Engaging Management Teams
While you may have implemented a holistic security perimeter, including endpoint protection, DNS filtering, and anti-spam measures, over 90% of successful security breaches involve a human element such as a social engineering attempt or a spear-phishing attack. Ensuring that your stakeholders understand the threats is the first step to initiating and then running a successful Security Awareness Training Program.
Send an email introducing Security Awareness to management, explaining the value of the service, and be sure to share details around your first phishing and training campaigns. Webroot also has a white paper called, "Why Businesses Need Security Awareness Training Now," which lays out the reasons why so many organizations are providing cybersecurity user education.
If applicable, loop in your local IT support so they are aware of the service and training schedule as well. If you are not sure how to craft that first email, we have provided sample stakeholder email templates within the Webroot Security Awareness Training learning management console. You can use these as is, or edit them to suit your needs.