does It Matter?
Cybersecurity

What Is Continuous Security Validation and Why Does It Matter?

Cyber threats evolve continuously. New vulnerabilities are discovered every day. Cloud environments change rapidly. Applications are updated frequently. Employees adopt new technologies and attackers constantly search for opportunities to exploit weaknesses. Yet many organizations still rely on periodic security assessments conducted once or twice a year. The challenge is simple: risk does not wait for the next penetration test. This is why more organizations are embracing Continuous Security Validation (CSV) as part of a modern cybersecurity strategy. WHAT IS CONTINUOUS SECURITY VALIDATION? Continuous Security Validation is the practice of continuously evaluating and validating an organization's security posture as environments, threats and attack surfaces evolve. Instead of providing a snapshot at a single point in time, Continuous Security Validation delivers ongoing visibility into security weaknesses and control effectiveness. Its purpose is to answer a critical question: "Are our defenses still working today?" Rather than waiting months between assessments, organizations gain a more dynamic understanding of their exposure. WHY TRADITIONAL ASSESSMENTS ARE NO LONGER ENOUGH Traditional penetration testing remains an important component of cybersecurity. However, most assessments are performed

ITSEC AsiaITSEC Asia
|
Jun 15, 2026 — 4 minutes read
Fraud Management in Digital Era: How to Detect, Prevent, and Respond Before Losses Escalate
Cybersecurity

Fraud Management in Digital Era: How to Detect, Prevent, and Respond Before Losses Escalate

INTRODUCTION In 2025, a large-scale fraud operation uncovered by INTERPOL revealed how sophisticated Business Email Compromise (BEC) scams have become. A transnational criminal group targeted a Japanese company by impersonating a legitimate business partner through hacked or spoofed email accounts. The communication looked completely normal with the same tone, same format, and same context. The attackers sent updated banking details for a supposed transaction, convincing the company to transfer funds to a fraudulent account based in Thailand. Because the email matched ongoing business conversations, there was no immediate suspicion. By the time the fraud was detected, millions had already been moved across multiple accounts. Fraud is no longer just about stolen wallets or obvious scams. In today’s digital world, it has evolved into something far more sophisticated, quiet, convincing, and often invisible. Powered by advanced technologies like Deepfake Technology and automated systems, modern fraud can replicate voices, mimic identities, and blend seamlessly into everyday digital interactions. What makes it dangerous is not just the technology, but how naturally it fits into

ITSEC AsiaITSEC Asia
|
Apr 10, 2026 — 6 minutes read
Web Application Penetration Testing Explained: Why Applications Remain a Top Target for Attackers
Cybersecurity

Web Application Penetration Testing Explained: Why Applications Remain a Top Target for Attackers

Web applications have become the foundation of digital business. From customer portals and online banking platforms to e-commerce systems and internal business applications, organizations rely on web technologies to deliver services and create seamless user experiences. Unfortunately, attackers rely on them too. Because web applications are often exposed to the internet and handle sensitive information, they remain one of the most attractive targets for cybercriminals. This is why Web Application Penetration Testing has become an essential part of a modern cybersecurity strategy. WHAT IS WEB APPLICATION PENETRATION TESTING? Web Application Penetration Testing is a security assessment designed to identify and validate vulnerabilities within web applications before malicious actors can exploit them. Unlike automated vulnerability scanning, penetration testing simulates real-world attack techniques to understand how weaknesses could affect an organization's confidentiality, integrity and availability. The objective is not simply to discover vulnerabilities but to determine their actual impact. WHY ARE WEB APPLICATIONS FREQUENTLY TARGETED? Attackers are constantly searching for exposed applications because they often provide direct access to valuable assets. SENSITIVE DATA Web applications commonly process: * Customer

ITSEC AsiaITSEC Asia
|
Jun 15, 2026 — 5 minutes read

Receive weekly
updates on new posts

Subscribe