Why hire a cyber security consultancy? Employee training

Why hire a cyber security consultancy? Employee training

In the 16+ years Arcanum has been operating, we have done all sorts of cyber security jobs for all sorts of clients.  Some have been large organisations, some small.  Some have been in the Public Sector, some in the Private Sector.  Some have been very profitable businesses, and some have been very small charities and not-for profit organisations.  What did they have in common and why did they come to us? In a series of posts, we will explore the question ‘Why hire a cyber security consultancy?’ Looking back at our records, we’ve worked out that, although there is no single reason, there are some common themes; specialist expertise required, fear, incident response, frameworks, training, compliance and risk management. In this post, cyber consultant Wendy Goucher outlines the importance of training.

The best cyber security is that which comes from working closely with clients so that issues are expressed in terms of the client perspective and their business requirements.  We know from our extensive experience that just bringing in a generic solution does not deliver quality or value for money for our clients whether that be in cyber security operations or in training that underpins it.   In my previous career, I trained as a teacher and worked as a lecturer in college and university for many years, so I am a resource that my colleagues can use even if I am not directly involved in training delivery for a project.  My colleagues have a rich vein of knowledge and experience in communicating around cyber security which means that training can be designed and delivered an a way that is applicable and effective to our clients.   For Arcanum, training is not a discrete part of our work.  We don’t just do a ‘training session,’ it is part of the way we work on a project.  We know that learning comes from understanding the issue and then working together to arrive at solutions or mitigations that meet both external needs, such as legal and regulatory compliance and the internal business requirements as closely as possible.  That work itself is implicit training because all involved are learning.   As a consultant I worked on a government project where we were understanding risk management in a rapidly changing threat environment.  There were instances where specific areas, such as HR, required a fuller understanding of threats to the data that they processed.  In that my colleague set the scene and then we worked with the team to look at scenarios and issues that they were aware of, as well as some that came from our experience.  We then supported and guided active problem solving in a collaborative way with a key ‘rule’ that was ‘there is no such thing as a stupid question’.  The initial session took half a day, which with very busy staff meant we needed to make every minute a value point.  Ultimately the staff were very happy that they had a better understanding of factors they needed on a daily basis and felt empowered to find advice when they needed it.   In another situation the staff worked in open plan office with small meeting rooms. As the only place everyone could gather was the main office there were too many distractions for training in a formal sense.  So, security communication was delivered using a variety of modes including posters, articles, online quizzes and small group meetings.  Managers had their own training event, which was interactive, and they were then able to use appropriate resources to cascade to their staff.  That was pre-COVID, so podcasting was not widely used.   Now we can incorporate videos and podcasts into the resources.  In some situations, pre-recorded podcasts prove popular as they can be stopped if there is a distraction.  They can also work well for staff with accessibility requirements.  However, as with all our work, being mindful of the culture and requirements of our clients is a critical factor in designing any training.   We also understand that there are times when formal training is required, and we make sure that this is delivered in a way that works best for the customer.  Building on their culture and communications to be as effective as possible.  We also like to involve those consultants who have been working on a project to help to train client staff as they have the best understanding of what is needed and how best to provide that.

Arcanum is a Cyber Security Consultancy, a team of cyber security professionals who, although many have a deep specialisation in one area or another, like incident response, operational technology or security testing, all have a core of extremely competent knowledge of cyber risk management.  If you’d like to talk to us about any aspect of managing your cyber risks, please get in touchRead more from this series: Incident response planning Expertise and specialisation